
In mobile banking, voice phishing (vishing) attacks have become widespread, in which the user is manipulated into voluntarily transmitting their one-time password (OTP). Rule-based systems that operate after the transaction detect this threat only after the financial loss has occurred. This study proposes OTP-BCAD, an explainable behavioral risk intelligence framework that detects fraud before transaction approval, during the active banking session. The hybrid architecture comprises four components: an LSTM Autoencoder and IsolationForest ensemble that learns each user's behavioral baseline; a Risk Intelligence Module producing a Behavioral Risk Score (BRS), a Trust Score, and a four-level risk classification; PC-algorithm- and SHAP-based explainability; and a Decision Support System producing operational intervention decisions. Lacking publicly available OTP-fraud-labeled data, a synthetic dataset of 500 users and 24,000 records was generated with reference to the BehavePassDB structure, with fraud scenarios defined in a controlled (simulation-defined) manner. Evaluation used user-based 5-fold StratifiedGroupKFold at the session level to prevent structural leakage. Within each fold, the LSTM Autoencoder is calibrated per user on that user's own sessions 1–4, while the Random Forest classifier is trained on the pooled feature vectors of the training users; the model therefore combines a personalized anomaly component with a globally trained decision component. The framework attained F1 = 0.713, ROC-AUC = 0.950, MCC = 0.676, and specificity = 0.944. A six-configuration ablation showed that removing the LSTM Autoencoder reduced F1 by 0.193 points, identifying it as the principal discriminative component. Compared with thirteen classical and five deep-learning models, OTP-BCAD achieved a higher F1, with differences significant under the McNemar test (p < 0.001). The reported metrics reflect a controlled synthetic setting, and real-world validation is left to future work.
Malware stands for MALicious softWARE that aims to compromise digital systems and devices, interrupt services, and leak sensitive information. The antiviruses’ detection capability is largely experimented by companies and organizations. However, such experiments: (i) focus only on the antiviruses’ detection rate, without performing any in-depth analysis, and (ii) often report an almost perfect antiviruses’ detection capability achieved under not clearly documented experiments’ setup. This paper reports on two experiments conducted to evaluate the detection capability of antiviruses, explore the role of defense evasion techniques, and the use of crowd-sourced detection rules. While the first experiment has been conducted installing the antiviruses locally, the second and larger one has been conducted via VirusTotal, an online multi-antivirus platform. The results show that: (i) a non-trivial percentage of malware samples (up to 26.8
Electromagnetic side-channel analysis provides a non-intrusive approach to malware characterization in settings where host-based instrumentation is unavailable, undesirable, or too costly to deploy. In practice, however, the usefulness of this approach depends not only on predictive performance but also on whether the selected models remain practically deployable under constrained hardware resources. This paper presents a controlled cross-platform evaluation of electromagnetic malware classification under resource-limited deployment conditions. A single corpus of electromagnetic traces acquired from a Raspberry Pi 5 using the EM-Sense acquisition workflow is reused unchanged throughout the study. This fixed dataset is used to train and evaluate four classical machine-learning pipelines (LDA+NB, LDA+SVM, LDA+RF, and LDA+XGBoost) and four neural architectures (MLP, CNN, RNN, and GRU) across four labeling granularities: Packer, Virtualized, Type, and Family. The same experimental protocol is executed on a virtual machine and three representative edge platforms (Raspberry Pi 5, Jetson Nano, and Jetson Orin Nano), allowing the influence of computational resources to be isolated from the acquisition process. The results show a clear task-dependent trade-off. In the coarse-grained classification tasks, the classical pipelines provide the most favourable accuracy–cost balance while remaining computationally inexpensive across all evaluated platforms. In the finer-grained tasks, the neural architectures achieve higher predictive performance, although at a substantially greater computational cost. The experiments also identify a practical deployment boundary on Jetson Nano, where the more demanding neural configurations no longer retain a practically useful GPU-accelerated operating mode. Under the evaluation conditions considered in this study, these findings support a resource-aware approach to model selection for electromagnetic malware classification on edge platforms.
