From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms,
2026
Edith Cowan University
From Oversight To Insight: Transforming Cybersecurity Governance In Boardrooms, Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke
Research outputs 2022 to 2026
Cybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors' knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board …
Fully Decentralized Hierarchical Federated Learning At The Edge With Post-Quantum Secure Communication,
2026
United Arab Emirates University
Fully Decentralized Hierarchical Federated Learning At The Edge With Post-Quantum Secure Communication, Tariq Qayyum
Thesis/ Dissertation Defenses
Federated learning (FL) enables collaborative model training without centralizing raw data, but deploying FL at scale in real edge environments remains challenging because iterative training and aggregation must operate over heterogeneous, resource-constrained, and often mobile devices with time-varying connectivity. Conventional hierarchical federated learning (HFL) partially mitigates communication cost by introducing fog/edge aggregation, yet many designs retain cloud-based global aggregation and cloud-centric coordination. This places wide-area network latency on the critical path of every training round, creates a single point of failure, and limits responsiveness as model sizes and federation scale grow. Moreover, moving coordination and aggregation closer to the edge …
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*,
2026
Southern Adventist University
A Strategic Roadmap For Assessing And Educating On Personal Cybersecurity Practices In Universities*, Ryan Lopez, Ysani Peña
Campus Research Month
Universities face a common cybersecurity threat: their own users. Although organizations may meet compliance standards and implement robust security infrastructures, the individual user remains the weakest link. This is particularly evident in higher education institutions, where both students and employees are frequent targets of cyber threats due to a lack of cybersecurity awareness. This paper proposes a strategic roadmap for assessing university student bodies and employee populations through cybersecurity domains that directly affect personal cyber hygiene awareness and practice.
Our proposed roadmap was validated in a U.S. university by using a domain-focused survey and simulated phishing campaigns. After the identification …
Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks,
2026
University of Arizona
Adopting Artificial Intelligence: Cross-Sector Analysis Of Ai Adoption Risks, Brandon Saari, Yona Berger, Yanett Munoz, Alex Agnick, Paul Wagner, Robert J. Honomichl
Journal of Cybersecurity Education, Research and Practice
Artificial intelligence (AI) is rapidly being adopted across public and private sectors. This offers significant gains in efficiency, decision making, and access to information. At the same time, AI introduces complex risks related to cybersecurity, privacy, bias, transparency, accountability, and equity that existing governance and security frameworks do not fully address. This paper presents a cross-sector literature review and comparative analysis of AI adoption risks and mitigation strategies across four critical domains: the federal government, libraries, K–12 education, and healthcare. Drawing on peer-reviewed research, institutional frameworks, and policy guidance, the study identifies sector-specific challenges alongside shared systemic gaps, including insufficient …
Innovations And Applications Of Virtual Private Networks And Sustainable Security In Society 5.0 Libraries,
2026
University of Lagos, Nigeria
Innovations And Applications Of Virtual Private Networks And Sustainable Security In Society 5.0 Libraries, Stella Chinnaya Nduka Dr., Adeyinka Tella Prof, Petros Dlamini Dr
Journal of Cybersecurity Education, Research and Practice
In order to improve digital resilience, privacy, and access equity in contemporary library environments, this study investigates the role of Virtual Private Networks (VPNs) in fostering sustainable cybersecurity within the framework of Society 5.0 libraries. It does this by looking at the latest developments, applications, difficulties, moral dilemmas, and tactical methods associated with VPN deployment. Using peer-reviewed journal articles, conference proceedings, white papers, and policy documents published between 2010 and 2024, a methodical approach to literature review was used. The literature that bridges the fields of cybersecurity, library science, and Society 5.0 concepts was the main focus of the review. …
Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs,
2026
University of Arkansas Little Rock
Bridging The Cybersecurity Education Gap: The Role Of Open Educational Resources In Supporting Rural Cybersecurity Programs, Brittni Hardie
Theses and Dissertations
