Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 3 of 201.

Next-Generation Dns Rpz For Automated Threat Intelligence, Risk-Aware Filtering, And User-Centric Security, Jinu S, Kishore V. Krishnan, Rajarshi Middya, Annasamy Bagubali 2026 Ministry of Electronics and Information Technology

Next-Generation Dns Rpz For Automated Threat Intelligence, Risk-Aware Filtering, And User-Centric Security, Jinu S, Kishore V. Krishnan, Rajarshi Middya, Annasamy Bagubali

Journal of Cybersecurity Education, Research and Practice

The Domain Name System (DNS) remains a critical attack vector exploited by adversaries for command-and-control (C2) communication, data exfiltration, and phishing campaigns. DNS Response Policy Zones (RPZ) have emerged as an effective defense mechanism by enabling the redirection or blocking of queries to malicious domains. However, current RPZ implementations encounter significant challenges related to scalability, adaptability, and user awareness, often resulting in static policies, delayed updates, and a high incidence of false positives. To address these limitations, this paper proposes an enhanced RPZ framework that integrates adaptive threat intelligence, machine learning-driven dynamic policy updates, and user-context-aware security controls. The proposed …


A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath 2026 Dakota State University

A Systematic Review Of Intrusion Detection Systems For Internet Of Medical Things: Performance, Efficiency, Explainability, And Generalization, Oswald Adohinzin, Youssef Harrath

Research & Publications

The Internet of Medical Things (IoMT) has transformed health care delivery through medical devices, remote patient monitoring, and real-time clinical decision support. However, the proliferation of IoMT devices introduces security vulnerabilities that put patient safety and data privacy at risk. Intrusion Detection Systems (IDS) have emerged as essential components for protecting IoMT networks from cyberattacks. This article presents a systematic review of IoMT-IDS research, analyzing 53 high-quality papers published between 2020 and 2025, identified through database searches spanning 2016–2025 across IEEE Xplore, Springer, ScienceDirect, and ACM Digital Library. We organize the literature through a comprehensive taxonomy spanning classical machine learning …


2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus 2026 ISTS

2026 Cyber-Resilient Health Care Workshop Report, Malcolm Schongalla, Sergey Bratus

Computer Science Technical Reports

The ISTS and the Dartmouth College Cybersecurity Cluster hosted the successful, inaugural Cyber-Resilient Health Care (CRHC) Workshop, March 5th & 6th, 2026. The event theme was "Innovation and Implementation," in response to the need to shift from reactive to proactive resiliency measures in the healthcare sector. Approximately 30 experts in clinical health care, cybersecurity, medical technology, policy, and innovation met to discuss solution-focused innovations addressing hard, cyber-related problems in health care. The agenda featured keynotes, an expert panel, innovation pitches, small group discussions, and a tabletop infrastructure disaster exercise. Participants gained insights into the obstacles and solutions involved in supporting …


The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala 2026 CUNY John Jay College

The Security Of Llm-Generated Code, Christopher Brian Gonzalez Ayala

Student Theses

The rapid adoption of Large Language Models (LLMs) in software development has transformed coding practices by enabling automated code generation, completion, and optimization. Despite these advantages, concerns persist regarding the security and reliability of LLM-generated code. This study presents a comprehensive evaluation of both the functional correctness and security of code produced by three prominent LLMs as of early 2026. A total of 4,800 code snippets were generated using 100 security-focused programming prompts derived from the OWASP Top 10:2025, translated across eight natural languages and two phrasing styles (literal and natural developer-oriented prompts). To assess performance, a multi-stage experimental framework …


Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy 2026 CUNY John Jay College

Adversarial Robustness Of Perceptual Hashing Systems: A Unified Security Evaluation Framework, Avijit Roy

Student Theses

Social network platforms, child safety organizations, and image provenance systems use perceptual hashing to identify known child sexual abuse material (CSAM), support content moderation and reverse image search, and verify image integrity. Perceptual hashing works by producing similar fingerprints for visually similar images, even after common transformations such as compression, resizing, or minor brightness changes. This useful similarity-preserving property also creates an adversarial attack surface, as attackers can use AI-assisted or conventional image manipulation techniques to move a hash across a matching threshold while maintaining visual similarity, often without access to specialized hardware.

