
In today's digital world, our reliance on the internet is pervasive, influencing nearly every aspect of daily life, from morning routines to evening relaxation. Cybersecurity, though essential, often goes unnoticed, as users routinely send, fetch, and transfer files with little attention to security. While more secure alternatives are available, many individuals and organizations continue to use File Transfer Protocol (FTP) in 2024 due to its simplicity and accessibility. However, the widespread use of FTP, despite its vulnerabilities, calls for immediate attention and improved security measures. This paper introduces a hybrid model designed to enhance the security of FTP by detecting potential attacks effectively. Our approach begins with a comprehensive categorization of possible FTP-based attacks, divided into two types: pre-compromise attacks aimed at gaining unauthorized access, and post-compromise attacks that exploit an already compromised server. The model incorporates two parallel components: a rule-based system that flags known attack signatures promptly and a machine learning component trained on FTP log data to recognize sophisticated and emerging attack patterns. Our model not only detects and classifies attack types but also provides valuable insights into the attacker, the attack path, and specific methods used, offering a comprehensive approach to FTP security.
Though it is possible to use pure OpenMP or pure MPI to develop parallel and distributed memory applications respectively, both are often combined in a hybrid MPI/OpenMP model to target clusters of multi-core nodes. In this paper, we introduce and discuss the design and implementation of a source-to-source compiler, translating OpenMP-annotated source code to MPI/OpenMP. We evaluate the performance of the translated programs on the HPC Spartan cluster at the University of Melbourne.
In 2018, the European Union's General Data Protection Regulation (GDPR) was enacted to regulate and harmonise data collection and processing practices, protect individuals' rights, and enforce legal accountability and penalties on non-compliant organisations. The GDPR is widely regarded as the world's most stringent privacy and security law, with implications for future amendments and privacy laws in countries such as Australia. Although organisations have implemented various approaches and processes to meet GDPR requirements, they continue to face challenges in aligning their systems and processes to ensure full GDPR compliance. In this paper, we review existing technical approaches and analyse the extent to which they are GDPR compliant and meet the rights of data subjects. Except for consent management, the existing literature sparsely covers other rights. Additionally, existing technical approaches assume that the data controller is trustworthy and will act according to the consent granted after receiving personal data. If this assumption is relaxed, none of the rights can be ensured in the current technical approaches. Next, we present a conceptual design for a holistic framework that ensures almost all data subjects' rights in GDPR, even in untrustworthy environments. Rather than providing personal data to the data controller, the proposed framework manages consent and provides a secure environment to process data using consented or trusted algorithms, returning only the processed data to the data controller. The framework builds on and integrates existing technologies, namely blockchains, personal data stores, and trusted execution environments, to create a secure environment with transparent processing. It aims to address the gaps identified in current technical approaches, ensuring that data subjects' rights are preserved in compliance with GDPR, even in untrustworthy environments.
Recent progress in generative artificial intelligence (GenAI) has yielded significant advancements in healthcare, affecting radiology, medical imaging, drug development, patient diagnostics, and supply chain optimisation. These innovations promise more improved diagnoses and time-saving cost-effectiveness. However, GenAI's rapid implementation poses significant challenges for meeting regulatory, ethical, and trustworthiness standards. These challenges include data privacy issues, reproducibility concerns, algorithmic bias in training data causing disparities in outcomes, and a lack of transparency and explainability. Unresolved, these issues could negatively affect the public's confidence in and perception of GenAI systems. Addressing these challenges, international AI governance frameworks, including the EU AI Act and WHO guidelines, prioritize regulatory adherence, trustworthiness, and the explainability of healthcare AI systems. While such frameworks have expanded, a deficiency remains in translating policy into effective compliance mechanisms. We propose a Compliance Agentic Model (CAM) framework to help organizations comply with GenAI and machine learning (ML)-based solutions. The CAM framework establishes trustworthiness in GenAI applications used in healthcare, ensuring alignment with organizational values and ethical standards to enhance accountability and regulatory adherence.
This paper introduces a novel method for generating differentially private synthetic datasets that harnesses Bayesian networks to ensure the preservation of essential statistical properties and referential integrity across linked tables. To address the dual challenges of maintaining privacy and minimizing computational overhead, we introduce a decomposition scheme for additive Laplacian noise that significantly reduces computational costs while enhancing the efficiency of the differential privacy framework. Our methodology offers a robust solution for creating synthetic datasets that not only mimic the statistical characteristics of original datasets, but also safeguard sensitive information against inference attacks. Through comprehensive evaluations, we demonstrate the practicality and effectiveness of our approach, which achieves a significant speedup in noise injection, thereby facilitating real-time data analysis. This breakthrough contributes to the broader accessibility of complex data analysis, particularly benefiting sectors dealing with sensitive information by improving data privacy and security measures. Our findings represent a significant advancement in statistical methodologies and software, underscoring the ongoing necessity for innovation in data processing techniques.
