
Industry 5.0 is transforming the industrial paradigm by placing humans at the center of manufacturing and service processes. This approach, which emphasizes the synergistic collaboration between humans and cyber-physical systems (CPS), goes beyond the purely productivity-oriented goals of Industry 4.0 and prioritizes sustainability, resilience, and human well-being. However, the evolving nature of human-machine interactions poses complex security challenges. Traditional information security management systems (ISMS), which are based on the PDCA cycle and top-down approaches, face limitations in adapting to operational dynamics and receiving qualitative feedback from frontline workers. This paper introduces a complementary human-centric framework, “Low-Level ISMS” (LL-ISMS), while identifying emerging security risks in these complex ecosystems. The framework operates as a bottom-up feedback loop and focuses on four key stages: purposeful preparation (Do’), practical perception (Feel), critical analysis (Think), and active participation (Help). By connecting operational insights from employees to management decisions, LL-ISMS significantly increases the effectiveness of security management in Industry 5.0 environments and fosters a shared and dynamic security culture.
INTRODUCTION: Cyber incidents are increasingly shaped not only by technical severity but also by how risk signals are amplified through AI-mediated information ecosystems. Deepfakes, synthetic media, algorithmic amplification, and AI-generated misinformation can intensify public fear, distort trust, and trigger disproportionate societal responses. OBJECTIVES: This paper develops the Resonant Risk Model as a sociotechnical extension of the Social Amplification of Risk Framework for AI-era cybersecurity. It also proposes the Resonant Risk Management Framework to support perception-aware cyber risk governance. METHODS: The study uses theory-building, interdisciplinary literature synthesis, structured case selection, and comparative case analysis. Six cases are assessed using dimensions including technical severity, amplification channels, resonance factors, public perception, societal ripple effects, and feedback loops. RESULTS: The analysis shows that high technical severity does not always produce high public resonance. SolarWinds showed very high technical severity but moderate public resonance, while AI-driven misinformation and deepfake cases produced high trust erosion despite lower direct technical impact. CONCLUSION: The paper argues that cyber resilience must include perception monitoring, rapid communication, misinformation correction, and trust recovery alongside technical controls.
The increasing demand for privacy has driven the adoption of privacy-enhancing tools such as VPNs, but website fingerprinting – the analysis of packet metadata like packet size and number of packets – still poses a substantial risk. Website fingerprinting allows adversaries to predict a victim’s web usage based on their browsing patterns, effectively creating a “fingerprint”. Recent studies have largely focused on laboratory settings and have assumed a simplified model: a victim visits a single website at a time and that all network packets can be observed. However, a new private browser extension, WebTracker, deployed with real users, shows that observed browsing patterns are significantly different from those previously assumed. Users’ behavior frequently exhibits defensive strategies, such as multiple websites overlapping and downloading simultaneously, which can interfere with website fingerprinting. A study of international users demonstrated that over 15% of websites overlap with at least another, with an average overlap time of 66 seconds, while a US-based study showed only 0.72% of websites overlap. Moreover, these overlaps typically occur shortly after the initial website download. These findings suggest that the beginning of a website is more crucial than the end for website fingerprinting attacks, highlighting the need for more analysis of webbrowsing behavior.
The growing reliance on Location-Based Services (LBS) has intensified privacy risks, as the continuous collection of sensitive user location data exposes individuals to potential re-identification and unauthorised tracking. This paper presents a hybrid privacy-preserving framework that combines the Diameter-Bounded DBSCAN clustering algorithm for spatial k-anonymity with an adaptive Laplace mechanism for ε-differential privacy. This integration ensures the formation of compact anonymity groups while maintaining high data utility. Experimental evaluation on the real-world GeoLife dataset demonstrates 85.1% query accuracy, 0.14 trajectory distortion (EDR), and average query latency below 100 milliseconds for 20,000 users, outperforming DPPS and AdaptiveGrid baselines. Comprehensive sensitivity analysis of the diameter threshold (dmax) and evaluation of suppression bias confirm the framework’s robustness, scalability, and practical suitability for real-time LBS deployment.
INTRODUCTION: The current volume and sophistication of cyber threats are beyond overshadowing the security capabilities of traditional reactive security approaches. Herein, we present a new cybersecurity framework that incorporates real-time threat intelligence with adaptive deception technologies for the proactive defense of digital infrastructures. OBJECTIVES: The objectives of this research include: (1) develop an AI-driven cybersecurity framework, (2) incorporate real-time threat intelligence and deception-based active defense approaches, and (3) assess performance in simulated and real-world cyber-attack scenarios. METHODS: The proposed cyber-defense framework uses machine learning approaches, automated deception technologies (e.g., honeypots, moving target defense), and real-time threat intelligence feeds. The framework is constructed in a modular architecture and tested in simulation environments with real-time attack emulation. RESULTS: The framework performed with over 93% of threats visible, an adaptive response time < 2 seconds, and < 12% overhead imposed on the system. The framework achieved > 85% threat prevention, measured long recovery time, and measured system integrity improvements. CONCLUSION: The conclusion of this work illustrates that a proactive cybersecurity framework can be achieved through the integration of AI-enabled adaptive response with real-time threat intelligence. This work represents an advancement toward intelligent, self-learning systems capable of anticipating and responding to developing cyber threats with minimal human intervention.
