Open Access. Powered by Scholars. Published by Universities.®

Information Security Commons™

Open Access. Powered by Scholars. Published by Universities.®

4,669 Full-Text Articles 6,837 Authors 4,560,043 Downloads 178 Institutions

All Articles in Information Security

Faceted Search

4,669 full-text articles. Page 5 of 201.

Llmqua: Practical Backdoor Injection On Large Language Model Quantization, Xiangxiang CHEN, Peixin ZHANG, Jun SUN, Jin Song DONG, Wenhai WANG, Jingyi WANG 2026 Singapore Management University

Llmqua: Practical Backdoor Injection On Large Language Model Quantization, Xiangxiang Chen, Peixin Zhang, Jun Sun, Jin Song Dong, Wenhai Wang, Jingyi Wang

Research Collection School Of Computing and Information Systems

Quantization is widely used to enable local deployment of large language models (LLMs) on resource-constrained devices. Recent work (e.g., QuRA) shows quantization can be exploited via rounding manipulation to implant backdoors. However, such an attack has been evaluated only on small models and does not directly apply to LLMs due to three key constraints: (1) limited poisoning data from small, task-agnostic calibration sets; (2) layer-wise quantization restricting adversarial access to global representations; and (3) lack of gradient access in quantization pipelines, blocking gradient-based attacks.We propose LLMQuA, a practical quantization-phase backdoor attack tailored to the LLM setting. LLMQuA (i) injects backdoors …


Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni 2026 Edith Cowan University

Federated Retrieval-Augmented Generation For Cybersecurity In Resource-Constrained Iot And Edge Environments: A Deployment-Oriented Scoping Review, Hangyu He, Yuan, Kai Wu, Wei Ni

Research outputs 2022 to 2026

Cybersecurity operations in IoT and edge environments require fast, evidence-grounded decisions under strict resource and trust constraints. While large language models can support triage and incident analysis, their parametric knowledge may be outdated and prone to hallucination. Retrieval-augmented generation (RAG) improves grounding by conditioning responses on retrieved evidence, but also introduces new risks such as knowledge-base poisoning, indirect prompt injection, and embedding leakage. Federated learning enables collaborative adaptation without centralizing sensitive data, motivating federated RAG (FedRAG) architectures for distributed cybersecurity deployments. This study presents a deployment-oriented scoping review of FedRAG for cybersecurity. The review follows PRISMA-ScR reporting guidance and synthesizes …


Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study, Manny Niri Dr. 2026 Oxford Brookes University

Enhancing Introductory Cybersecurity Learning: A Design-Based Research Case Study, Manny Niri Dr.

Journal of Cybersecurity Education, Research and Practice

This study employs a design-based research (DBR) framework to examine the impact of a comprehensive curriculum redesign in an introductory Foundations of Security module for undergraduate students in computing and cybersecurity at a UK public university between 2019 and 2025. The redesign aimed to enhance student learning, engagement, and critical thinking through the embodiment of evidence-based pedagogical strategies, including flipped classroom delivery, blended learning, gamified practical exercises, repeated low-stakes mock assessments, and structured problem-solving activities. Student feedback, assessment outcomes, attendance records, and faculty reflections were analysed to evaluate the effectiveness of the redesign. The results indicate substantial improvements in student …


Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand 2026 Louisiana State University and Agricultural and Mechanical College

Large-Scale File Fragment Classification Via Multi-View Learning, Samuel Hildebrand

LSU Master's Theses

File reassembly is one of the most fundamental tasks in digital forensics, enabling recovery of data from potentially damaged storage media even when file system metadata is unavailable. This thesis reviews more than two decades of work in the realm of file carving, with a particular focus on fragmented file carving, which remains a focus of research, and file fragment classification, a principal component of fragmented file carving. This thesis serves a literature review of both file carving and fragmented file carving, surveys the massive amounts of data needed for the task of fragment classification and the datasets that serve …


Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs, Dr Atul Bamrara, Partha Roy, Vishwanath Gargote, Khandu Thungon 2026 Department of School Education, Government of Uttarakhand - India