Email Phishing is one of the most pervasive social-engineering attack that targets user credentials and personal information. Current defenses often rely on pattern-based rules or signatures to detect phishing emails. These rules have been prone to changes in the content of the email body as they cannot comprehend the semantics of the message. Cybercriminals are using modern generative AI tools to craft phishing messages that can evade current defenses. In this paper, we present PhishEmailLLM a novel system that relies on publicly available LLMs and advanced ML models to accurately detect phishing emails. We highlight the challenges to creating and use such systems and present our solution to overcome these challenges using modern software and cloud architectures. A thorough evaluation of our system was conducted using publicly available high-quality phishing datasets. We evaluated several top of the line freely available LLMs and compared our system to well-known baseline systems for Phishing detection. We established that our meta-hybrid approach, using LLMs and traditional ML algorithms for phishing detection, outperforms other systems and costs less to run.
We propose a solution for optimized scaling of multi-party computation using the MP-SPDZ framework (CCS'20). It does not use manual optimization but extends the compiler and the virtual machine of the framework, thus providing an improvement for any user. We found that our solution improves timings four-fold for a simple example in MP-SPDZ, and it improves an order of magnitude on every framework using secret sharing considered by Hastings et al. (S&P'19) either in terms of time or RAM usage. The core of our approach is finding a balance between communication round optimization and memory usage.
The rapid integration of Internet of Things (IoT) devices into enterprise environments presents significant security challenges. Many IoT devices are released to the market with minimal security measures, often harbouring an average of 25 vulnerabilities per device. To enhance cybersecurity measures and aid system administrators in managing IoT patches more effectively, we propose an innovative framework that predicts the time it will take for a vulnerable IoT device to receive a fix or patch. We developed a survival analysis model based on the Accelerated Failure Time (AFT) approach, implemented using the XGBoost ensemble regression model, to predict when vulnerable IoT devices will receive fixes or patches. By constructing a comprehensive IoT vulnerabilities database that combines public and private sources, we provide insights into affected devices, vulnerability detection dates, published CVEs, patch release dates, and associated Twitter activity trends. We conducted thorough experiments evaluating different combinations of features, including fundamental device and vulnerability data, National Vulnerability Database (NVD) information such as CVE, CWE, and CVSS scores, transformed textual descriptions into sentence vectors, and the frequency of Twitter trends related to CVEs. Our experiments demonstrate that the proposed model accurately predicts the time to fix for IoT vulnerabilities, with data from VulDB and NVD proving particularly effective. Incorporating Twitter trend data offered minimal additional benefit. This framework provides a practical tool for organisations to anticipate vulnerability resolutions, improve IoT patch management, and strengthen their cybersecurity posture against potential threats.
Social media platforms, including WeChat, are increasingly being included in health interventions, however, the impact of doing so remains largely unknown. Given the popularity of the WeChat platform, this review synthesises evidence of including WeChat in interventions for the management of risk factors in cardiovascular disease (CVD). This review forms a sub-set of an ongoing systematic review examining the inclusion of social media use on health outcomes in people with chronic disease. We searched seven databases for randomised controlled trials published in English, between January 2000 and June 2023, on interventions for the management of chronic diseases in adults that included social media as an intervention component. Data on health-related outcomes, the role of WeChat use in the intervention, and affordances (identity, flexibility, structure, narration, adaptation) applied to WeChat were extracted. Four papers were identified, three were on risk factors for CVD (2 x diabetes, 1 x hypertension), and one on CVD. Given the small number and heterogeneity of included studies, findings were reported as a narrative synthesis. Interventions that included WeChat showed improvement in health-related outcomes, including HbA1C, blood pressure, and functional capacity (6-min walk). WeChat was used to support and educate patients, and to help manage and modify disease. All interventions appeared to afford study participants flexibility and at least one other affordance, such as structure. With an increasing popularity of WeChat use, this review presents the important and potential role of WeChat in health interventions, suggesting further research examining and using WeChat to help people manage CVD and associated risk factors is needed.
