Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 15 of 201.

Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett 2025 University of South Alabama

Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett

Shelby Hall Graduate Research Forum Posters

The primary goal of this research is to understand and exploit the security vulnerabilities of a Field Programmable Gate Array (FPGA), at the bitstream level. This paper is working to successfully show that an FPGA can be altered via the bitstream file, and a Trojan can be inserted into the device. Once a Trojan is successfully inserted into the FPGA and activated through a certain input value, a Siamese Neural Network (SNN) will be used to test the effectiveness of Trojan detection. Followed by recording the successful flag rate to detect Trojans, which will be averaged to determine the accuracy …


Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel 2025 University of South Alabama

Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel

Shelby Hall Graduate Research Forum Posters

The rapid evolution of computational ecosystems—ranging from embedded systems and cloud platforms to hybrid and quantum architectures—has introduced new challenges in deploying machine learning (ML) applications. While cloud computing offers scalability, it comes with increased latency and security risks, whereas edge computing, such as FPGA-based systems, provides real-time processing with constrained resources. Hybrid and quantum ecosystems further complicate decision-making, requiring careful trade-offs between performance and security. This research seeks to establish a framework for evaluating ML performance and security risks across these ecosystems, forming the foundation of the Computational Performance And Security System (COMPASS) decision-support tool. The study will systematically …


Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black 2025 University of South Alabama

Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black

Shelby Hall Graduate Research Forum Posters

Current forensic tools struggle to effectively detect encrypted storage media. In recent years, there have been significant advancements, but a noticeable gap remains when it comes to identifying encrypted volumes from metadata alone. The goal of this research is to develop a novel algorithm that will identify the presence of volumes on a disk image which have been encrypted with the Linux Unified Key Setup (LUKS) encryption algorithm, in an effort to aid digital forensics investigations. Bad actors often use encryption as an anti-forensics tool to pose significant challenges to forensic investigators, especially when it is done within sections of …


Preserving Privacy In Senior Care At Home Monitoring Systems, Sam Russel, Ryan Benton, Amy Campbell, Scott Sittig 2025 University of South Alabama

Preserving Privacy In Senior Care At Home Monitoring Systems, Sam Russel, Ryan Benton, Amy Campbell, Scott Sittig

Shelby Hall Graduate Research Forum Posters

Many seniors prefer to live at home which necessitates research into the application of technologies to provide a safer environment with less caregiver resources. However, the application of home health care (HHC) monitoring for seniors is still in an evolutionary stage. Present HHC systems are produced by private companies with general regulatory guidelines lacking specific care of the elderly. As such, each company that produces such a system claims to have better safety, privacy, and security that their competitors. A pressing issues is devising and applying a general framework for the application of technologies that delivers safety while preserving privacy. …


False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell 2025 University of South Alabama

False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell

Shelby Hall Graduate Research Forum Posters

Social media is an increasingly significant tool in modern cyber warfare, capable of rapidly shaping public opinion. The swift dissemination of information complicates efforts to distinguish fact from fiction [1]. During public health crises, healthcare professionals use these platforms to share updates, yet their credible content must contend with false or deliberately misleading narratives [2]. This environment creates an opportunity for cyberattacks through social media influence campaigns [3]. While disinformation's role in political interference has been widely studied, its potential to destabilize healthcare remains largely unexplored. Prior research primarily focuses on how vaccine misinformation affects the general public [4]. This …


Detecting Sensor Data Manipulation, Ricky Green, Michael Black 2025 University of South Alabama

Detecting Sensor Data Manipulation, Ricky Green, Michael Black

Shelby Hall Graduate Research Forum Posters

The integration of Information Technology (IT) and Operational Technology (OT) have made OT devices vulnerable to threats that have been successfully exploited with devastating results. Many modern techniques for hardening and securing enterprise IT systems are either incompatible with OT components in an Industrial Control System (ICS), reduce the efficiency of processes, or are prohibitively expensive to implement. Research in the area of ICS security focuses on a top-down approach, such as intrusion prevention by securing the perimeter of the network and hardening computer systems. This approach is useful in business IT systems, but full compatibility with OT components in …


Backdoor Token Unlearning: Exposing And Defending Backdoors In Pretrained Language Models, Peihai JIANG, Xixiang LYU, Yige LI, Jing MA 2025 Singapore Management University

Backdoor Token Unlearning: Exposing And Defending Backdoors In Pretrained Language Models, Peihai Jiang, Xixiang Lyu, Yige Li, Jing Ma

Research Collection School Of Computing and Information Systems

Supervised fine-tuning has become the predominant method for adapting large pretrained models to downstream tasks. However, recent studies have revealed that these models are vulnerable to backdoor attacks, where even a small number of malicious samples can successfully embed backdoor triggers into the model. While most existing defense methods focus on post-training backdoor defense, efficiently defending against backdoor attacks during training phase remains largely unexplored. To address this gap, we propose a novel defense method called Backdoor Token Unlearning (BTU), which proactively detects and neutralizes trigger tokens during the training stage. Our work is based on two key findings: 1) …


