Security Vulnerabilities Of A Field Programmable Gate Array,
2025
University of South Alabama
Security Vulnerabilities Of A Field Programmable Gate Array, Kylie Arnett
Shelby Hall Graduate Research Forum Posters
The primary goal of this research is to understand and exploit the security vulnerabilities of a Field Programmable Gate Array (FPGA), at the bitstream level. This paper is working to successfully show that an FPGA can be altered via the bitstream file, and a Trojan can be inserted into the device. Once a Trojan is successfully inserted into the FPGA and activated through a certain input value, a Siamese Neural Network (SNN) will be used to test the effectiveness of Trojan detection. Followed by recording the successful flag rate to detect Trojans, which will be averaged to determine the accuracy …
Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems,
2025
University of South Alabama
Establishing A Framework For Evaluating Machine Learning Performance And Security Across Computational Ecosystems, Krista Stacey, Todd R. Andel
Shelby Hall Graduate Research Forum Posters
The rapid evolution of computational ecosystems—ranging from embedded systems and cloud platforms to hybrid and quantum architectures—has introduced new challenges in deploying machine learning (ML) applications. While cloud computing offers scalability, it comes with increased latency and security risks, whereas edge computing, such as FPGA-based systems, provides real-time processing with constrained resources. Hybrid and quantum ecosystems further complicate decision-making, requiring careful trade-offs between performance and security. This research seeks to establish a framework for evaluating ML performance and security risks across these ecosystems, forming the foundation of the Computational Performance And Security System (COMPASS) decision-support tool. The study will systematically …
Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive,
2025
University of South Alabama
Development Of An Algorithm To Identify The Presence Of Luks-Encrypted Volumes On A Forensic Image Of A Drive, Nicholas Flynn, Michael Black
Shelby Hall Graduate Research Forum Posters
Current forensic tools struggle to effectively detect encrypted storage media. In recent years, there have been significant advancements, but a noticeable gap remains when it comes to identifying encrypted volumes from metadata alone. The goal of this research is to develop a novel algorithm that will identify the presence of volumes on a disk image which have been encrypted with the Linux Unified Key Setup (LUKS) encryption algorithm, in an effort to aid digital forensics investigations. Bad actors often use encryption as an anti-forensics tool to pose significant challenges to forensic investigators, especially when it is done within sections of …
Preserving Privacy In Senior Care At Home Monitoring Systems,
2025
University of South Alabama
Preserving Privacy In Senior Care At Home Monitoring Systems, Sam Russel, Ryan Benton, Amy Campbell, Scott Sittig
Shelby Hall Graduate Research Forum Posters
Many seniors prefer to live at home which necessitates research into the application of technologies to provide a safer environment with less caregiver resources. However, the application of home health care (HHC) monitoring for seniors is still in an evolutionary stage. Present HHC systems are produced by private companies with general regulatory guidelines lacking specific care of the elderly. As such, each company that produces such a system claims to have better safety, privacy, and security that their competitors. A pressing issues is devising and applying a general framework for the application of technologies that delivers safety while preserving privacy. …
False Narratives, Real Consequences,
2025
University of South Alabama
False Narratives, Real Consequences, Russell W. Cantrell, Matt Campbell
Shelby Hall Graduate Research Forum Posters
Social media is an increasingly significant tool in modern cyber warfare, capable of rapidly shaping public opinion. The swift dissemination of information complicates efforts to distinguish fact from fiction [1]. During public health crises, healthcare professionals use these platforms to share updates, yet their credible content must contend with false or deliberately misleading narratives [2]. This environment creates an opportunity for cyberattacks through social media influence campaigns [3]. While disinformation's role in political interference has been widely studied, its potential to destabilize healthcare remains largely unexplored. Prior research primarily focuses on how vaccine misinformation affects the general public [4]. This …