Health technology assessment (HTA) is crucial in making adoption decisions for emerging health technologies, such as an enterprise health information system. Variance-based approaches are commonly used in HTA. However, given health technologies’ complexity and multifaceted nature, relying solely on a net effect approach could be misleading. Instead, case-based approaches such as qualitative comparative analysis (QCA) have the uniqueness to capture combinations of complex factors that align with the outcomes being studied. This study aims to demonstrate using QCA as a case-based approach to provide additional nuances in traditional evidence-based synthesis in HTA. We designed a measurement model based on technology acceptance and information systems success models from literature to collect clinicians’ experience with an electronic medication management system (EMMS). Confirmatory factor analysis (CFA) was conducted to examine the dimension's reliability and validity in the measurement model. QCA was then performed and revealed three different configurations that led to the successful adoption of EMMS for doctors and one for nurses. Information quality, perceived usefulness, service quality and satisfaction were core conditions indispensable to EMMS adoption and success. Doctors and nurses have interrelated but different results. Overall, we demonstrated that QCA, as a case-based approach, can add valuable information to HTA and adoption decision-making about new health technologies.
This study focuses on Attention Deficit Hyperactivity Disorder (ADHD), a neurodevelopmental disorder that affects both children and adults. Individuals with ADHD often struggle with difficulties related to attention, impulse control, and hyperactivity. To learn more about ADHD, researchers have employed a variety of neuroimaging modalities and analysis techniques over the years. To research brain activity in children with ADHD, this study examines the characteristics of Electroencephalogram (EEG) data using Machine Learning Techniques, which can be a trustworthy diagnostic tool for physicians. After analyzing the EEG data obtained, we can infer from this empirical investigation that the frontal regions of the brain are mostly active and model accuracy is 80% for ADHD classification.
Clinical Decision Support Systems (CDSS) are pivotal in modern healthcare, aiding healthcare practitioners in making accurate decisions. Most of the existing CDSSs are static; due to this, adaptation to a new environment or changes in the same environment is difficult. There is a requirement for CDSS adaptation strategies that enable the system to adjust to a new environment or local changes in the same environment including associated factors such as different types of patients, different ecosystems, and varying guidelines. Additionally, two significant challenges of CDSS persist: its maintenance and the issue of portability across different hospitals with varying data ecosystems. In this paper, we propose an Adaptive Semantic Framework (ASF) for CDSS adaptation to a changing environment to overcome the above challenges. The framework includes various methods such as Knowledge-Based Systems (KBS) and Data-Driven Elements (DDE) to adjust the CDSS to new conditions.
In the United Arab Emirates, housing establishments offer citizens opportunities to apply for housing loans or grants. The eligibility for a loan or grant depends on the citizen’s income. Those with incomes below a predetermined threshold can apply for grants, while those with higher incomes are eligible for loans. Along with proof of income, other information such as the citizen’s health, fitness level, number of dependents, and marital status must be submitted with the application. This information, typically sourced from various government entities, must be verified. Traditionally, verifying this information through direct contact with these entities has been inefficient and time-consuming. To address this, we propose a blockchain-based, graph-traversing framework. This framework aims to create a secure mechanism for information sharing between housing establishments and government entities, thereby automating the processing of housing support applications. The framework also represents housing regulations as a graph, enabling updates to the regulations without disrupting workflow. We conducted several experiments to analyse the cost-effectiveness of the proposed framework, finding that processing a single application costs less than $1 on average.
Colonic and gastric cancers are the second and third most frequent causes of cancer-related deaths in Japan. Surveillance endoscopy plays an important role in the early detection of such occurrences. Explanations of endoscopy are repetitive and require extensive labor effort; hence, substituting manual explanations with information technology could assist in reducing medical staff workloads. As part of an implementation science study, we designed and developed a rule-based Chatbot system to assist in real-life endoscopy explanations in Japan. We employed a LINE official account to develop the system consisting of educational video materials created by VYOND animation software. Conceived, designed, and developed by endoscopists, the team used mixed methods to assess the Chatbot system's usability, engaging with interdisciplinary medical staff and patient users. The designed Chatbot system features eight video materials, all of which were developed in accordance with both hospital and national endoscopy procedures. The medical staff groups agreed on the correct content and potential usability of the system. The Chatbot system received an average System Usability Scale score of 90 from external user evaluators. As of December 2023, the Chatbot system has been implemented in a real-world hospital in Japan for more than 6 months. The system has recorded support for more than 700 patients who needed to undergo gastroscopy/colonoscopy operations, and no adverse events were reported. The management plans to expand the content coverage for endoscopy operations, targeting the normalization of endoscopic practices.
Adverse Drug Reactions (ADRs) pose a critical challenge to patient safety and healthcare economics worldwide. This study presents a novel graph-assisted machine learning algorithm applied to a comprehensive dataset provided by the Commonwealth Bank Health Society (CBHS), spanning 1976 to 2018, to predict ADRs. Utilizing the narrative-like structure of patients’ medical histories through Natural Language Processing (NLP), the research uniquely encodes International Classification of Diseases (ICD) codes into word embeddings. In a departure from traditional methods, it also employs networks analytics to transform disease histories into a knowledge graph structure that captures temporal and contextual relationships between ICD codes. This study's results demonstrated that integrating Node2Vec with Word2Vec improved model performance across various metrics, with significant enhancements in recall for K-nearest neighbors (KNN) and area under the receiver operating characteristic curve (AUROC) for all models. The findings underscore the potential of NLP in medical contexts and highlight the advantages of graph-based approaches in capturing complex, non-linear interdependencies inherent in patient data. This research marks a significant stride toward harnessing the power of NLP and graph theory in the predictive modeling of ADRs, aiming to improve patient outcomes by preempting potential adverse drug interactions.
