
Graph data has emerged as a critical resource due to its rich structural and semantic information. Anonymization is essential for preventing node re-identification during graph data sharing or publishing. Different users have diverse privacy requirements, motivating research on personalized anonymization. In practice, multiple data analysts may demand different levels of privacy protection for the same graph, requiring regeneration of anonymized graphs for distinct privacy requirements. Existing personalized anonymization methods suffer from high computational overhead when supporting diverse, scenario-specific requirements. To address this inefficiency, we formulate a personalized k2-anonymity model to protect both node degrees and attribute information. Then we design a Hierarchical Personalized Graph Anonymization (HPGA) algorithm to efficiently generate multi-scenario anonymized graphs under varying privacy requirements. HPGA constructs a reusable hierarchical structure and incorporates an efficient privacy requirement matching mechanism for anonymization. It applies edge modification and attribute generalization strategies to generate anonymized graphs. Experimental results on real-world datasets show that HPGA significantly reduces 99% computation time compared to the existing method. In addition, HPGA maintains good data utility.
The Internet of Medical Things (IoMT) delivers transformative clinical value but introduces systemic cybersecurity risks with direct patient-safety consequences. We develop a group-stratified, stochastic System Dynamics model that captures nonlinear socio-technical feedbacks driving IoMT vulnerability. The loss-severity component is empirically calibrated to 1,617 U.S. Hacking/IT healthcare breaches as a conservative proxy for the IoMT-integrated loss regime using a Bayesian spliced LogNormal-GPD framework estimated via Hamiltonian Monte Carlo. The posterior indicates a heavy-tailed regime with Pareto tail index α≈1.63, so moment-based risk metrics understate catastrophic exposure. Running 8,000 Monte Carlo trajectories per configuration, we evaluate five regulator-anchored governance interventions. An efficiency-oriented Combined strategy reduces high-threshold losses per marginal dollar but fails to mitigate deep-tail risk and can create a Vulnerability Trap that widens a modelled Digital Security Divide for resource-constrained providers. An unconditional Trust Buffer preserves short-term adoption and trust yet induces moral hazard, allowing latent vulnerabilities to accumulate and amplifying catastrophic tail exposure. To reconcile trade-offs, we propose a multi-objective Robustness Pivot balancing efficiency and deep-tail resilience under heavy-tailed risk. We operationalize this as a Tri-Pillar Resilience Architecture: risk-priced cyber-liability insurance, a conditional Digital Health Trust Fund, and equity-sensitive lifecycle certification aligned with ISO/IEC 81001-5-1 and FDA §524B. This design pursues systemic resilience and equity jointly, showing that the two are structurally interdependent under heavy-tailed cyber risk.
CI security controls combine contract, semantic, policy, provenance, dependency, and review evidence before release. Binary gates are difficult to tune: low thresholds interrupt benign changes, while high thresholds allow residual security risk to pass. This study evaluates a cost-sensitive decision framework that aggregates stage evidence and selects thresholds under explicit trade-offs among escaped risk, bad-block rate, and review load. The evaluation uses a deterministic campaign with 960 integration changes, 60 seeded replicates across eight stress profiles, a REST interface check, and a retrospective publication-cohort audit of 32,281 GitHub-reviewed security advisories linked to the CISA Known Exploited Vulnerabilities catalog. In the deterministic campaign, threshold 5 holds changes containing 99.35% of generated risk with one false block; across seeded campaigns, mean held-change risk coverage is 99.30% under baseline conditions. At 1% faulty-change prevalence, transported mean precision is 77.7% at threshold 5 and 29.0% at threshold 3. Stratified score permutation reduces threshold-5 held-change risk coverage to 65.25%, exposing dependence on the generator’s score ordering. In the advisory audit, a balanced unweighted point covers 96.23% of observed KEV risk at 48.58% review share, while a review-limited regularized point covers 62.26% at 3.45%. Current EPSS is stronger on the matched CVE subset, so the audit demonstrates cross-domain risk–workload analysis rather than validating the CI gate or establishing scoring superiority. The results support explicit, locally validated operating points rather than universal thresholds.