INTRODUCTION: Brain-Computer Interfaces (BCIs) embedded with Artificial Intelligence (AI) have created powerful closed-loop cognitive systems in the fields of neurorehabilitation, robotics, and assistive technologies. However, these tightly bound systems of human-AI integration expose the system to new security vulnerabilities and adversarial distortions of neural signals.OBJECTIVES: The paper seeks to formally develop and assess neuro-adversarial attacks, a new class of attack vector that targets AI cognitive feedback systems through attacks on electroencephalographic (EEG) signals. The goal of the research was to simulate such attacks, measure the effects, and propose countermeasures. METHODS: Adversarial machine learning (AML) techniques, including Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD), were applied to open EEG datasets using Long Short Term Memory (LSTM), Convolutional Neural Networks (CNN), and Transformer-based models. Closed-loop simulations of BCI-AI systems, including real-time feedback, were conducted, and both the attack vectors and the attacks countermeasure approaches (e.g., VAEs, wavelet denoising, adversarial detectors) were tested.RESULTS: Neuro-adversarial perturbations yielded up to 30% reduction in classification accuracy and over 35% user intent misalignment. Transformer-based models performed relatively better, but overall performance degradation was significant. Defense strategies such as variational autoencoders and real-time adversarial detectors returned classification accuracy to over 80% and reduced successful attacks to below 10%.CONCLUSION: The threat model presented in this paper is a significant addition to the world of neuroscience and AI security. Neuro-adversarial attacks represent a real risk to cognitive-AI systems by misaligning human intent and action with machine response. Mobile layer signal sanitation and detection.
As the cloud-based file sharing becomes increasingly popular, it is crucial to protect the outsourced data against unauthorized access. Existing cryptography-based approach suffers from expensive re-encryption upon permission revocation. Other solutions that utilize Trusted Execution Environment (TEE) to enforce access control either expose the plaintext keys to users or turn out incapable of handling concurrent requests. In this paper, we propose SeFS, a secure and practical file sharing framework that leverages cooperation of server-side and client-side enclaves to enforce access control, with the former responsible for registration, authentication and access control enforcement and the latter performing file decryption. Such design significantly reduces the computation workload of server-side enclave, thus capable of handling concurrent requests. Meanwhile, it also supports immediate permission revocation, since the file decryption keys inside the client-side enclaves are destroyed immediately after use. We implement a prototype of SeFS and the evaluation demonstrates it enforces access control securely with high throughput and low latency.
This paper presents a systematic literature review on the psychology of insider threats—security risks originating from individuals within organizations. While this is a well-established research area, psychological perspectives remain underdeveloped. The extended version adds background to better contextualize the role of personality traits, psychological states, and situational factors in insider threats. The paper also highlights research gaps and the need for stronger theoretical foundations in this domain.
INTRODUCTION: Many online services use data-sharing nudges to solicit personal data from their customers for personalized services. OBJECTIVES: This study aims to study people’s privacy preferences in sharing di ff erent types of personal data under di ff erent nudging conditions, how digital nudging can change their data sharing willingness, and if people’s data sharing preferences can be predicted using their responses to a questionnaire. METHODS: This paper reports a machine learning-based analysis on people’s privacy preference patterns under four di ff erent data-sharing nudging conditions (without nudging, monetary incentives, non-monetary incentives, and privacy assurance). The analysis is based on data collected from 685 UK residents who participated in a panel survey. Their self-reported willingness levels towards sharing 23 di ff erent types of personal data were analyzed by using both unsupervised (clustering) and supervised (classification) machine learning algorithms. RESULTS: The results led to a better understanding of people’s privacy preference patterns across di ff erent data-sharing nudging conditions, e.g., our participants’ preferences are distributed in a space of 48 possible profiles more sparsely than we expected, and the unexpected observation that all the three data-sharing nudging strategies led to an overall negative e ff ect: they led to a reduced level of self-reported willingness for more participants, comparing with the case of no nudging at all. Our experiments with supervised machine learning models also showed that people’s privacy (data-sharing) preference profiles can be automatically predicted with a good accuracy, even when a small questionnaire with just seven questions is used. CONCLUSION: Our work revealed a more complicated structure of people’s privacy preference profiles, which have some dependencies on the type of data nudging and the type of personal data shared. Such complicated privacy preference profiles can be e ff ectively analyzed using machine learning methods, including automatic prediction based on a small questionnaire. The negative results on the overall e ff ect of di ff erent data-sharing nudges imply that service providers should consider if and how to use such mechanisms to incentivise their consumers to share personal data. We believe that more consumer-centric and transparent methods and tools should be used to help improve trust between consumers and service providers.