The security failures produced by adversarial attacks …


Sok: Understanding Zkvm: From Research To Practice, Guomin YANG, Yunbo YANG, Yuejia CHENG, Haibo TANG, Bingsheng ZHANG, Kui REN 2026 Singapore Management University

Sok: Understanding Zkvm: From Research To Practice, Guomin Yang, Yunbo Yang, Yuejia Cheng, Haibo Tang, Bingsheng Zhang, Kui Ren

Research Collection School Of Computing and Information Systems

Zero-knowledge virtual machine (zkVM) is a powerful infrastructure for proving the correctness of a program execution with a succinct proof, attracting significant interest from researchers, developers, and users. It has been widely used in applications such as blockchain rollups, privacy-preserving machine learning, and off-chain computation. As the field grows, a wide range of zkVMs have been proposed. However, they adopt different choices in instruction formats, trace layouts, and proving backends, which results in a highly heterogeneous design landscape and makes it difficult to understand the relations among these systems.To bridge this gap, we provide a comprehensive study of zkVMs that …


From 5g To 6g: A Survey On Security, Privacy, And Standardization Pathways, Mengmeng Yang, Youyang Qu, Thilina Ranbaduge, Chandra Thapa, Nazatul Haque Sultan, Ming Ding, Hajime Suzuki, Wei Ni, Sharif Abuadbba, David Smith, Paul Tyler, Josef Pieprzyk, Thierry Rakotoarivelo, Xinlong Guan, Sirine Mrabet 2026 Edith Cowan University

From 5g To 6g: A Survey On Security, Privacy, And Standardization Pathways, Mengmeng Yang, Youyang Qu, Thilina Ranbaduge, Chandra Thapa, Nazatul Haque Sultan, Ming Ding, Hajime Suzuki, Wei Ni, Sharif Abuadbba, David Smith, Paul Tyler, Josef Pieprzyk, Thierry Rakotoarivelo, Xinlong Guan, Sirine Mrabet

Research outputs 2022 to 2026

The vision for 6G aims to enhance network capabilities, supporting an intelligent digital ecosystem where artificial intelligence (AI) is a key. However, the expansion of 6G raises critical security and privacy concerns due to the increased integration of IoT devices, edge computing, and AI. This survey provides a comprehensive overview of 6G protocols with a focus on security and privacy, identifying risks that have not been experienced in preceding 5G systems, and presenting mitigation strategies. While many vulnerabilities from earlier generations persist, the introduction of AI/ML introduces novel risks like model inversion and malicious manipulation of AI. Vulnerabilities in emerging …


Anonymity And Accountability In Secure Messaging, Erin Kenney 2026 New Jersey Institute of Technology

Anonymity And Accountability In Secure Messaging, Erin Kenney

Dissertations

Encypted messaging has become more and more prevalent as time moves on, and its benefits in assuring privacy cannot be overstated, but it also brings along with it concerns on how to moderate platforms where all messages are hidden. Message Franking, followed by Traceback systems, addressed these concerns by allowing the sender of a message to be proven when reported, even for forwarded messages in the case of Traceback, however these systems damage the privacy guarantees that originally motivated encrypted messaging to begin with.

In practice, even without those concerns encrypted messaging alone is not enough to prevent the most …


A Govsecops-Oriented Governance, Risk, And Compliance Platform For Continuous Authorization In Dod Il4/Il5 Environments, Anand Janjal 2026 CyberSecurity Subject Matter Expert

A Govsecops-Oriented Governance, Risk, And Compliance Platform For Continuous Authorization In Dod Il4/Il5 Environments, Anand Janjal

Journal of Cybersecurity Education, Research and Practice

Department of Defense (DoD) Impact Level 4 and Impact Level 5 (IL4/IL5) systems require continuous assurance of cybersecurity posture under stringent operational and regulatory constraints. While the NIST Risk Management Framework (RMF) and DoD DevSecOps guidance emphasize continuous authorization supported by real-time evidence, many existing Governance, Risk, and Compliance (GRC) platforms remain documentation-centric and insufficiently integrated with operational telemetry. This paper presents a GovSecOps-oriented GRC architecture that integrates vulnerability ingestion, automated Plan of Action and Milestones (POA&M) lifecycle management, dynamic risk scoring, and continuous authorization dashboards within IL4/IL5 environments. Using a Design Science Research methodology, the study develops and evaluates …


Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder 2026 Embry-Riddle Aeronautical University

Security Assessment Of A Machine Learning Approach To Generate And Validate Digital Signatures, Juan Ortiz Couder

Doctoral Dissertations and Master's Theses

Cybersecurity has become a global concern as cyber-attacks have become more common, and the cost of the damage caused by them continues to increase. There are several approaches to improve the cyber security of systems such as Digital Signatures, hashing, watermarking, and encryption among others. Digital Signatures are a cryptographic technique used to verify the authenticity and integrity of digital messages or documents. Digital Signatures use a combination of hashing and public-private key encryption to verify the authenticity and integrity of videos, just as they are used for documents and messages. As a result of using a combination of other …


