
Logistics organizations depend on software whose quality determines whether digital transformation delivers its operational benefits, yet formal quality evaluation against internationally standardized frameworks is systematically absent in both research and practice. Three interconnected gaps define this research problem: logistics IS practice focuses on functional capabilities rather than quality characteristics; ISO/IEC 25010:2023, the authoritative international standard for software product quality, has never been comprehensively applied to logistics software; and security evaluation remains insufficiently addressed despite mandatory requirements introduced by the EU Cyber Resilience Act. This study addresses these gaps through a systematic literature review conducted under PRISMA 2020 guidelines, encompassing 224 articles from 554 raw records identified across six bibliographic databases — 63% published between 2019 and 2026 — organized into eight thematic groups: blockchain, IoT, Industry 4.0, IT platforms, service quality, cybersecurity, software quality standards, and supply chain digitalization. Of these, only 11 explicitly reference ISO/IEC 25010, and only five apply it directly to logistics software. The review establishes a consistent hierarchy of quality imperatives: compatibility and functional suitability appear in 60% of articles each, reliability in 46%, maintainability in 45%, and interaction capability in 36%, while security appears in only 21% despite its cross-cutting regulatory relevance. These findings provide logistics organizations with an evidence-based quality checklist for software evaluation; developers with design guidance calibrated to logistics demands; and regulators with the empirical foundation for domain-adapted evaluation instruments under the EU Cyber Resilience Act. The study contributes the first systematic literature review explicitly applying a dual logistics-domain and ISO/IEC 25010:2023 lens. On this basis, it proposes a preliminary logistics software quality profile that prioritizes the ISO/IEC 25010 characteristics and links them to logistics indicators, candidate metrics, and evidence types across the principal logistics system types.
Personally identifiable information (PII) detection is foundational to privacy-preserving analytics, compliant data sharing, and safe model training. Traditional rule-based and supervised named entity recognition (NER) pipelines excel on templated fields but are brittle under domain drift and long-tail variants, motivating large language models (LLMs) that generalize via in-context learning. Despite rapid LLM progress, we lack systematic and cross-domain evaluations that reflect redaction-centric error costs and practical deployment constraints. This paper presents an LLM-centric benchmark of PII detection across three textual domains and introduces a carefully annotated multimodal PII dataset to extend beyond text-only settings. Our experiments examine zero-shot and few-shot prompting, quantify prompt sensitivity, and characterize privacy-relevant error modes. We further assess a privacy-oriented, cost-aware baseline that combines a small open-source model with a multi-agent retrieval-augmented workflow, analyzing performance and feasibility for resource-constrained environments. Results highlight domain and modality effects, consistent gains from few-shot prompting (with saturation effects), and precision–recall trade-offs that vary across tasks and models. The proposed agentic retrieval augmented generation (RAG) pipeline approaches, and in some cases exceed the performance of large proprietary models while improving privacy posture and operational cost. The prompts and the multimodal dataset are made publicly available to support reproducibility and future benchmarking.
Ensuring semantic consistency between formal system models and natural-language requirements remains a major bottleneck for scalable Model-Based Systems Engineering (MBSE). While SysML v2 introduces enhanced expressiveness and richer semantics, existing validation approaches primarily focus on syntactic correctness and provide limited support for assessing standards-aligned requirement satisfaction.This paper presents a deterministic multi-agent framework for the automated semantic validation of SysML v2 models, explicitly grounded in requirements engineering standards. The approach decomposes the evaluation process into five specialised reasoning agents covering model abstraction, requirement normalisation, semantic judgement aligned with ISO/IEC/IEEE 29148:2018 “Systems and software engineering — Life cycle processes — Requirements engineering” quality attributes, coverage metric aggregation, and feedback generation with code-level patch synthesis. The architecture is implemented as a typed state machine using LangGraph, ensuring traceable, auditable, and reproducible evaluation workflows.The framework is evaluated on a curated dataset of 14 SysML v2 models and their associated requirements, derived from official specifications. A comparative analysis using two Large Language Models (GPT-4o-mini and DeepSeek-R1) shows that the two backends agree on well-specified models and diverge on under-specified ones, where they exhibit different degrees of strictness when detecting missing or partially satisfied requirements. Results show that the proposed pipeline reliably detects semantic inconsistencies, partial fulfilment, and missing requirements.Beyond evaluation, the system generates standards-aligned diagnostic reports and actionable model improvements, supporting iterative refinement. The proposed approach contributes a scalable and interpretable method for standards-driven semantic validation, bridging the gap between informal requirements and formal system models within modern software and systems engineering workflows.