Detecting Sensor Data Manipulation,
2025
University of South Alabama
Detecting Sensor Data Manipulation, Ricky Green, Michael Black
Shelby Hall Graduate Research Forum Posters
The integration of Information Technology (IT) and Operational Technology (OT) have made OT devices vulnerable to threats that have been successfully exploited with devastating results. Many modern techniques for hardening and securing enterprise IT systems are either incompatible with OT components in an Industrial Control System (ICS), reduce the efficiency of processes, or are prohibitively expensive to implement. Research in the area of ICS security focuses on a top-down approach, such as intrusion prevention by securing the perimeter of the network and hardening computer systems. This approach is useful in business IT systems, but full compatibility with OT components in …
Backdoor Token Unlearning: Exposing And Defending Backdoors In Pretrained Language Models,
2025
Singapore Management University
Backdoor Token Unlearning: Exposing And Defending Backdoors In Pretrained Language Models, Peihai Jiang, Xixiang Lyu, Yige Li, Jing Ma
Research Collection School Of Computing and Information Systems
Supervised fine-tuning has become the predominant method for adapting large pretrained models to downstream tasks. However, recent studies have revealed that these models are vulnerable to backdoor attacks, where even a small number of malicious samples can successfully embed backdoor triggers into the model. While most existing defense methods focus on post-training backdoor defense, efficiently defending against backdoor attacks during training phase remains largely unexplored. To address this gap, we propose a novel defense method called Backdoor Token Unlearning (BTU), which proactively detects and neutralizes trigger tokens during the training stage. Our work is based on two key findings: 1) …
Private Reachability Queries On Structured Encrypted Temporal Bipartite Graphs,
2025
Fujian Normal University
Private Reachability Queries On Structured Encrypted Temporal Bipartite Graphs, Yulin Wu, Lanxiang Chen, Gaolin Chen, Yi Mu, Robert H. Deng
Research Collection School Of Computing and Information Systems
A temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on …
Forward-Secure Hierarchical Delegable Signature For Smart Homes,
2025
Singapore Management University
Forward-Secure Hierarchical Delegable Signature For Smart Homes, Jianfei Sun, Guowen Xu, Yang Yang, Xuehuan Yang, Xiaoguo Li, Cong Wu, Zhen Liu, Guomin Yang, Robert H. Deng
Research Collection School Of Computing and Information Systems
Aiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: (1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; (2) flexible self-sovereign permission delegation; (3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever …
Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities,
2025
Edith Cowan University
Generative Ai And Llms For Critical Infrastructure Protection: Evaluation Benchmarks, Agentic Ai, Challenges, And Opportunities, Yagmur Yigit, Mohamed Amine Ferrag, Mohamed C. Ghanem, Iqbal H. Sarker, Leandros A. Maglaras, Christos Chrysoulas, Naghmeh Moradpoor, Norbert Tihanyi, Helge Janicke
Research outputs 2022 to 2026
Critical National Infrastructures (CNIs)—including energy grids, water systems, transportation networks, and communication frameworks—are essential to modern society yet face escalating cybersecurity threats. This review paper comprehensively analyzes AI-driven approaches for Critical Infrastructure Protection (CIP). We begin by examining the reliability of CNIs and introduce established benchmarks for evaluating Large Language Models (LLMs) within cybersecurity contexts. Next, we explore core cybersecurity issues, focusing on trust, privacy, resilience, and securability in these vital systems. Building on this foundation, we assess the role of Generative AI and LLMs in enhancing CIP and present insights on applying Agentic AI for proactive defense mechanisms. Finally, …
Provable Security In Idealised Models,
2025
Indian Statistical Institute
Provable Security In Idealised Models, Chandranan Dhar
Doctoral Theses
This thesis is a compilation of provable security analyses of various cryptographic constructions in idealised models. The first construction examined is the ABR hash. We revisit the existing proof of the ABR hash in the random oracle model and identify significant errors in the proof. Although we are unable to correct the original proof, we establish the security of the ABR tree of height 3 from scratch, addressing the first non-trivial case. As our second contribution, we conduct a tight and comprehensive security analysis of the Ascon AEAD mode in the random permutation model. We show that the efficiency of …
Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition,
2025
Temple University
Educating Students On The Behavioral And Psychological Aspects Of Romance Scam Victimization Via A Social Engineering Competition, Rachel Bleiman, Hwanhee Park, Aunshul Rege
Journal of Cybersecurity Education, Research and Practice
The online dating industry generated 2.98 billion USD in 2023 and is estimated to reach 3.6 billion USD by 2025. Not surprisingly, online dating platforms are rife with romance scams that cause financial damages, with estimated losses of 1.3 billion USD in 2022 alone. Additionally, victims suffer emotional and psychological harms. This paper shares findings from a 2023 Romance Scam and Social Engineering Competition (RSSEC) that introduced students to the behavioral and psychological aspects of romance scams. Specifically, the competition aimed to expose students to (i) understanding how victims experience social engineering (SE) - the psychological manipulation of human behavior, …
Managing Cybersecurity In Local Governments: 2022,
2025
University of Maryland, Baltimore County (UMBC)
Managing Cybersecurity In Local Governments: 2022, Donald F. Norris Phd, Laura K. Mateczun Jd
Journal of Cybersecurity Education, Research and Practice
This paper, based on data from our second nationwide survey of cybersecurity among local or grassroots governments in the U.S., examines how these governments manage this important function. As we have shown elsewhere, cybersecurity among local governments is increasingly important because these governments are under constant or nearly constant cyberattack. Due to the frequency of cyberattacks, as well as the probability that at least some attacks will succeed and cause damage to local government information systems, these governments have great responsibility to protect their information assets. This, in turn, requires these governments to manage cybersecurity effectively, something our data show …
Artificial Intelligence (Ai) In Pharmacy,
2025
Ohio Northern University
Artificial Intelligence (Ai) In Pharmacy, Giang Nguyen, Elizabeth Sartschev, John Reyes, Allie Honigford, Marisa Petrunich, Kiley Devoll, Brianna Lu, Joshua Honaker, T'Bony M. Jewell
Pharmacy and Wellness Review
Artificial Intelligence (AI) has transformed the pharmaceutical field by enabling computer software systems to learn and perform human behavior. Specifically, AI has revolutionized chronic diabetes management through continuous glucose monitoring, showcasing its immense potential in healthcare. However, alongside its transformative impact, AI’s increasing role in healthcare has prompted concerns over privacy and its premature integration. Despite these challenges, AI offers limitless opportunities to improve medication management and treatment regimens, driving advancements across various domains. From improving CT imaging to enhancing adenoma detection in colonoscopies and facilitating medication adherence, AI’s impact on healthcare is profound. Furthermore, AI plays a pivotal role …
Scrutinizer: Towards Secure Forensics On Compromised Trustzone,
2025
Singapore Management University
Scrutinizer: Towards Secure Forensics On Compromised Trustzone, Yiming Zhang, Fengwei Zhang, Xiapu Luo, Rui Hou, Xuhua Ding, Zhenkai Liang, Shoumeng Yan, Tao We, Zhengyu He
Research Collection School Of Computing and Information Systems
The number of vulnerabilities exploited in Arm TrustZone systems has been increasing recently. The absence of digital forensics tools prevents platform owners from incident response or periodic security scans. However, the area of secure forensics for compromised TrustZone remains unexplored and presents unresolved challenges. Traditional out-of-TrustZone forensics are inherently hindered by TrustZone protection, rendering them infeasible. In-TrustZone approaches are susceptible to attacks from privileged adversaries, undermining their security. To fill these gaps, we introduce SCRUTINIZER, the first secure forensics solution for compromised TrustZone systems. SCRUTINIZER utilizes the highest privilege domain of the recent Arm Confidential Computing Architecture (CCA), called the …
Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning,
2025
Singapore Management University
Qultsf: Long-Term Time Series Forecasting With Quantum Machine Learning, Hari Hara Suthan Chittoor, Paul Robert Griffin, Ariel Neufeld, Jayne Thompson, Mile Gu
Research Collection School Of Computing and Information Systems