Small and medium-sized enterprises (SMEs) often face challenges in managing data privacy due to limited resources and a lack of specialized expertise. The NIST Privacy Framework provides a structured foundation for identifying and managing privacy risks, yet it offers limited practical guidance on how to operationalize its components in resource-constrained settings. This study adopts a Design Science Research approach within a Stockholm-based start-up to examine SME-specific privacy challenges and develop a structured solution.The study proposes a tailored privacy management framework that operationalizes the NIST implementation tiers as a cumulative maturity roadmap and provides actionable guidance for practical implementation. The framework is instantiated in a lightweight web application to support structured planning, task prioritization, and communication of privacy posture. The design further integrates considerations relevant to assurance readiness, including alignment with SOC 2. Evaluation through stakeholder interviews and a practitioner survey indicates that the proposed artefacts enhance privacy awareness, enable actionable planning, and provide practical value for SMEs seeking structured privacy management.
Information systems have become foundational to modern critical infrastructures, where security is of paramount importance. However, with the increasing complexity of highly dynamic and large-scale environments, traditional perimeter-based defense mechanisms, which rely on external protection and reactive responses, are no longer sufficient to counter sophisticated and evolving threats. To address this challenge, this paper proposes a dynamic Defense Model based on Bionic Mechanism (DMBM), inspired by the human immune system’s capability to distinguish “self” from “non-self” through adaptive and distributed mechanisms. The proposed model introduces an endogenous and active defense paradigm, integrating trust evaluation, dynamic defense, self-healing and immune memory. A dynamic threshold mechanism is further introduced to enhance adaptability to runtime variations and unknown attacks. Experimental results demonstrate that DMBM achieves True Positive Rate (TPR) of 97.45% with False Positive Rate (FPR) as low as 2.81%. Compared with NeuroShield, Active Defense Model based on Situational Awareness and Firewalls (SAF-ADM), Immune-Inspired Malware Detection Algorithm (IIMDA) and Federated, Trust-Aware, and Explainable Self-Healing (FTASH) architecture, DMBM improves detection accuracy by approximately 3%–10% while reducing the false positive rate by about 2%–3%. For unknown attacks, DMBM achieves detection accuracy improvement of approximately 2%–15%.
With the rapid proliferation of social media platforms, social bots have posed serious challenges by manipulating public opinion and spreading misinformation. Existing detection methods mainly fall into two categories: individual-level approaches focus on user behaviors and attributes but struggle to capture group behavioral patterns of social bots, while group-level approaches, including community-based methods and botnet detection, exploit collective structural information but can be weakened when sophisticated bots infiltrate legitimate communities through deceptive social connections. To address these challenges, we propose a multi-community feature fusion framework (MC-FF) that models users’ multi-community features to construct robust group-level representations. Specifically, MC-FF consists of three main components. First, the Multi-Community Feature Extraction module captures users’ affiliations across different communities to obtain their group-level behavioral patterns. Next, the Community-Individual Feature Fusion module integrates these group features with individual attributes, obtaining unified user representations for more comprehensive detection. Finally, the Contrastive Learning Enhancement module enforces intra-group compactness while maximizing inter-group separability in the embedding space, thereby enhancing the discriminative power of group features. Experiments on multiple social bot detection datasets demonstrate that MC-FF consistently outperforms existing approaches, effectively mitigating group feature distortion and balancing detection accuracy with computational efficiency.
Service providers collect users’ personal information not only to improve service quality but also to maximize their revenue. Recognizing the mounting privacy risks posed by such practices, regulations worldwide have been enacted to govern the collection and processing of personal data. Part of the regulatory requirement is to obtain users’ consent before collecting personal information, giving users more control over their data. However, the informed consent approach has been criticized for failing to adequately protect users’ privacy, particularly due to deceptive design and overly lengthy explanations. Drawing on the coping appraisal mechanism from the Protection Motivation Theory, this paper examines how different informed consent designs influence privacy protection behavior and the role of privacy cynicism in this context. Using an experimental design (N = 302), we manipulate two independent variables (effort and control), resulting in four experimental conditions with different consent form designs (high x low). Our results reveal that informed consent forms do not have a universal effect on privacy protection behavior and that their impact varies with the level of effort and control they exert. In addition, privacy cynicism drives individuals to become less engaged in privacy protection behaviors.
Despite the significance of the Internet in global information exchange, authorities in many jurisdictions apply censorship to online communications within their sphere of influence. Some people consider censorship a violation of human rights, such as the freedom of expression or the right to access information. Others view censorship methods as a means of social control, protecting national security or social harmony. Regardless of the motivation, researchers, policymakers, and technology practitioners should have a thorough understanding of the capabilities of Internet censors. We present a taxonomy of Internet censorship methods derived from a systematic review of the literature and analysis of the technology that has enabled the Internet’s progression. We describe the technical means that censors implement, contextualized by the legal and social circumstances in which they have occurred over the past three decades. We assert that the taxonomy has pedagogical value and serves as a research framework for further studies. Our study illuminates the dynamic challenges faced in interdisciplinary research on Internet censorship, offering direction for future work on Internet measurement, censorship circumvention, and protocol standards design.