Many techniques have been proposed to harden programs with protection mechanisms to defend against vulnerability exploits. Unfortunately the vast majority of them cannot be applied to closed source software because they require access to program source code. This paper presents our work on automatically hardening binary code with security workarounds, a protection mechanism that prevents vulnerabilities from being triggered by disabling vulnerable code. By working solely with binary code, our approach is applicable to closed source software. To automatically synthesize security workarounds, we develop binary program analysis techniques to identify existing error handling code in binary code, synthesize security workarounds in the form of binary code, and instrument security workarounds into binary programs. We designed and implemented a prototype or our approach for Windows and Linux binary programs. Our evaluation shows that our approach can apply security workarounds to an average of 69.3% of program code and the security workarounds successfully prevents exploits to trigger real-world vulnerabilities.
In this contemporary era internet of things are used in every realm of life. Recent software’s (e.g., vehicle networking, smart grid, and wearable) are established in result of its use: furthermore, as development, consolidation, and revolution of varied ancient areas (e.g., medical and automotive). The number of devices connected in conjunction with the ad-hoc nature of the system any exacerbates the case. Therefore, security and privacy has emerged as a big challenge for the IoT. This paper provides an outline of IoT security attacks on Three-Layer Architecture: Three-layer such as application layer, network layer, perception layer/physical layer and attacks that are associated with these layers will be discussed. Moreover, this paper will provide some possible solution mechanisms for such attacks. The aim is to produce a radical survey associated with the privacy and security challenges of the IoT. This paper addresses these challenges from the attitude of technologies and design used. The objective of this paper is to rendering possible solution for various attacks on different layers of IoT architecture. It also presents comparison based on reviewing multiple solutions and defines the best one solution for a specific attack on particular layer.
People have many accounts and usually need to create a password for each. They tend to create insecure passwords and re-use passwords, which can lead to compromised data. This research examines if there is a link between personality type and password security among a variety of participants in two groups of participants: SONA and MTurk. Each participant in both surveys answered questions based on password security and their personality type. Our results show that participants in the MTurk survey were more likely to choose a strong password and to exhibit better security behaviors and knowledge than participants in the SONA survey. This is mostly attributed to the age di ff erence. However, the distribution of the results was similar for both MTurk and SONA. In the second part of our study, we found that security behaviors actually went down – this could be due to the pandemic or indicative of a need for more regular messaging/training.
Cyberspace is growing at full tilt creating an amalgamation of disparate systems. This heterogeneity leads to increased system complexity and security flaws. It is crucial to understand and identify these flaws to prevent catastrophic events. However, the current state-of-the-art solutions are threat-specific and focus on either risk, vulnerabilities, or adversary emulation. In this work, we present a scalable Cyber-threats and Vulnerability Information Analyzer (CyVIA) framework. CyVIA analyzes cyber risks and abnormalities in real-time using multi-formatted knowledge bases derived from open-source vulnerability databases. CyVIA achieves the following goals: 1) assess the target network for risk and vulnerabilities, 2) map services and policies to network nodes, 3) classify nodes based on severity, and 4) provide consequences, mitigation, and relationships for the found vulnerabilities. We use CyVIA and other tools to examine a simulated network for threats and compare the results.
Given the fact that many software projects are closed-source, analyzing security-related vulnerabilities at the binary level is quintessential to protect computer systems from attacks of malware.Binary code similarity detection is a potential solution for detecting malware from the binaries generated by the processor.In this paper, we proposed a malware detection mechanism based on the binaries using machine learning techniques.Through utilizing the Recurrent Neural Network (RNN), more specifically Long Short-Term Memory (LSTM) network, we generate the uniformed feature embedding of each binary file and further take advantage of the Siamese Neural Network to compute the similarity measure of the extracted features.Therefore, the security risks of the software projects can be evaluated through the similarity measure of the corresponding binaries with existing trained malware.Our real-world experimental results demonstrate a convincing performance in distinguishing out the outliers, and achieved slightly better performance compared with existing state-of-theart methods.
With the proliferation of mobile devices and smart cameras, detecting anomalies and predicting their mobility are critical for enhancing safety in ubiquitous computing systems. Due to data privacy regulations and limited communication bandwidth, it is infeasible to collect, transmit, and store all data from mobile devices at a central location. To overcome this challenge, we propose FedADMP, a federated learning based joint Anomaly Detection and Mobility Prediction framework. FedADMP adaptively splits the training process between the server and clients to reduce computation loads on clients. To protect the privacy of user data, clients in FedADMP upload only intermediate model parameters to the cloud server. We also develop a di ff erential privacy method to prevent the cloud server and external attackers from inferring private information during the model upload procedure. Extensive experiments using real-world datasets show that FedADMP consistently outperforms existing methods.