Research On Smart Intelligence Service System Of National Defense Science And Technology In Complex Information Environment, Yang YANG, Keping WANG, Huawei SUN 2026 NARI Technology Company Limited, Nanjing 211106

Research On Smart Intelligence Service System Of National Defense Science And Technology In Complex Information Environment, Yang Yang, Keping Wang, Huawei Sun

Journal of Scientific Information Research

[Purpose/significance] National defense science and technology intelligence serves as a powerful guarantee for promoting national defense science and techndogy innovation and development. Exploring optimization paths for defense science and technology intelligence service systems holds practical significance in developing new quality combat capabilities and safeguarding national security and stability. [Method/process] Through literature review and summarization, this study clarifies the impact of complex information environments on intelligent defense science and technology intelligence services, as well as the core tasks of intelligent intelligence services. Based on activity theory, the study deconstructs system elements and employs systems engineering principles to construct an intelligent defense …


Benchmarking Gaslighting Attacks Against Speech Large Language Models, Jinyang WU, Bin ZHU, Xiandong ZOU, Qiquan ZHANG 2026 Singapore Management University

Benchmarking Gaslighting Attacks Against Speech Large Language Models, Jinyang Wu, Bin Zhu, Xiandong Zou, Qiquan Zhang

PhD Student’s Publications Collection

As Speech Large Language Models (Speech LLMs) become increasingly integrated into voice-based applications, ensuring their robustness against manipulative or adversarial input becomes critical. Although prior work has studied adversarial attacks in text-based LLMs and vision-language models, the unique cognitive and perceptual challenges of speech-based interaction remain underexplored. In contrast, speech presents inherent ambiguity, continuity, and perceptual diversity, which make adversarial attacks more difficult to detect. In this paper, we introduce gaslighting attacks, strategically crafted prompts designed to mislead, override, or distort model reasoning as a means to evaluate the vulnerability of Speech LLMs. Specifically, we construct five manipulation strategies: Anger, …


Post-Quantum Cryptography Encryption Implementation For Messaging App, Callum S. Ward 2026 University of Nebraska at Omaha

Post-Quantum Cryptography Encryption Implementation For Messaging App, Callum S. Ward

Theses/Capstones/Creative Projects

This paper and complementary capstone project aim to explore the state of post-quantum cryptography today by defining the algorithms with which quantum computers can decipher modern asymmetric cryptographic algorithms in exponentially accelerated time, exploring national standards body NIST’s recommendations to circumvent these weaknesses with post-quantum solutions, and implementing recommended algorithms in my group’s project for the UNO Computer Science Capstone course, LockTalk. After having decided on ML-KEM for quantum-resistant asymmetric key transfer and AES-256 for symmetric message encryption and decryption, I was able to cryptographically encode messages to obscure their plaintext values from communication interceptions without any discernible increase in …


Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection, Brendan J. Farrell 2026 University of Nebraska at Omaha

Blockchain Message Integrity For Messaging App: Python-Based Implementation Of Blockchain-Backed Verification And Tamper Detection, Brendan J. Farrell

Theses/Capstones/Creative Projects

With the rapid development and use of digital communication, the need for maintaining the integrity and authenticity of transmitted information becomes more pressing than ever.  However, existing methods of data exchange have several flaws and drawbacks such as reliance on centralized networks which are subject to manipulation, modifications, and potential failures.  Thus, the current project offers an innovative approach to improving the integrity and detection capabilities of messages in real-time communication platforms using the power of blockchain technology.  The proposed solution uses the inherent features of blockchain-based systems to ensure secure and safe message transmission.


Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen 2026 Liberty University

Know Thy Enemy: Building A Command-And-Control Solution For Adversarial Emulation, Caleb J. Chen

Senior Honors Theses

Command and Control (C2) is a critical part of any cyberattack. It serves many purposes, including Distributed Denial of Service (DDoS) attacks, data exfiltration, and malware deployment. Consequently, C2 frameworks play an important part in red team engagements and adversary emulation. However, many adversary emulation solutions focus on comprehensive testing through sequential technique execution instead of realistic chained and automated attacks. The proposed solution is Centurion, an open-source C2 framework that integrates MITRE's ATT&CK framework and several cybersecurity tools into modular playbooks for effective threat emulation. This paper provides background by defining key terms and concepts before delving into a …


Securing Cloud-Native Systems: From Vulnerability Analysis To External And Insider Threat Detection, Jiongchi YU 2026 Singapore Management University

Securing Cloud-Native Systems: From Vulnerability Analysis To External And Insider Threat Detection, Jiongchi Yu

Dissertations and Theses Collection (Open Access)

Cloud-native systems have become the backbone of modern software infrastructure. However, their dynamic resource orchestration and complex configurability introduce a large attack surface and intricate security challenges. Adversaries can externally exploit vulnerabilities in cloud components or perform insider movement within cloud environments to launch attacks. As these systems increasingly support critical services, security breaches can lead to severe operational and economic consequences.