Fuzzy hashing can identify source code duplication in compiled binary functions, with applications ranging from vulnerability detection to malware attribution, where the source code is not available. However, its application across the compilation gap has not been systematically studied. This paper studies fuzzy hashes applied to cross-compiled Binary Function Similarity Analysis (BFSA). We first propose the Stratified Abstraction Model, a taxonomy that maps how platform divergence affects binary artefacts across six analysis layers. Then, we use it to classify existing approaches, ranging from learned embeddings to fuzzy hashes. Then, we evaluate the effect of divergence across compilers, optimisation settings, bitness, and architectures to reframe what Machine Learning techniques should be expected to achieve.We conduct a large-scale evaluation of state-of-the-art fuzzy hashes, including Catalog1, FunctionSimSearch, Machoke, and CCBHash. We evaluate these techniques against uncompressed byte signatures (Position Independent Code), using a ground truth of cross-compiled functions, comprising 2.8M targets and 4.3M distractors. Under cross-architecture divergence (XA), the single-modality fuzzy hashes FCatalog and Machoke reach 8.57E−4 and 0.0978 in Mean Reciprocal Rank at 10 (MRR@10). Conversely, the weighted multi-modal algorithms, CCBHash and FunctionSimSearch, achieve 0.4671 and 0.4720 in the same scenario. Under optimisation divergence (XO), CCBHash reaches the highest values, between 0.6271 with feature weights and 0.6865 with naive, unweighted features. Our results show that fuzzy hashes may be used to detect code duplication in cross-compiled binaries, where the original source code is not available. They cannot, however, detect different source implementations with shared intent. This second gap defines where learned representations become necessary.
The research literature on employee non-/compliance with information security policies (ISPs) suffers from inconsistent findings. The aim of this paper is to investigate a promising, yet largely unexplored cause of these inconsistencies, namely, differences in how key variables have been conceptualized and operationalized into questionnaire measurement items across this literature. Specifically, by means of a survey experiment with 215 participants from a Swedish university, we formally tested whether alternative operationalizations of two key variables from Protection Motivation Theory—Perceived vulnerability and Perceived severity of a threat—lead to statistically significant differences in mean values across responder groups. Regarding the former variable, we found significant differences between operationalizations focusing on the probability and vulnerability of the threat. Regarding the latter, we found significant differences between whether the target of the consequences of the threat was unclear or clear to respondents, but not between clearly stated targets in terms of individuals and organizations. Overall, therefore, this study contributes to the field by highlighting the importance of conceptual clarity and precision in measuring key variables. It also highlights the potential of survey experiments—an underutilized method in ISP compliance research—for exploring the empirical impact of the different variable operationalizations which currently characterize much of the extant literature.
Human behavior remains a primary attack surface in everyday cybersecurity incidents, as employees make fast, routine decisions when using digital tools, communicating, and handling sensitive information in technology-rich workplaces, making cybersecurity competence (CSC) a foundational workplace capability. To foster CSC, technology-mediated training needs to go beyond awareness and enable practice in recognizing, evaluating, and responding to security-relevant situations in realistic, interactive scenarios, particularly at career entry points in vocational education and training (VET) when routines and mental models are still forming. Organizations therefore increasingly use gamified security education, training, and awareness (SETA) programs such as digital educational escape rooms (DEERs), yet longitudinal evidence for sustained CSC gains is scarce. The present study addresses this gap by evaluating a competence- and game-based learning environment using a DEER in a cluster-randomized controlled trial with VET apprentices (N=154). CSC was assessed at three time points using a validated situational judgment test, with intervention effects analysed through a latent change score model (LCSM). The intervention group started higher in latent CSC at pretest (b = 0.71, p = .023, β = .23) and showed a substantially larger short-term gain from pretest to posttest than the control group (b = 1.97, p < .001, β = .66). From posttest to follow-up, this advantage attenuated significantly (b = −0.96, p = .028, β = −.40). The findings suggest that the competence- and game-based learning environment using a DEER provides a promising, practice-oriented SETA format for VET, while underscoring the need for booster sessions and transfer-focused practice to ensure long-term effects.