Enhancing Cyber Hygiene Among Communities Through Experiential Cyber-Security Awareness Programs, Dr Atul Bamrara, Partha Roy, Vishwanath Gargote, Khandu Thungon

Journal of Cybersecurity Education, Research and Practice

Human error remains the most frequently exploited vulnerability in the cyber-security ecosystem. Despite substantial investments in technical safeguards, cybercriminals increasingly rely on social engineering, misinformation, and emotionally manipulative tactics to compromise users. This study examines behavioral changes among participants who underwent structured cyber-security workshops addressing both conventional cyber hygiene practices and emerging digital threats. The training modules covered digital arrest scams, identity theft, sextortion, fake technical support fraud, fake social media profiles, online gaming related risks, and deep fake manipulation. The workshops were designed using interactive simulations, real world case studies, and hands on problem based exercises, with the explicit …


Research On Signal Perception System Of Key Technology Regulation In The United States, Kaile WANG, Hao LIU, Yunwei CHEN 2026 Scientometrics & Evaluation Research Center, National Science Library (Chengdu), Chinese Academy of Sciences, Chengdu 610299, China

Research On Signal Perception System Of Key Technology Regulation In The United States, Kaile Wang, Hao Liu, Yunwei Chen

Bulletin of Chinese Academy of Sciences (Chinese Version)

The purpose of the study is to analyze the operation mechanism of the key technology control signal perception system, and reveal the deep logic and basic procedures of the United States’ external technical containment. Through literature review and information mining, this study analyzes the structural features of the U.S. key technology control signal perception system, such as “front-end technical perception and technology locking”, “mid-end technical evaluation and risk identification”, and “back-end technical control response and dynamic sanctions”. It further explores the participating subjects and role positioning of the United States in key technology control signal perception, the sources and mechanisms …


Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal 2026 Southern Methodist University

Anomaly Detection For Multi-System Bug Triage, Gibran Miguel Zavala Gamero, Hayoung Cheon, Mustafa Iqbal

SMU Data Science Review

Large-scale software systems produce vast volumes of logs and telemetry, making manual incident triage slow and error prone. This study presents an unsupervised anomaly detection pipeline that fuses logs, metrics, and traces through late fusion. Using Hybrid Ensemble modeling with Isolation Forest, and Long Short-Term Memory (LSTM) Deep Learning model, the system detects cross-service anomalies producing and assigning a composite triage score reflecting severity and impact. Ranked alerts are categorized into Critical, High, or Medium priorities for review. A retrieval-augmented generation (RAG) layer enriches results with contextual summaries for explainable triage. Evaluated on synthetic multi-service datasets, the pipeline …


A Novel Privacy-Preserving User Information Queries Scheme With Functional Policy, Yuhang LEI, Rui SHI, Yang YANG, Chunjie CAO, Huamin FENG 2026 Singapore Management University

A Novel Privacy-Preserving User Information Queries Scheme With Functional Policy, Yuhang Lei, Rui Shi, Yang Yang, Chunjie Cao, Huamin Feng

Research Collection School Of Computing and Information Systems

Privacy-preserving information queries enable a requester to obtain only the value f(x) computed over sensitive data x, while preventing disclosure of the underlying records. Existing approaches typically reveal full data, incur high on-chain overhead, or lack fair and verifiable delivery of function outputs. We propose a general-purpose, blockchain-compatible framework that ensures the requester learns only f(x) with no extra leakage and that the provider receives fair payment. The design integrates Adaptor Signatures (AS) for fair exchange and Inner-Product Functional Encryption (IPFE) for fine-grained function extraction. The framework is domain-agnostic and applicable to privacy-sensitive applications such as medical insurance and financial …


Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker 2026 Edith Cowan University

Graph Convolution Neural Network And Deep Q-Network Optimization-Based Intrusion Detection With Explainability Analysis, Kelvin Mwiga, Mussa Dida, Leandros Maglaras, Ahmad Mohsin, Helge Janicke, Iqbal H. Sarker