With the rapid advancement of cloud computing and IoT, outsourcing spatial data computation has become essential yet raises critical privacy concerns, particularly for high-dimensional data with multi-keyword constraints. To tackle these challenges, we propose PPFS, a cloud-edge-end privacy-preserving framework for queries over high-dimensional geospatial data. This framework incorporates a sophisticated enhanced asymmetric scalar-product-preserving encryption (EASPE) algorithm with spatial dimensionality-reduction encoding and enforces fine-grained access control via ciphertext-policy attribute-based encryption, thereby enabling expeditious multi-keyword queries over encrypted high-dimensional data. To further bolster scalability and enhance query efficiency, specifically, we develop an extended scheme, termed PPFS+, which leverages a tree-based index to achieve sub-linear query latency and superior performance. Comprehensive evaluation using large-scale, real-world geospatial datasets demonstrates that our framework achieves retrieval speeds nearly 4 & times; faster than current advanced schemes and realizes higher scalability. Furthermore, rigorous security proofs verify that the proposed schemes achieve IND-CPA and IND-CKA resilience in the generic bilinear group model. These empirical and theoretical results validate that PPFS/PPFS+ provide practical, efficient, and provably secure solutions for authorized high-dimensional geospatial data queries in mobile-edge environments.
This review highlights the findings of studies conducted during 2020-2026 on the application of graph neural networks (GNNs), large language models (LLMs), knowledge graphs, and graph-based retrieval approaches (GraphRAGs) to intelligent information systems. These findings have been grouped into a single study framework, namely the framework for intelligent information systems integration, which covers various aspects of integration. The paper provides a unified systems-level approach to linking architectural design decisions with retrieval and reasoning behavior in graph-language systems. Based on a carefully selected set of system-level studies, the authors show that across the reviewed studies, graph-preserving approaches are reported to improve multi-hop reasoning, evidence localization, and interpretability compared with text-only or graphserialization baselines in several benchmark settings. Good performance is highly dependent on high-quality graph construction, proper retrieval, and the costs of the entire process. The use of graph-language synergy is most effective when the graphs serve as functionally involved parts of retrieval and reasoning, rather than merely as background information.
Accountable anonymous credentials protect user privacy while enabling the tracing of malicious behavior, making them a crucial mechanism for privacy-preserving authentication and blockchain applications. The most secure existing schemes rely on a hidden committee to perform identity tracing. However, such mechanisms face challenges in maintaining member anonymity, while also suffering from high computational and communication overhead, difficulties in monitoring and holding committee members accountable, and potential identity leakage through voting interactions, which ultimately affect system efficiency and privacy guarantees. To overcome these challenges, this paper proposes DA-Cred, a dual-accountable anonymous credential system that achieves dual accountability for both users and committee members based on an Accountable Dynamic Hidden Committee (ADHC). Our scheme introduces an efficient Hidden Committee Public Key Selection Protocol (KSS) to support random and anonymous committee selection. Moreover, by leveraging structure-preserving signatures, bilinear accumulators, and group signatures, we construct the ADHC, which enables threshold-based user identity tracing and verifiable accountability for malicious committee members. Finally, we conduct a comprehensive analysis of the security and practicality of DA-Cred and compare its performance with existing works. The assessment demonstrates that DA-Cred achieves a reduction of more than 25% in computational overhead while simultaneously strengthening privacy and accountability, demonstrating excellent practicality.