Privacy and information security have consistently been a priority for the European Union lawmaker. This paper investigates the security requirements of the General Data Protection Regulation (GDPR) and the Directive on security of network and information systems (NISD). This investigation incorporates what is unique about the NISD; how it overlaps with existing frameworks; and how security requirements in the GDPR influence the NISD. This mapping of requirements can help businesses and organizations to distinguish possible difficulties that may experience while conforming to GDPR and NISD, and help them create a consistent cybersecurity framework and structure new security plans.
Virtual machine escape is one of the most serious vulnerabilities happening if the isolation between the hosts and between the VMs is compromised, which presents new security challenges that the security concern is the major factor effecting virtualization technology widely adopted in IT industry.In VM escape, the program running in a virtual machine is able to completely bypass the hypervisor layer, and get access to the host machine.The traditional research method is analyzing a vulnerability separately, but that consumes too much time and not constructs the attack model.So we innovatively design VM escape elevated penetration attack models based on finite state machine, which could be used to identify potential vulnerabilities in design, implementation and testing phases.In this paper, firstly, we extract elevated privilege models of different virtualization methods, studying that VMCS pointer instruction state indicates system state.Secondly, we define a formal language Datalog to represent pre-and post-conditions of the exploits of application vulnerabilities and infer a basic elevated penetration attack model.Thirdly, through the analysis of vulnerable source code and vulnerability reports from NVD, we shed light on four attack models to cover the most VM escape attacks.Finally, we evaluate the presented approach by applying code-level finite state machine models with formal language to specific vulnerabilities, together with the statistical results of different attack models.
The Internet of things (IoT) is a new ubiquitous technology that relies on heterogeneous devices and protocols.The IoT technologies are expected to offer a new level of connectivity thanks to its smart devices able toenhance everyday tasks and facilitate smart decisions based on sensed data. The IoT could collect sensitivedata and should be able to face attacks and privacy issues. The IoT security issue is a hot topic of researchand industrial concern. Indeed, threats against IoT devices and services could cause security breaches anddata leakage. Aiming to identify attempts to abuse the IoT systems and mitigate malicious events, this paperstudied the Intrusion Detection Systems (IDS) based on Machine Learning (ML) techniques. The ML approachcould provide good tools to detect novel intrusion activities in a timely manner. This paper, therefore,highlighted the related issues to develop secured and efficient IoT services. It tried to allow a comprehensivereview of IoT features and design. It mainly focused on intrusion detection based on the machine learningschema and built a taxonomy of different IoT attacks and threats. This paper also compared between thedifferent intrusion detection techniques and established a taxonomy of machine leaning methods for intrusiondetection solutions.
Many traditional machine learning and deep learning algorithms work as a black box and lack interpretability. Attention-based mechanisms can be used to address the interpretability of such models by providing insights into the features that a model uses to make its decisions. Recent success of attention-based mechanisms in natural language processing motivates us to apply the idea for security vetting of Android apps. An Android app’s code contains API-calls that can provide clues regarding the malicious or benign nature of an app. By observing the pattern of the API-calls being invoked, we can interpret the predictions of a model trained to separate benign apps from malicious apps. In this paper, using the attention mechanism, we aim to find the API-calls that are predictive with respect to the maliciousness of Android apps. More specifically, we target to identify a set of API-calls that malicious apps exploit, which might help the community discover new signatures of malware. In our experiment, we work with two attention-based models: Bi-LSTM Attention and Self-Attention. Our classification models achieve high accuracy in malware detection. Using the attention weights, we also extract the top 200 API-calls (that reflect the malicious behavior of the apps) from each of these two models, and we observe that there is significant overlap between the top 200 API-calls identified by the two models. This result increases our confidence that the top 200 API-calls can be used to improve the interpretability of the models. Received on 14 July 2021; accepted on 03 August 2021; published on 27 September 2021
Collaborative machine learning is a promising paradigm that allows multiple participants to jointly train a machine learning model without exposing their private datasets to other parties. Although collaborative machine learning is more privacy-friendly compared with conventional machine learning methods, the intermediate model parameters exchanged among different participants in the training process may still reveal sensitive information about participants’ local datasets. In this paper, we introduce a novel privacy-preserving collaborative machine learning mechanism by utilizing two non-colluding servers to perform secure aggregation of the intermediate parameters from participants. Compared with other existing solutions, our solution can achieve the same level of accuracy while incurring significantly lower computational cost.