This study examines the intersection of cybersecurity education, open educational resources (OER), and rural higher education through a systematic review of current literature and an exploratory survey of rural community college faculty. The purpose of this research, consistent with the approved Institutional Review Board (IRB) protocol, was to understand how OER can be leveraged to design and deliver an affordable, high-quality System Security course within a rural higher-education environment. As cybersecurity workforce shortages continue to grow across the United States, rural institutions face persistent challenges in sustaining high-quality programs due to financial constraints, limited faculty capacity, and rapidly evolving curriculum …
Llmqua: Practical Backdoor Injection On Large Language Model Quantization,
2026
Singapore Management University
Llmqua: Practical Backdoor Injection On Large Language Model Quantization, Xiangxiang Chen, Peixin Zhang, Jun Sun, Jin Song Dong, Wenhai Wang, Jingyi Wang
Research Collection School Of Computing and Information Systems
Quantization is widely used to enable local deployment of large language models (LLMs) on resource-constrained devices. Recent work (e.g., QuRA) shows quantization can be exploited via rounding manipulation to implant backdoors. However, such an attack has been evaluated only on small models and does not directly apply to LLMs due to three key constraints: (1) limited poisoning data from small, task-agnostic calibration sets; (2) layer-wise quantization restricting adversarial access to global representations; and (3) lack of gradient access in quantization pipelines, blocking gradient-based attacks.We propose LLMQuA, a practical quantization-phase backdoor attack tailored to the LLM setting. LLMQuA (i) injects backdoors …
A.I.R.E. - Ai-Assisted Reverse Engineering,
2026
St. Mary's University
A.I.R.E. - Ai-Assisted Reverse Engineering, Laurene Robinson
Posters - 2026
Reverse engineering plays a vital role in cybersecurity by helping analysts examine unknown binaries, investigate malware, identify vulnerabilities, and better protect sensitive systems. However, once a program is compiled and stripped, the meaningful names that describe its behavior are lost, leaving behind generic function labels like FUN_00401a30. Analysts must then manually interpret decompiled code, trace call chains, and infer program behavior function by function, which is slow and mentally demanding on large binaries. To address this challenge, this project introduces A.I.R.E., a local Ghidra extension that extracts contextual evidence from stripped functions and uses a locally hosted language model to …
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance,
2026
Pepperdine University
Next-Generation Democratic Cyber Statecraft - Balancing The Signal: Shutdown Shocks And Democratic Digital Governance, Scott M. Di Panni
School of Public Policy Capstones
This paper develops Next-Generation Democratic Cyber Statecraft (NG-DCS), a unified strategic doctrine for democratic governments to contest the cognitive domain against authoritarian adversaries. Drawing on twenty-six years of cross-national panel data (1999–2024) spanning 213 countries, game-theoretic modeling, and qualitative case analysis, the paper establishes three interconnected empirical and theoretical foundations. First, cross-national OLS regression across 160+ countries demonstrates that regime type is the dominant structural determinant of internet freedom (R²=0.615, β=2.513, p< 0.001), explaining more than twice the variance attributable to per-capita wealth (R²=0.268). Democratic governance, not economic development, produces open digital environments. Second, a two-way fixed effects (TWFE) difference-in-differences study exploiting government-ordered internet shutdowns as discrete policy interventions finds that digital restrictions causally degrade V-Dem governance quality by 0.21–0.38 standard deviations (p< 0.001 across all specifications). Treatment effects are immediate (β=−0.302 at k=0) and persist through five post-treatment years (β=−0.246 at k=+5), indicating structural rather than transitory governance damage. Parallel trends validation (p=0.352) and Callaway–Sant’Anna heterogeneity-robust estimation (ATT=−0.230, SE=0.077) support causal identification. Instrumental variable triangulation (2SLS β=−0.949, p=0.005) confirms that simultaneity was attenuating, not inflating, the primary estimates. Third, formal game-theoretic analysis reveals that the current U.S.–adversary equilibrium is (Restrain, Escalate)—the risk-dominant but Pareto-inferior outcome of a Stag Hunt structure. China, Russia, North Korea, and Venezuela each occupy structurally distinct positions (Stackelberg commitment, asymmetric two-level, autarky, and reactive trigger, respectively), requiring differentiated doctrinal responses rather than a uniform strategic playbook. Generative AI and algorithmic governance are shown to accelerate cognitive vulnerability by collapsing influence operation costs and exploiting engagement-optimized platform architectures that systematically degrade deliberative capacity in democratic populations.