The rapid advancement of the Internet of Vehicles (IoV) necessitates robust solutions that balance user privacy with efficient service delivery, particularly for personalized charging station recommendations. This paper proposes a lightweight anonymous authentication and secure computing service integration scheme based on distributed center architecture. By leveraging a distributed dual-cloud architecture, the scheme ensures secure and traceable anonymous authentication while facilitating efficient vehicle-to-service communication. Vehicle users encrypt their preference data, which is processed using matrix factorization and secure multi-party computation to deliver accurate, privacy-preserving charging station recommendations. The quick reconnection mechanism we established reduces re-authentication time costs by roughly 53 percent, while the dual-server architecture supports privacy computing for vehicles after authentication. The framework integrates multi-source heterogeneous data, such as real-time traffic and charging station status, to enhance recommendation accuracy and timeliness. Experimental results demonstrate that the proposed approach achieves strong anonymity, traceability, and low-latency performance, offering a practical and scalable solution for secure, intelligent IoV services.
To raise awareness of the environmental impact of deep learning (DL), numerous studies have estimated the energy consumption of DL systems. However, energy estimates during DL training often rely on unverified assumptions. This work addresses that gap by investigating how model architecture and training environment affect energy consumption. We train a variety of computer vision models and collect energy consumption and accuracy metrics to analyze their trade-offs across configurations. Our results show that selecting the right model-training environment combination can reduce training energy consumption by up to 80.68% with less than 2% loss in F1 score. We find a significant interaction effect between model and training environment: energy efficiency improves when GPU computational power scales with model complexity. Moreover, we demonstrate that common estimation practices, such as using FLOPs or GPU TDP, fail to capture these dynamics and can lead to substantial errors. To address these shortcomings, we propose the Stable Training Epoch Projection (STEP) and the Pre-training Regression-based Estimation (PRE) methods. Our evaluation demonstrates that STEP and PRE achieve reductions in Root Mean Squared Error (RMSE) up to 97% and 84%, respectively, when compared to existing estimation tools.
Secure and reliable image transmission has become increasingly important for protecting confidential visual data. However, existing image encryption techniques still face challenges in achieving an effective balance between security, computational complexity, and robustness against various attacks. To address these limitations, we proposed a novel image encryption scheme that first employs the Secure Hash Algorithm (SHA-256) to generate a 240-bit master key. The two-dimensional Infinite Collapse Map (2D-ICM) is utilized to generate chaotic sequences for two-round permutation using the sub-keys derived from the master key. Subsequently, the permuted pixels are encoded into Deoxyribonucleic Acid (DNA) sequences and grouped into multiple sets, each containing four sequences. These sets undergo a unique DNA-based diffusion process achieving effective diffusion of all sequences at the nucleotide level. To ensure robust security, the cipher image is generated by applying XOR operations between the diffusion-processed sequences and the chaotic masked image. This scheme is evaluated on public datasets, including chest X-rays, fingerprints, the USC-SIPI database, and standard test images. The proposed scheme achieves an average entropy value of 7.997, NPCR of approximately 99.60%, and UACI close to the theoretical value of 33.46%, while maintaining low correlation coefficients and improved histogram uniformity. Moreover, robustness evaluations under noise and cropping attacks demonstrate reliable image recovery under transmission disturbances. The results indicate that the proposed approach provides an effective and efficient solution for secure grayscale image encryption.
Advanced Persistent Threat (APT) groups represent some of the most sophisticated and persistent actors in the cyber threat landscape, often linked to nation-states and characterized by long-term, covert operations targeting critical infrastructure. Despite growing academic and industry attention, existing research remains fragmented, with inconsistencies in group profiling, activity classification, and countermeasure frameworks. This study addresses these gaps through a systematic literature review of 57 peer-reviewed articles, complemented by industry threat intelligence. It presents a unified framework that integrates three core components: (i) a historical and behavioral analysis of major APT incidents and tactics, (ii) a classification of APT groups by activity status and regional patterns, and (iii) a comprehensive taxonomy of countermeasures grounded in observed threat behaviors. The taxonomy spans eight domains, including Detection, CTI, Operations, Risk Assessment, Policy, New Attacks Countermeasures, Attribution, Conceptual Countermeasures, and Deception. By linking APT group behaviors to tailored defense strategies, this work enhances the clarity, consistency, and applicability of APT research. The findings offer a foundation for improved threat tracking, collaborative defense, and future research on profiling methodologies and adaptive countermeasures.