Private Reachability Queries On Structured Encrypted Temporal Bipartite Graphs, Yulin WU, Lanxiang CHEN, Gaolin CHEN, Yi MU, Robert H. DENG 2025 Fujian Normal University

Private Reachability Queries On Structured Encrypted Temporal Bipartite Graphs, Yulin Wu, Lanxiang Chen, Gaolin Chen, Yi Mu, Robert H. Deng

Research Collection School Of Computing and Information Systems

A temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on …


Forward-Secure Hierarchical Delegable Signature For Smart Homes, Jianfei SUN, Guowen XU, Yang YANG, Xuehuan YANG, Xiaoguo LI, Cong WU, Zhen LIU, Guomin YANG, Robert H. DENG 2025 Singapore Management University

Forward-Secure Hierarchical Delegable Signature For Smart Homes, Jianfei Sun, Guowen Xu, Yang Yang, Xuehuan Yang, Xiaoguo Li, Cong Wu, Zhen Liu, Guomin Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Aiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: (1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; (2) flexible self-sovereign permission delegation; (3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever …


Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities, Yagmur Yigit, Mohamed Amine Ferrag, Mohamed C. Ghanem, Iqbal H. Sarker, Leandros A. Maglaras, Christos Chrysoulas, Naghmeh Moradpoor, Norbert Tihanyi, Helge Janicke 2025 Edith Cowan University

Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities, Yagmur Yigit, Mohamed Amine Ferrag, Mohamed C. Ghanem, Iqbal H. Sarker, Leandros A. Maglaras, Christos Chrysoulas, Naghmeh Moradpoor, Norbert Tihanyi, Helge Janicke

Research outputs 2022 to 2026

Critical National Infrastructures (CNIs)—including energy grids, water systems, transportation networks, and communication frameworks—are essential to modern society yet face escalating cybersecurity threats. This review paper comprehensively analyzes AI-driven approaches for Critical Infrastructure Protection (CIP). We begin by examining the reliability of CNIs and introduce established benchmarks for evaluating Large Language Models (LLMs) within cybersecurity contexts. Next, we explore core cybersecurity issues, focusing on trust, privacy, resilience, and securability in these vital systems. Building on this foundation, we assess the role of Generative AI and LLMs in enhancing CIP and present insights on applying Agentic AI for proactive defense mechanisms. Finally, …


Provable Security In Idealised Models, Chandranan Dhar 2025 Indian Statistical Institute

Provable Security In Idealised Models, Chandranan Dhar

Doctoral Theses

This thesis is a compilation of provable security analyses of various cryptographic constructions in idealised models. The first construction examined is the ABR hash. We revisit the existing proof of the ABR hash in the random oracle model and identify significant errors in the proof. Although we are unable to correct the original proof, we establish the security of the ABR tree of height 3 from scratch, addressing the first non-trivial case. As our second contribution, we conduct a tight and comprehensive security analysis of the Ascon AEAD mode in the random permutation model. We show that the efficiency of …


Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege 2025 Temple University

Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege

Journal of Cybersecurity Education, Research and Practice

The online dating industry generated 2.98 billion USD in 2023 and is estimated to reach 3.6 billion USD by 2025. Not surprisingly, online dating platforms are rife with romance scams that cause financial damages, with estimated losses of 1.3 billion USD in 2022 alone. Additionally, victims suffer emotional and psychological harms. This paper shares findings from a 2023 Romance Scam and Social Engineering Competition (RSSEC) that introduced students to the behavioral and psychological aspects of romance scams. Specifically, the competition aimed to expose students to (i) understanding how victims experience social engineering (SE) - the psychological manipulation of human behavior, …


Managing Cybersecurity In Local Governments: 2022, Donald F. Norris PhD, Laura K. Mateczun JD 2025 University of Maryland, Baltimore County (UMBC)

Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd

Journal of Cybersecurity Education, Research and Practice

This paper, based on data from our second nationwide survey of cybersecurity among local or grassroots governments in the U.S., examines how these governments manage this important function. As we have shown elsewhere, cybersecurity among local governments is increasingly important because these governments are under constant or nearly constant cyberattack. Due to the frequency of cyberattacks, as well as the probability that at least some attacks will succeed and cause damage to local government information systems, these governments have great responsibility to protect their information assets. This, in turn, requires these governments to manage cybersecurity effectively, something our data show …


Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell 2025 Ohio Northern University

Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell

Pharmacy and Wellness Review

Artificial Intelligence (AI) has transformed the pharmaceutical field by enabling computer software systems to learn and perform human behavior. Specifically, AI has revolutionized chronic diabetes management through continuous glucose monitoring, showcasing its immense potential in healthcare. However, alongside its transformative impact, AI’s increasing role in healthcare has prompted concerns over privacy and its premature integration. Despite these challenges, AI offers limitless opportunities to improve medication management and treatment regimens, driving advancements across various domains. From improving CT imaging to enhancing adenoma detection in colonoscopies and facilitating medication adherence, AI’s impact on healthcare is profound. Furthermore, AI plays a pivotal role …


Scrutinizer: Towards Secure Forensics On Compromised Trustzone, Yiming ZHANG, Fengwei ZHANG, Xiapu LUO, Rui HOU, Xuhua DING, Zhenkai LIANG, Shoumeng YAN, Tao WE, Zhengyu HE 2025 Singapore Management University