Loss aversion is a powerful tool used in commercial games to increase revenue. This is achieved by letting players obtain items of value, e.g., special abilities, which are eventually lost unless the player performs a certain desired behaviour such as viewing advertisements or doing in-game purchases. The technique is based on the observation that the fear of loosing is a stronger motivator than the possibility of winning. So far little is known to what extend loss aversion can be used to increase motivation and physical activity in an exergame, and whether this depends on personality types. We found that the loss aversion strategy increased players’ physical activity and motivation but also increased pressure. Participants with higher openness were more engaged, and those with higher neuroticism felt more pressured. Emotionally stable individuals were receptive to the loss aversion strategy, and participants with higher conscientiousness experienced less pressure. Individuals with higher agreeableness showed greater interest in the loss aversion version. Our findings suggest that loss aversion can increase users’ motivation in exergames, but can have the opposite effect for some personality types. We conclude that ideally an exergame should use personalised motivation strategies.
Communication theorists discern six types of dialogue that occur between participants in discourse with each other: persuasion, inquiry, deliberation, information-seeking, eristic, and discovery. Although social media use in health care settings has been investigated from diverse perspectives, few studies have analysed social media interactions as dialogues and the implications for individualised care. The objective of this study is to identify the extent to which the six types of dialogue can be discerned from the self-reported social media activities of health care providers and the implications for individualised care. To realise the objectives of this study, transcripts of the interview of health care providers that use social media were thematically analysed using NVivo software. Findings reveal that each of the six types of dialogue is discernible from the social media posts of health care providers, and these dialogues help narrow the communication gap between stakeholders in health care. This suggests the use of social media in health care can be analysed using dialogue theory and paves the way for future research to discover precursors that trigger a dialogue shift from one type to another and a new way to assess the effectiveness of social media.
Inaccurate and incomplete medical history taking can hinder diagnosis and impede optimal healthcare delivery. This research explores the potential of large language models (LLMs) as conversational assistants for patient history collection, aiming to optimize the process for both patients and healthcare providers. Through three field trials involving a total of 150 patients, we identified key challenges and innovative solutions to implement LLMs effectively, paving the way for improved patient care. The research highlights the success of a mobile web application linked by QR code, the utilization of constitutional AI training instead of traditional data-driven methods, and the presentation of patient history summaries directly to physicians to reduce cognitive load. This comprehensive approach enhances the efficiency and quality of patient history-taking, addressing common issues such as the lack of in-depth medical history, doctor's cognitive overload, and the impact of different communication modalities on patient engagement.
The incidence of metabolic disorders is increasing at an alarming rate. A theoretically reversible collection of risk factors called metabolic syndrome precedes some of these conditions, such as diabetes. Additionally, treatments designed for diabetes do not often incorporate the individualized real-time lifestyle and physiological data. Monitoring glucose levels for diabetics and stopping prediabetics from progressing further can be aided by continuous glucose monitoring. The ubiquitous and unobtrusive nature of wrist-worn smart watches and continuous glucose monitors allow a longitudinal flow of information rich data. However, a comprehensive inspection or cascaded statistical tests must be performed to draw insights from this data. These methods suffer from subjectivity, observation bias and complexity. To overcome these, Artificial intelligence (AI) can be leveraged to draw these insights due to scalable utility of data. Alongside phenotyping glucose changes AI can also help reduce the costs associated with glucose level monitoring. This study proposes to develop an AI-driven precision medicine framework to incorporate data from wrist-worn sensors and glucose monitors to deliver insights.
Epilepsy is one of the most prevalent neurological conditions, where an epileptic seizure is a transient occurrence due to abnormal, excessive and synchronous activity in the brain. Electroencephalogram signals emanating from the brain may be captured, analysed and then play a significant role in detection and prediction of epileptic seizures. The intention here is to leverage off the abilities of the the Maximum Overlap Discrete Wavelet Transform to provide analysis of variance exhibited at differing inherent frequency levels and to develop develop various graph based metrics of connection between the electrodes placed upon the scalp. Using statistical parameters derived from these graph theoretic indicators for electrode connectivity, build the attribute space. The entire exercise is to be undertaken in open-source software and publicly available data.