Social Federated Computing enables collaborative computation over distributed user-held data in social systems while preserving data locality and participant autonomy. To mitigate gradient inversion-based privacy leakage, intermediate updates are commonly protected through encryption, which fundamentally reduces system observability and weakens conventional poisoning detection mechanisms. This loss of observability introduces new security risks, including ciphertext-level poisoning, while exhaustive cryptographic auditing and verification incur prohibitive computational and communication overheads at scale. These inherent conflicts lie between privacy preservation, detection capability, and operational efficiency in encrypted Social Federated Computing environments. In this paper, we propose an evolutionary game-theoretic defense framework for encrypted Social Federated Computing to model and regulate these inherent conflicts. The framework captures two defining characteristics of social federated environments: adversarial behaviors that propagate along social relationships and organizational constraints, and participants that operate under partial information and exhibit locally rational behavior rather than global rationality. Server-side detection intensity and client-side poisoning propensity are modeled as co-evolving strategies under partial observability, explicitly accounting for false positive penalties, external incentives that motivate poisoning, and practical deployment constraints such as energy budgets. Through equilibrium and stability analysis, we characterize how defense policies adapt to varying costs, incentives, and resource limitations, and we identify stable strategy regimes across representative deployment scenarios. The proposed framework yields deployment-oriented guidance for tuning server-side defenses, enabling adaptive and cost-aware mitigation of ciphertext poisoning in large-scale encrypted Social Federated Computing systems.
Attribute-based searchable encryption (ABSE) is a fundamental primitive for secure data sharing and outsourcing. However, to enhance post-quantum security, existing lattice-based ABSE schemes suffer from two critical limitations: vulnerability to (insider) keyword guessing attacks (KGA) and the inability to verify the correctness of outsourced search results. In this paper, we propose a verifiable attribute-based searchable encryption scheme based on the ring learning with errors (RLWE) assumption. Our construction preserves fine-grained access control while achieving resistance against (insider) KGA and enabling the verifiability of search results. We formalize comprehensive security models capturing multi-keyword ciphertext and token scenarios, and prove indistinguishability under the RLWE assumption. Theoretical and experimental evaluations demonstrate that, for complex access policies, our scheme achieves speedups of approximately 6× and 660× in encryption, and 16× and 940× in token generation over LWE schemes. This efficiency makes it highly suitable for practical post-quantum cloud environments.
In cloud storage, data owners can use data integrity auditing mechanisms to authorize third-party auditors (TPA) to perform real-time verification of whether the stored cloud data remains intact. When data stored in the cloud needs to be transferred from a previous user (PU) to a new user (NU), it is only necessary to transfer data ownership from the PU to the NU, not the physical data itself. To address this issue, researchers have proposed several Provable Data Possession (PDP) schemes that support ownership transfer. However, in most existing schemes, the transfer of data ownership relies on a secure channel. It is well known that achieving an absolutely secure channel in the real world is challenging. To solve this problem, we propose a Certificate-Less Provable Data Possession (CL-PDP) scheme, which supports the transfer of data ownership without any additional secure channels. Security analysis shows that the scheme achieves unforgeability of authenticators, non-deceptiveness of proof information, and non-stealability of data. Performance analysis indicates that compared with existing schemes, this scheme has significant efficiency advantages in the data ownership transfer phase.
Threshold encryption is becoming a significant part in modern cryptography and is standing as a central focus of the upcoming NIST competition. An active branch in this field is Threshold Broadcast Encryption (TBE), which integrates threshold settings into the broadcast encryption paradigm. In a TBE scheme, a sender can arbitrarily select a target set of recipients to encrypt a message; decryption is successful if and only if at least t users within that set collaborate, where t represents the predefined threshold. Despite its utility, existing TBE literature is largely restricted to single-message, single-group scenarios. This constraint makes TBE impractical for modern platforms, such as social media and streaming services, which requires to efficiently deliver diverse content to multiple distinct groups of viewers simultaneously.To address this limitation, we first establish formal definitions for a new primitive: Multi-group Threshold Broadcast Encryption (MTBE), which supports the encryption of one or more messages that are sent to multiple target groups. As a proof of concept, we then propose the first Identity-based MTBE construction. Our scheme achieves constant-size ciphertexts, being independent of the number of recipients or groups. We also implement our proposed scheme to give some concrete benchmarks.