We consider the problem of enforcing corporate governance control relying on cloud-based services. Extending previous work, we focus, in particular, on the support for delegation of director privileges, enabling their dynamic and temporary assignment to a vice-director. Like previous work, our control relies on encrypted tags, which are extended to address the challenges introduced by dynamic delegation which operates on a time dimension orthogonal to the corporate governance control process. Our solution enables delegation while ensuring a vice-director to enjoy the director privileges only when delegation is active, or on operations for which the vice-director has already started the director phase, and not to operate as director for operations the vice-director has processed as employee (separation of duties). Our tag construction ensures integrity of the dynamic delegation control and protection against tag tampering. Our implementation of the proposed framework, which relies on FoundationDB for persistent encrypted workflow state and OpenBao for key management, demonstrates its viability and integration with current technological solutions. The high throughput obtained in our experimental evaluation confirms the applicability of the approach and the limited impact of delegation.
Online fraud is a growing global threat, yet anti-fraud warnings rely predominantly on static visual cues vulnerable to habituation and attentional failure. Drawing on the Communication–Human Information Processing (C-HIP) model and multimodal warning theory, this study examined whether auditory-warning principles transfer to simulated online financial decision-making. A total of 175 participants completed an investment task involving a fraud scenario and were randomly assigned to one of four conditions: visual-only, visual plus auditory icon, visual plus speech, or visual plus icon and speech. Behavioral compliance and subjective evaluations across C-HIP stages were assessed. The icon-plus-speech condition had the lowest descriptive payment rate (38%, versus 68% in the visual-only baseline). Although the unadjusted comparison was significant, the difference was not confirmed after Tukey or false discovery rate correction. Nevertheless, compared with speech alone, icon plus speech produced significantly higher text noticeability, perceived alertness, and suspicion after FDR correction. Exploratory analyses also identified suggestive gender-related patterns across selected processing outcomes. Overall, the evidence does not support a firm conclusion that auditory augmentation is behaviorally superior to visual-only warnings in fraud contexts. However, auditory configurations differed significantly in specific measures of early and evaluative stages of warning processing. These findings provide an initial basis for systematically investigating how warning configuration may influence protective behavior in fraud settings.
With the rapid development of the Internet of Things and mobile crowdsensing, collecting multidimensional numerical data while preserving users’ privacy has become a critical challenge. Existing (ϵ,δ)-local differential privacy (LDP) mechanisms typically adopt dimension sampling to alleviate privacy-budget splitting. However, these methods persistently rely on two-valued extreme perturbation structures, which increase estimation variance. To overcome this limitation, this paper proposes a multidimensional interval-based perturbation mechanism (MIPM). Rather than using two-valued extreme outputs, MIPM maps the original data to a three-interval distribution and assigns a higher probability to the input-dependent middle interval, thereby reducing single-dimensional perturbation variance. Furthermore, to balance dimension coverage against per-dimension noise, the selection of the sampling dimension k from d dimensions is formulated as a theoretical variance-minimization problem. The variance-minimizing sampling dimension is derived under each of the minimum worst-case variance (MWCV) and minimum average expected variance (MAEV) criteria to replace previous empirical approximation rules. We provide rigorous theoretical proofs of unbiasedness and multidimensional (ϵ,δ)-LDP guarantees, complemented by detailed security and complexity analyses. Extensive experiments on two synthetic and two real-world datasets demonstrate that the proposed MIPM consistently achieve lower estimation errors and tighter confidence intervals than Mechanism-2/MEMND, with MIPM-MAEV and MIPM-MWCV reducing the mean squared error (MSE) by an average of 53.7% and 46.2%, respectively.
Security standardization can improve product security while maintaining interoperability across manufacturers. We examine whether this holds true for the Internet-of-Things (IoT) by analyzing Bluetooth LE (BLE), a widely adopted industry standard. We also survey the international standardization landscape for IoT security, finding that Smart Home security will soon be addressed by dedicated ISO 27xxx standards. To assess real-world compliance, we developed an automated sniffing tool that analyzes the BLE pairing process between IoT devices and their companion smartphone apps, identifying whether devices use the security mechanisms prescribed by the BLE standard. Our results are concerning: fewer than 5% of tested devices implemented a secure pairing method as specified by the standard. Most devices either used weaker standard mechanisms or none at all. Notably, some manufacturers went further in the wrong direction – rather than using the secure pairing mechanisms built into the smartphone’s operating system, they replicated or simulated higher-security pairing within their own proprietary app protocols. This approach undermines the very purpose of standardization and suggests that regulatory pressure, such as the emerging EU framework, may be necessary to drive meaningful security compliance in the IoT ecosystem.