Research outputs 2022 to 2026

As networks expand in size and complexity, coupled with an exponential increase in intrusions on network and IoT systems, this leads to traditional models failing to capture increasingly intricate correlations among network components accurately. Graph Convolution Networks (GCNs) have recently acquired prominence for their capacity to represent nodes, edges, or entire graphs by aggregating information from adjacent nodes. However, the correlations between nodes and their neighbours, as well as related edges, differ. Assigning higher weights to nodes and edges with high similarity improves model accuracy and expressiveness. In this paper, we propose the GCN-DQN model, which integrates GCN with a …


Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani FAN, Lwin Khin SHAR, Ruichen ZHANG, Ziyao LIU, Wenzhuo YANG, Dusit NIYATO, Kwok-Yan LAM 2026 Singapore Management University

Deep Learning Approaches For Anti-Money Laundering On Mobile Transactions: Review, Framework, And Directions, Jiani Fan, Lwin Khin Shar, Ruichen Zhang, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam

Research Collection School Of Computing and Information Systems

Money laundering is a financial crime that obscures the origin of illicit funds, necessitating the development and enforcement of anti-money laundering (AML) policies by governments and organizations. The proliferation of mobile payment platforms and smart IoT devices has significantly complicated AML investigations. As payment networks become more interconnected, there is an increasing need for efficient real-time detection to process large volumes of transaction data on heterogeneous payment systems by different operators such as digital currencies, cryptocurrencies, and account-based payments. Most of these mobile payment networks are supported by connected devices, many of which are considered loT devices in the FinTech …


Private Set Intersection: A Systematic Review, Yunbo YANG, Defan ZHU, Jianting NING, Qi FENG, Xiaoguo LI, Yuejia CHENG, Guomin YANG, Kui REN 2026 Singapore Management University

Private Set Intersection: A Systematic Review, Yunbo Yang, Defan Zhu, Jianting Ning, Qi Feng, Xiaoguo Li, Yuejia Cheng, Guomin Yang, Kui Ren

Research Collection School Of Computing and Information Systems

Various services, such as search engines, are increasingly deployed in cloud-based and distributed systems. However, data are typically managed by trusted servers, making user privacy and data security critical concerns. Private set intersection (PSI) is a powerful cryptographic primitive that enables multiple parties to compute the intersection of their datasets without revealing private inputs. It has been extensively studied over the past two decades, leading to significant gains in computational and communication efficiency. Yet, in many real-world scenarios, revealing the raw intersection may still leak sensitive information. To address this, numerous PSI variants have been developed to meet different application …


An Explainable Transformer-Based Model For Phishing Email Detection: A Large Language Model Approach, Mohammad Amaz Uddin, Md Mahiuddin, Iqbal H. Sarker 2026 Edith Cowan University

An Explainable Transformer-Based Model For Phishing Email Detection: A Large Language Model Approach, Mohammad Amaz Uddin, Md Mahiuddin, Iqbal H. Sarker

Research outputs 2022 to 2026

Phishing email is a serious cyber threat that tries to deceive users by sending false emails with the intention of stealing confidential information or causing financial harm. Attackers, often posing as trustworthy entities, exploit technological advancements and sophistication to make the detection and prevention of phishing more challenging. Despite extensive academic research, phishing detection remains an ongoing and formidable challenge in the cybersecurity landscape. In this research paper, we present a fine-tuned transformer-based masked language model, RoBERTa (Robustly Optimized BERT Pretraining Approach), for phishing email detection. In the detection process, we employ a phishing email dataset and apply the preprocessing …


Explainable Artificial Intelligence Models For Detecting Suspicious Bank Transactions, Narasimha Kumar Narasapuram, Syed Afaq Ali Shah, Mohd Fairuz Shiratuddin, Ferdous Sohel 2026 Edith Cowan University

Explainable Artificial Intelligence Models For Detecting Suspicious Bank Transactions, Narasimha Kumar Narasapuram, Syed Afaq Ali Shah, Mohd Fairuz Shiratuddin, Ferdous Sohel