Federated learning (FL) enables collaborative training of medical AI models without centralized patient data sharing, but practical healthcare deployments face significant challenges due to dynamic participant availability (clients unpredictably joining or dropping out) and non-identically distributed (non-IID) data. These factors can severely degrade model accuracy and convergence. To address these issues, we propose a novel FL framework integrating dynamic masking, adaptive dropout recovery, and differential privacy. Our dynamic masking approach securely encrypts client updates with randomized masks, allowing the server to reconstruct missing updates when clients unexpectedly drop out, thereby ensuring robust and secure aggregation. The adaptive dropout-recovery mechanism compensates by intelligently re-weighting remaining clients’ contributions or reusing the last available update from dropped clients, thereby stabilizing training despite participant variability. Furthermore, differential privacy noise injection rigorously controls information leakage, aligning the framework with stringent medical privacy regulations. Extensive experiments conducted under realistic medical federated scenarios demonstrate that our approach significantly improves model robustness, consistently achieving higher accuracy and faster convergence compared to baseline methods. Specifically, our results illustrate that the proposed method maintains strong performance even in highly dynamic, heterogeneous environments, preserving model utility while ensuring rigorous privacy guarantees. Therefore, our framework effectively addresses practical challenges in medical FL deployments, providing a reliable, privacy-compliant solution particularly suited to healthcare scenarios characterized by dynamic participation and data heterogeneity.
Chaos-based encryption has attracted growing interest for resource-constrained embedded systems, yet its practical use remains limited by sequential processing overhead, precision-related degradation, and implementation cost. This study presents a hardware-aware framework for accelerating chaos-based encryption through the joint optimization of fixed-point chaotic keystream generation, a pipelined XOR/permute datapath, and entropy-driven adaptive control. To compare candidate implementations in a unified manner, we introduce the Cryptographic Throughput Index (CTI), a composite design metric that jointly reflects encryption rate, ciphertext entropy, and hardware cost. Using representative chaotic generators, the study shows how different maps lead to distinct trade-offs between throughput, entropy preservation, and implementation footprint in constrained hardware environments. The paper also outlines a reconfigurable Crypto-IP architecture suitable for FPGA/ASIC-oriented IoT platforms and derives practical design rules for selecting chaos models, precision levels, and operating modes under hardware budgets. Overall, the work contributes a methodological basis for structuring and evaluating high-throughput, entropy-aware chaos-based encryption architectures for embedded systems.
Fraud detection is critical in financial transactions, as failures can lead to monetary losses, erosion of customer trust, and long-term reputational damage. Standard systems are often unable to enhance detection accuracy with minimal data, which limits their ability to adapt to evolving fraud tactics and identify complex fraud behaviors. To mitigate this issue, a Snow Carpet Weaver Optimization-based Spiking Neural Network (SCWO-SNN) is designed to detect fraud in Unified Payment Interface (UPI) transactions using Federated Learning (FL). The entities involve nodes and servers. The local training process begins with using local data, after which it updates the server with the results. Afterward, the server aggregates the models and downloads the global model to the nodes, iterating the training process at each epoch. Input data normalization is achieved through Comprehensive Normalization during model training, and Snow Carpet Weaver Optimization (SCWO) is used for feature selection. Data augmentation is conducted through the Borderline-SMOTE oversampling technique. Finally, fraud detection is done by a Spiking Neural Network (SNN) that is tuned by SCWO. At the server, local updating and aggregation are transformed using the Average method. The evaluation measures of the proposed SCWO-SNN are Loss function, Normalized Mean Squared Error (MSE), Normalized Root Mean Squared Error (RMSE), Precision, Recall, and F-measure, which obtained superior values of 0.119, 0.197, 0.443, 91.400%, 91.275%, and 91.448%, respectively.