Propaganda Ai: An Analysis Of Semantic Divergence In Large Language Models,
2026
Singapore Management University
Propaganda Ai: An Analysis Of Semantic Divergence In Large Language Models, Nay Myat Min, Long H. Pham, Yige Li, Jun Sun
Research Collection School Of Computing and Information Systems
Large language models (LLMs) can exhibit concept-conditioned semantic divergence: common high-level cues (e.g., ideologies, public figures) elicit unusually uniform, stance-like responses that evade token-trigger audits. This behavior falls in a blind spot of current safety evaluations, yet carries major societal stakes, as such concept cues can steer content exposure at scale. We formalize this phenomenon and present RAVEN (Response Anomaly Vigilance), a black-box audit that flags cases where a model is simultaneously highly certain and atypical among peers by coupling semantic entropy over paraphrastic samples with cross-model disagreement. In a controlled LoRA fine-tuning study, we implant a concept-conditioned stance using …
Trace: Securing Smart Contract Repository Against Access Control Vulnerability,
2026
Singapore Management University
Trace: Securing Smart Contract Repository Against Access Control Vulnerability, Chong Chen, Lingfeng Bao, David Lo, Yanlin Wang, Zhenyu Shan, Ting Chen, Guangqiang Yin, Jianxing Yu, Zibin Zheng, Jiachi Chen
Research Collection School Of Computing and Information Systems
Smart contract vulnerabilities have led to billions of dollars in economic losses. Among these, improper Access Control, which allows unauthorized users to execute restricted functions, is particularly prevalent and has caused significant financial damage. Smart contract repositories contain source code, documentation, configuration files, and other artifacts necessary for building and deploying smart contracts. GitHub hosts numerous open-source repositories of this kind, which serve as intermediate artifacts in development and require compilation and packaging to produce deployable contracts. Third-party developers often reference, reuse, or fork code from these repositories during custom development. However, if the referenced code contains vulnerabilities, it can …
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks,
2026
Old Dominion University
The Psychology Behind Ai-Generated Phishing And Social Engineering Attacks, A’Shya Reynolds
School of Cybersecurity Master's Level Projects and Papers
Cybercrime has evolved significantly with the integration of artificial intelligence (AI), transforming traditional phishing and social engineering attacks into highly sophisticated and personalized threats. While early phishing attempts relied on generic messaging and low success rates, modern AI-driven attacks leverage advanced data analytics, natural language processing, and behavioral prediction to manipulate victims more effectively.
This research examines how cybercriminals utilize AI to enhance psychological manipulation techniques in phishing and social engineering attacks, increasing victim susceptibility. Drawing from interdisciplinary literature in cybersecurity and psychology, this study explores key psychological mechanisms, including cognitive biases, emotional triggers, and decision-making processes that influence victim …
Hypersiniel: Guaranteed Output Delivery Comes (Almost) Free In Private Delegation Of Zksnarks,
2026
Singapore Management University
Hypersiniel: Guaranteed Output Delivery Comes (Almost) Free In Private Delegation Of Zksnarks, Yunbo Yang, Yuejia Cheng, Junkai Liang, Kailun Wang, Xuanming Liu, Xiaoguo Li, Jianfei Sun, Jiachen Shen, Xiaolei Dong, Zhenfu Cao, Meng Hao, Guomin Yang, Deng, Robert H., Kui Ren
Research Collection School Of Computing and Information Systems
Zero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive that enables a prover to convince a verifier that something is true without leaking the private witness.Current zkSNARKs face significant computational costs in generating proofs, which restricts their use in areas like private payments, confidential smart contracts, and anonymous credentials. Private delegation offers a practical solution by outsourcing the heavy computation to powerful external workers without leaking any private information. In this work, we propose HyperSiniel, an efficient private delegation framework for general zkSNARKs that achieves a new feature called guaranteed output delivery (GOD). HyperSiniel is designed to …
Penforge: On-The-Fly Expert Agent Construction For Automated Penetration Testing,
2026
Singapore Management University
Penforge: On-The-Fly Expert Agent Construction For Automated Penetration Testing, Huihui Huang, Jieke Shi, Junkai Chen, Ting Zhang, Yikun Li, Chengran Yang, Eng Lieh Ouh, Lwin Khin Shar, David Lo
Research Collection School Of Computing and Information Systems
Penetration testing is essential for identifying vulnerabilities in web applications before real adversaries can exploit them. Recent work has explored automating this process with Large Language Model (LLM)-powered agents, but existing approaches either rely on a single generic agent that struggles in complex scenarios or narrowly specialized agents that cannot adapt to diverse vulnerability types. We therefore introduce PenForge, a framework that dynamically constructs expert agents during testing rather than relying on those prepared beforehand. By integrating automated reconnaissance of potential attack surfaces with agents instantiated on the fly for context-aware exploitation, PenForge achieves a 30.0% exploit success rate (12/40) …