Long-term time series forecasting (LTSF) involves predicting a large number of future values of a time series based on the past values. This is an essential task in a wide range of domains including weather forecasting, stock market analysis and disease outbreak prediction. Over the decades LTSF algorithms have transitioned from statistical models to deep learning models like transformer models. Despite the complex architecture of transformer based LTSF models ‘Are Transformers Effective for Time Series Forecasting? (Zeng et al., 2023)’ showed that simple linear models can outperform the state-of-the-art transformer based LTSF models. Recently, quantum machine learning (QML) is evolving …
Siniel: Distributed Privacy-Preserving Zksnark,
2025
Singapore Management University
Siniel: Distributed Privacy-Preserving Zksnark, Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng
Research Collection School Of Computing and Information Systems
Zero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive, in which a prover convinces a verifier that a given statement is true without leaking any additional information. However, existing zkSNARKs suffer from high computation overhead in the proof generation. This limits the applications of zkSNARKs, such as private payments, private smart contracts, and anonymous credentials. Private delegation has become a prominent way to accelerate proof generation. In this work, we propose Siniel, an efficient private delegation framework for zkSNARKs constructed from polynomial interactive oracle proof (PIOP) and polynomial commitment scheme (PCS). Our protocol allows a computationally limited …
Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems,
2025
Singapore Management University
Impact Tracing: Identifying The Culprit Of Misinformation In Encrypted Messaging Systems, Zhongming Wang, Tao Xiang, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma, Robert H. Deng
Research Collection School Of Computing and Information Systems
Encrypted messaging systems obstruct content moderation, although they provide end-to-end security. As a result, misinformation proliferates in these systems, thereby exacerbating online hate and harassment. The paradigm of “Reporting-then-Tracing” shows great potential in mitigating the spread of misinformation. For instance, message traceback (CCS’19) traces all the dissemination paths of a message, while source tracing (CCS’21) traces its originator. However, message traceback lacks privacy preservation for non-influential users (e.g., users who only receive the message once), while source tracing maintains privacy but only provides limited traceability. In this paper, we initiate the study of impact tracing. Intuitively, impact tracing traces influential …
Bgp Anomaly Detection As A Group Dynamics Problem,
2025
Edith Cowan University
Bgp Anomaly Detection As A Group Dynamics Problem, Ben A. Scott, Michael N. Johnstone, Patryk Szewczyk, Steven Richardson
Research outputs 2022 to 2026
Understanding group information and collective behaviors is an ongoing area of research, encompassing natural phenomena and human dynamics. Quantifying interactions and interdependencies at the group level can be valuable for understanding complex and dynamical systems. The Border Gateway Protocol (BGP), the default inter-domain routing protocol for the Internet, operates within a large, complex, and dynamic system vulnerable to security threats. Traditional BGP anomaly detection focuses on single observables from individual Autonomous Systems (ASes), which inadequately addresses the multidimensional, multi-viewpoint nature of the Internet and interdomain routing. This paper introduces a novel approach for quantifying group AS-level information and dynamics. We …
Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments,
2025
Old Dominion University
Bridging The Gap: Understanding And Mitigating Csrf Threats In Service Worker Environments, Sivakanesan Dhanushkanda, Mustafa A. Ibrahim
Graduate Student Government Association Research Conference
Progressive Web Applications (PWAs) are gaining popularity due to their rich features. Service Workers (SWs), one of its integral components, make this possible by providing users with offline functionality, improved performance, and effective caching techniques. SWs act as proxies positioned between the client browser and the web server, capable of intercepting requests and responses. Recent research has revealed that, despite being designed with security in mind, there are ways to circumvent these security precautions and launch various attacks.
Sensitive functions in JavaScript are functions that can introduce security vulnerabilities if not properly coded or validated. These functions can manipulate the …