Scrutinizer: Towards Secure Forensics On Compromised Trustzone, Yiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou, Xuhua Ding, Zhenkai Liang, Shoumeng Yan, Tao We, Zhengyu He

Research Collection School Of Computing and Information Systems

The number of vulnerabilities exploited in Arm TrustZone systems has been increasing recently. The absence of digital forensics tools prevents platform owners from incident response or periodic security scans. However, the area of secure forensics for compromised TrustZone remains unexplored and presents unresolved challenges. Traditional out-of-TrustZone forensics are inherently hindered by TrustZone protection, rendering them infeasible. In-TrustZone approaches are susceptible to attacks from privileged adversaries, undermining their security. To fill these gaps, we introduce SCRUTINIZER, the first secure forensics solution for compromised TrustZone systems. SCRUTINIZER utilizes the highest privilege domain of the recent Arm Confidential Computing Architecture (CCA), called the …


Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning, Hari Hara Suthan CHITTOOR, Paul Robert GRIFFIN, Ariel NEUFELD, Jayne THOMPSON, Mile GU 2025 Singapore Management University

Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning, Hari Hara Suthan Chittoor, Paul Robert Griffin, Ariel Neufeld, Jayne Thompson, Mile Gu

Research Collection School Of Computing and Information Systems

Long-term time series forecasting (LTSF) involves predicting a large number of future values of a time series based on the past values. This is an essential task in a wide range of domains including weather forecasting, stock market analysis and disease outbreak prediction. Over the decades LTSF algorithms have transitioned from statistical models to deep learning models like transformer models. Despite the complex architecture of transformer based LTSF models ‘Are Transformers Effective for Time Series Forecasting? (Zeng et al., 2023)’ showed that simple linear models can outperform the state-of-the-art transformer based LTSF models. Recently, quantum machine learning (QML) is evolving …


Siniel: Distributed Privacy-Preserving Zksnark, Yunbo YANG, Yuejia CHENG, Kailun WANG, Xiaoguo LI, Jianfei SUN, Jiachen SHEN, Xiaolei DONG, Zhenfu CAO, Guomin YANG, Robert H. DENG 2025 Singapore Management University

Siniel: Distributed Privacy-Preserving Zksnark, Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng

Research Collection School Of Computing and Information Systems

Zero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive, in which a prover convinces a verifier that a given statement is true without leaking any additional information. However, existing zkSNARKs suffer from high computation overhead in the proof generation. This limits the applications of zkSNARKs, such as private payments, private smart contracts, and anonymous credentials. Private delegation has become a prominent way to accelerate proof generation. In this work, we propose Siniel, an efficient private delegation framework for zkSNARKs constructed from polynomial interactive oracle proof (PIOP) and polynomial commitment scheme (PCS). Our protocol allows a computationally limited …


Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems, Zhongming WANG, Tao XIANG, Xiaoguo LI, Biwen CHEN, Guomin YANG, Chuan MA, Robert H. DENG 2025 Singapore Management University

Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems, Zhongming Wang, Tao Xiang, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma, Robert H. Deng

Research Collection School Of Computing and Information Systems

Encrypted messaging systems obstruct content moderation, although they provide end-to-end security. As a result, misinformation proliferates in these systems, thereby exacerbating online hate and harassment. The paradigm of “Reporting-then-Tracing” shows great potential in mitigating the spread of misinformation. For instance, message traceback (CCS’19) traces all the dissemination paths of a message, while source tracing (CCS’21) traces its originator. However, message traceback lacks privacy preservation for non-influential users (e.g., users who only receive the message once), while source tracing maintains privacy but only provides limited traceability. In this paper, we initiate the study of impact tracing. Intuitively, impact tracing traces influential …


Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson 2025 Edith Cowan University

Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson

Research outputs 2022 to 2026

Understanding group information and collective behaviors is an ongoing area of research, encompassing natural phenomena and human dynamics. Quantifying interactions and interdependencies at the group level can be valuable for understanding complex and dynamical systems. The Border Gateway Protocol (BGP), the default inter-domain routing protocol for the Internet, operates within a large, complex, and dynamic system vulnerable to security threats. Traditional BGP anomaly detection focuses on single observables from individual Autonomous Systems (ASes), which inadequately addresses the multidimensional, multi-viewpoint nature of the Internet and interdomain routing. This paper introduces a novel approach for quantifying group AS-level information and dynamics. We …


Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim 2025 Old Dominion University

Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim

Graduate Student Government Association Research Conference

Progressive Web Applications (PWAs) are gaining popularity due to their rich features. Service Workers (SWs), one of its integral components, make this possible by providing users with offline functionality, improved performance, and effective caching techniques. SWs act as proxies positioned between the client browser and the web server, capable of intercepting requests and responses. Recent research has revealed that, despite being designed with security in mind, there are ways to circumvent these security precautions and launch various attacks.

Sensitive functions in JavaScript are functions that can introduce security vulnerabilities if not properly coded or validated. These functions can manipulate the …


Digital Commons powered by bepress