Research outputs 2022 to 2026

Detecting financial crime is a complex challenge due to evolving criminal strategies and fragmented detection systems, particularly in the areas of money laundering and fraud. While it is easy to implement, traditional rule-based approaches lack adaptability to new threats, and machine learning models, though more effective, often function as opaque "black boxes," limiting their practical use in regulated domains like banking, where interpretability and accountability are essential. This research presents a novel framework that combines intrinsic and post-hoc XAI techniques to detect suspicious bank transactions. Intrinsic methods provide model-inherent transparency, while post-hoc methods offer behavior-level explanations, enabling robust cross-verification of …


Empowering Neurodiverse Talent In Cybersecurity Through Fair And Inclusive Ai Education, Sheikh Rabiul Islam, Yansi Keim, Mohiuddin Ahmed, Maanak Gupta, Ingrid Russell, Mahmoud Abdelsalam 2026 Edith Cowan University

Empowering Neurodiverse Talent In Cybersecurity Through Fair And Inclusive Ai Education, Sheikh Rabiul Islam, Yansi Keim, Mohiuddin Ahmed, Maanak Gupta, Ingrid Russell, Mahmoud Abdelsalam

Research outputs 2022 to 2026

Cybersecurity demands creativity, persistence, and sharp pattern recognition—strengths frequently reported among neurodivergent people (e.g., autism, ADHD, dyslexia). Yet AI-driven hiring pipelines can systematically disadvantage neurodivergent applicants by misreading communication styles or valuing narrow proxies of “fit.” Demand for cybersecurity talent is growing, and experts note that neurodiverse individuals are both underrepresented and highly valuable to security teams. However, progress remains uneven without targeted educational interventions [1]. We present a curricular module that simultaneously (a) centers neurodiversity as a strength in the cybersecurity workforce and (b) trains students to audit and redesign AI hiring systems using open-source fairness and explainability toolkits …


Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn 2026 University of Pretoria

Cybersecurity In Higher Education Institutions: Awareness, Policy, And Experience On Employee Behaviour, Abdullahi Abiodun Yusuf, Adriana A. Steyn

Journal of Cybersecurity Education, Research and Practice

The digital transformation of higher education institutions (HEIs) has introduced unprecedented connectivity and operational efficiency, but it has also heightened their exposure to cyber threats. South African HEIs, in particular, face increasing vulnerability due to their reliance on technology, openness, and diverse user communities. This study examines the influence of the institutional cybersecurity environment on employee cybersecurity-compliant behaviour (CCB), emphasising the critical roles of awareness, policy engagement, and experience. Drawing on Protection Motivation Theory and the Theory of Planned Behaviour, a conceptual model was developed to explore how cybersecurity awareness, policy familiarity, and prior experience shape employees’ attitudes, subjective norms, …


Cyber Science Education Meets Healthcare Technology, Angela Spencer 2026 Capitol Technology University

Cyber Science Education Meets Healthcare Technology, Angela Spencer

Journal of Cybersecurity Education, Research and Practice

The research investigates how cyber science education combines with healthcare technology during the digital age to resolve a fundamental research gap in these two advancing areas. A combined approach utilizing extensive surveys and detailed interviews evaluates the functionality of learning platforms as well as cybersecurity measures and potential uses of emerging virtual reality (VR) and augmented reality (AR) tools to improve both educational and clinical environments. The research document describes its methodologies thoroughly while. The research documents multiple quantitative and qualitative results before performing its analysis, which leads to strategy development for digit. The researchers worked to find ways that …


Defending Code Language Models Against Backdoor Attacks With Deceptive Cross-Entropy Loss, Guang YANG, Yu ZHOU, Xiangyu ZHANG, Xiang CHEN, Terry Yue ZHUO, David LO, Taolue CHEN 2026 Singapore Management University

Defending Code Language Models Against Backdoor Attacks With Deceptive Cross-Entropy Loss, Guang Yang, Yu Zhou, Xiangyu Zhang, Xiang Chen, Terry Yue Zhuo, David Lo, Taolue Chen