Despite extensive efforts in vulnerability detection and attack monitoring, existing approaches struggle to remain effective in cloud-native environments characterized by rapid evolution and inherent heterogeneity. In particular, they exhibit three fundamental limitations: (1) Insufficient understanding of defect patterns …


Post-Vote Tampering In Nigerian Elections And The Role Of Blockchain-Enabled Electoral Systems, Ransome Chukwubuikem Enechukwu 2026 East Tennessee State University

Post-Vote Tampering In Nigerian Elections And The Role Of Blockchain-Enabled Electoral Systems, Ransome Chukwubuikem Enechukwu

Electronic Theses and Dissertations

Post-vote tampering during the collation and transmission of election results remains a persistent challenge in Nigerian elections, enabling manipulation of already-cast votes and weakening public trust in electoral outcomes. Existing technological interventions, including biometric voter accreditation and digital result transmission systems, improve voter authentication but do not adequately secure the post-vote result collation process. This thesis proposes a blockchain-enabled framework designed to protect the integrity of election results during the collation and transmission stages. Using a Design Science Research methodology, the study develops a permissioned blockchain framework based on Hyperledger Fabric that records polling-unit results as immutable ledger entries and …


Federated Neuromorphic Intelligence: Advancing Robustness, Efficiency, And Continual Adaptation In Edge Environments, Manh V. Nguyen 2026 Kennesaw State University

Federated Neuromorphic Intelligence: Advancing Robustness, Efficiency, And Continual Adaptation In Edge Environments, Manh V. Nguyen

Dissertations

This dissertation investigates how spiking neural networks (SNNs) can improve federated edge intelligence by advancing three interconnected goals: communication efficiency, adversarial robustness, and continual adaptation. As edge computing deployments expand across Internet of Things (IoT), sensing, and privacy-sensitive applications, conventional federated learning approaches built around artificial neural networks (ANNs) face growing limitations in power consumption, bandwidth demand, and resilience to real-world uncertainty. SNNs offer an alternative computational paradigm based on event-driven, sparse, and temporally structured processing that is naturally suited to constrained edge environments. However, their behavior in practical federated settings remains insufficiently understood.

To address this gap, this dissertation …


Sevoauth: Secure Voiceprint Authentication With Hash-Based Feature Transformation, Rui ZHANG, Zheng YAN, Robert H. DENG 2026 Singapore Management University

Sevoauth: Secure Voiceprint Authentication With Hash-Based Feature Transformation, Rui Zhang, Zheng Yan, Robert H. Deng

Research Collection School Of Computing and Information Systems

While voiceprint authentication offers convenient user authentication and access control through voice feature recognition, a critical research gap remains: existing voiceprint authentication systems fail to simultaneously achieve sound security against replay, spoofing, and adversarial attacks, preserve voice privacy leakage, and satisfy usability demand. Previous efforts have struggled to balance these issues comprehensively. To bridge this gap, we present SeVoAuth, a cloud-based Voiceprint Authentication as a Service (VAaaS) system designed to provide privacy preservation, robust security, and enhanced usability. SeVoAuth stores a synthesized voiceprint of a user in the cloud during user registration, thereby safeguarding the privacy of the real voiceprint …


A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott 2026 Edith Cowan University

A Survey Of Privacy-Preserving Federated Learning For Intrusion Detection Systems, Thomas Bunko, Michael N. Johnstone, Wencheng Yang, Ben A. Scott

Research outputs 2022 to 2026

Intrusion detection systems (IDS) monitor and detect malicious activity and unauthorized access that may compromise systems. Traditional IDS approaches send data to a central server for analysis, raising privacy concerns as data owners lose control over security. Federated Learning (FL) offers a privacy-preserving alternative by allowing local devices to process their data and generate models without sharing raw data. These local models are aggregated centrally to form a comprehensive model with performance comparable to centralized systems. This paper reviews FL-based IDS research, and is the first review paper to focus on privacy-preserving techniques collectively known as privacy-preserving Federated Learning (PPFL) …


Digital Commons powered by bepress