Where Did It Go Wrong? Attributing Undesirable Llm Behaviors Via Representation Gradient Tracing,
2026
Singapore Management University
Where Did It Go Wrong? Attributing Undesirable Llm Behaviors Via Representation Gradient Tracing, Zhe Li, Wei Zhao, Yige Li, Jun Sun
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have demonstrated remarkable capabilities, yet their deployment is frequently undermined by undesirable behaviors such as generating harmful content, factual inaccuracies, and societal biases. Diagnosing the root causes of these failures poses a critical challenge for AI safety. Existing attribution methods, particularly those based on parameter gradients, often fall short due to prohibitive noisy signals and computational complexity. In this work, we introduce a novel and efficient framework that diagnoses a range of undesirable LLM behaviors by analyzing representation and its gradients, which operates directly in the model's activation space to provide a semantically meaningful signal linking …
Be Responsible In Your Answers! Monitoring Out-Of-Domain Behaviors In Domain-Specific Llms,
2026
Singapore Management University
Be Responsible In Your Answers! Monitoring Out-Of-Domain Behaviors In Domain-Specific Llms, Boquan Li, Chenzhe Lou, Zhe Ren, Peixin Zhang, Zirui Fu, Jun Sun, Yaowen Zheng
Research Collection School Of Computing and Information Systems
Large Language Models (LLMs) have accelerated the rapid development of chatbot web applications in various domains, such as coding, biomedicine and psychology. Compared to general LLMs like ChatGPT, domain-specific LLMs require a greater sense of responsibility. For instance, if a programming LLM casually answers medical or psychological questions, it not only misleads the public but also poses legal risks. This highlights new demands for monitoring and preventing such irresponsible behaviors. Existing efforts attempt to monitor LLMs from multiple aspects, such as lying, jailbreaks, and toxic content, while overlooking out-of-domain behaviors. In this work, we propose an innovative LLM domain monitoring …
Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review,
2026
Edith Cowan University
Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni
Research outputs 2022 to 2026
Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes …
Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study,
2026
Oxford Brookes University
Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study, Manny Niri Dr.
Journal of Cybersecurity Education, Research and Practice
This study employs a design-based research (DBR) framework to examine the impact of a comprehensive curriculum redesign in an introductory Foundations of Security module for undergraduate students in computing and cybersecurity at a UK public university between 2019 and 2025. The redesign aimed to enhance student learning, engagement, and critical thinking through the embodiment of evidence-based pedagogical strategies, including flipped classroom delivery, blended learning, gamified practical exercises, repeated low-stakes mock assessments, and structured problem-solving activities. Student feedback, assessment outcomes, attendance records, and faculty reflections were analysed to evaluate the effectiveness of the redesign. The results indicate substantial improvements in student …
Large-Scale File Fragment Classification Via Multi-View Learning,
2026
Louisiana State University and Agricultural and Mechanical College
Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand
LSU Master's Theses
File reassembly is one of the most fundamental tasks in digital forensics, enabling recovery of data from potentially damaged storage media even when file system metadata is unavailable. This thesis reviews more than two decades of work in the realm of file carving, with a particular focus on fragmented file carving, which remains a focus of research, and file fragment classification, a principal component of fragmented file carving. This thesis serves a literature review of both file carving and fragmented file carving, surveys the massive amounts of data needed for the task of fragment classification and the datasets that serve …
Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs,
2026
Department of School Education, Government of Uttarakhand - India
Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs, Dr Atul Bamrara, Partha Roy, Vishwanath Gargote, Khandu Thungon
Journal of Cybersecurity Education, Research and Practice
Human error remains the most frequently exploited vulnerability in the cyber-security ecosystem. Despite substantial investments in technical safeguards, cybercriminals increasingly rely on social engineering, misinformation, and emotionally manipulative tactics to compromise users. This study examines behavioral changes among participants who underwent structured cyber-security workshops addressing both conventional cyber hygiene practices and emerging digital threats. The training modules covered digital arrest scams, identity theft, sextortion, fake technical support fraud, fake social media profiles, online gaming related risks, and deep fake manipulation. The workshops were designed using interactive simulations, real world case studies, and hands on problem based exercises, with the explicit …