Research Collection School Of Computing and Information Systems

Code Language Models (CLMs), particularly those leveraging deep learning, have achieved significant success in code intelligence domain. However, the issue of security, particularly backdoor attacks, is often overlooked in this process. The previous research has focused on designing backdoor attacks for CLMs, but effective defenses have not been adequately addressed. In particular, existing defense methods from natural language processing, when directly applied to CLMs, are not effective enough and lack generality, working well in some models and scenarios but failing in others, thus fall short in consistently mitigating backdoor attacks. To bridge this gap, we first confirm the phenomenon of …


Fcghunter: Towards Evaluating Robustness Of Graph-Based Android Malware Detection, Shiwen SONG, Xiaofei XIE, Ruitao FENG, Qi GUO, Sen CHEN 2026 Singapore Management University

Fcghunter: Towards Evaluating Robustness Of Graph-Based Android Malware Detection, Shiwen Song, Xiaofei Xie, Ruitao Feng, Qi Guo, Sen Chen

Research Collection School Of Computing and Information Systems

Graph-based detection methods leveraging Function Call Graph (FCG) have shown promise for Android malware detection (AMD) due to their semantic insights. However, the deployment of malware detectors in dynamic and hostile environments raises significant concerns about their robustness. While recent approaches evaluate the robustness of FCG-based detectors using adversarial attacks, their effectiveness is constrained by the vast perturbation space, particularly across diverse models and features. To address these challenges, we introduce FCGHunter, a novel robustness testing framework for FCG-based AMD systems. Specifically, FCGHunter employs innovative techniques to enhance exploration and exploitation within this huge search space. Initially, it identifies critical …


Prisrv+: Privacy And Usability-Enhanced Wireless Service Discovery With Fast And Expressive Matchmaking Encryption, Yang YANG, Guomin YANG, Yingjiu LI, Pengfei WU, Rui SHI, Minming HUANG, Jian WENG, Hwee Hwa PANG, DENG, Robert H. 2026 Singapore Management University

Prisrv+: Privacy And Usability-Enhanced Wireless Service Discovery With Fast And Expressive Matchmaking Encryption, Yang Yang, Guomin Yang, Yingjiu Li, Pengfei Wu, Rui Shi, Minming Huang, Jian Weng, Hwee Hwa Pang, Deng, Robert H.

Research Collection School Of Computing and Information Systems

The evolution of decentralized identity (DID) and self-sovereign identity (SSI) frameworks, as endorsed by W3C Verifiable Credentials (VC) and eIDAS 2.0, underscores the need for secure, efficient, and privacy-preserving credential management. However, existing credential systems often depend on centralized issuers, lack efficient aggregation mechanisms, or fail to ensure unlinkability across authentication sessions. To address these challenges, we propose DISC (Decentralized Identity System with Self-Sovereign Credential Aggregation), a novel credential system that enables multi-authority credential issuance, user-controlled credential aggregation, and unlinkable authentication. DISC allows users to aggregate credentials from multiple issuers while maintaining constant-size authentication tokens and supporting batch verification for …


Mm-Attackg: A Multimodal Approach To Attack Graph Construction With Large Language Models, Yongheng ZHANG, Xinyun ZHAO, Yunshan MA, Haokai MA, Yingxiao GUAN, Guozheng YANG, Yuliang LU, Xiang WANG 2026 Singapore Management University

Mm-Attackg: A Multimodal Approach To Attack Graph Construction With Large Language Models, Yongheng Zhang, Xinyun Zhao, Yunshan Ma, Haokai Ma, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang

Research Collection School Of Computing and Information Systems

Cyber Threat Intelligence (CTI) parsing aims to extract key threat information from massive data, transform it into actionable intelligence, enhance threat detection and defense efficiency, including attack graph construction, intelligence fusion, and indicator extraction. Among these research topics, Attack Graph Construction (AGC) is essential for visualizing and understanding the potential attack paths of threat events from CTI reports. Existing approaches primarily construct the attack graphs purely from the textual data to reveal the logical threat relationships between entities within the attack behavioral sequence. However, they typically overlook the specific threat information inherent in visual modalities, which preserves key threat details …


Digital Commons powered by bepress