Blockchain has attracted growing interest in the e-government industry since its decentralized architecture can alter how public information is recorded, verified and shared. However, existing research has focused primarily on technical, economic and administrative benefits such as security, efficiency, transparency and data integrity, paying less attention to the potential political implications of blockchain for social equity and the socio-democratic functions of digital government. This study examines how blockchain-driven data management may contribute to more egalitarian e-government service through the interconnected dimensions of distributive justice, procedural equity and capability enhancement. The research adopts a scatter-gun approach design combining expert interviews, focus group discussions and content analysis of blockchain-driven technology adoption and data management models with the main goal to identify promising cases and models of implementation in the area. As a result, the analysis identifies four socioeconomic domains in which blockchain-enabled e-government may have particular relevance: collaborative urban planning and e-participation, social security management, migration governance and public healthcare. Based on expert knowledge and collaborative model development, the study develops four illustrative frameworks involving blockchain-driven urban planning e-voting, decentralized pension and welfare tracking, interconnected registries and verifiable digital credentials for migration management and peer-to-peer recording of healthcare information. The findings suggest that blockchain may strengthen the traceability of public resources and decisions, expand opportunities for participation, improve the portability and verification of personal credentials and increase individual control over sensitive information. However, these benefits are not automatic. Technical complexity, digital exclusion, data governance concentration, privacy risks and algorithmic bias, especially from influential actors, may reproduce or intensify existing challenges of information governance and thus decision making in the area. In this regard, the study contributes a conceptual framework linking blockchain architecture with egalitarian digital governance and an informed agenda to evaluate blockchain adoption in sociodemocratic and socioeconomic e-government. It concludes that blockchain should be assessed not as an inherently egalitarian technology, but as a sociotechnical infrastructure whose contribution to social equity depends on inclusive institutional design, accessibility and accountable information governance against intrusion or unauthorized data tampering.
Advanced Persistent Threats (APTs) pose a severe and growing risk to financial technology Fintech ecosystems, in which cloud services, open APIs, and complex software supply chains continually expand the attack surface. This paper presents the P.A.C.T. Framework, an integrated defense architecture organized around four mutually-reinforcing pillars: Proactive threat anticipation using predictive attack-path modelling and deception; Adaptive response driven by AI-based behavioral analytics; Collaborative intelligence sharing based on privacy-preserving cryptographic protocols (private set intersection, homomorphic encryption, and differentially-private federated learning); and Trustless verification using hardware attestation and Merkle-tree audit logs. We evaluate the framework on three public benchmark datasets (CICIDS2017, UNSW-NB15, and CTU-13) and a purpose-built financial-sector APT dataset. An anonymized historical log corpus drawn from 847 institutions is used solely as a baseline reference for scale and diversity; it does not constitute active operational validation. Active validation was obtained separately through a six-month operational pilot at 23 institutions. In laboratory evaluation the framework attained 94.7
The widespread use of manipulated and synthetic images in cybercrime, identity fraud, and misinformation campaigns has created serious threats to digital trust and multimedia security systems. As image manipulation techniques continue to advance, reliable localization of tampered regions has become a critical requirement for digital forensic analysis. Existing image manipulation localization approaches, including handcrafted feature-based methods and convolutional neural networks (CNNs), often suffer from limited flexibility or insufficient sensitivity to subtle forensic artifacts. CNN-based models may overlook fine-grained traces, while handcrafted approaches rely on rigid assumptions that hinder generalization. To address these limitations, this paper proposes a multi-branch hierarchical framework with four core innovations: (1) a dual-branch architecture processing noise residuals (Bayar and SRM convolutions) and frequency-domain features (DCT-based decomposition) in parallel; (2) a noise–frequency feature fusion strategy within a separate encoder–decoder backbone; (3) a dual attention mechanism capturing long-range spatial and cross-channel dependencies; and (4) a hierarchical encoder–decoder design with skip connections for precise pixel-level localization. Experimental evaluations on benchmark forensic datasets, including CASIA, COVERAGE, COLUMBIA, and NIST16, demonstrate that the proposed framework achieves competitive detection performance and robustness across most datasets, attaining an AUC of up to 0.998 on NIST16, while highlighting specific failure modes on challenging cases such as COVERAGE. The proposed system can be integrated into digital forensic pipelines and security platforms to support proactive detection of counterfeit image attacks.
DeepFakes pose significant risks to digital security by enabling realistic facial manipulations that can evade conventional visual inspection. This study presents an attention-enhanced EfficientNet-B7 framework with a Custom Soft Spatial Attention (CSSA) module designed to localize manipulation-sensitive facial regions, including eye boundaries, mouth contours, blending boundaries, and skin-texture discontinuities. Evaluation is conducted on three benchmarks, a balanced Kaggle image subset containing 20,000 facial images, Celeb-DF (v2) with 50,000 sampled frames, and FaceForensics++ Low Quality with 40,000 sampled frames. The proposed model achieves 93.28
Deep learning-based malware detectors remain highly vulnerable to adversarial attacks. While individual defense mechanisms such as denoising autoencoders, adversarial training, and generative networks have been explored separately, their orchestrated integration into a unified, multi-layer defense pipeline remains an open challenge. This paper introduces DefendMal, a novel framework that synergistically combines Denoise Autoencoder with Sequence Squeezing (DA-SS), a Context-aware Adversarial Generator (CAG-AdvGAN), Projected Gradient Descent (PGD) adversarial training, and a Positive–Negative Detector with Variational Autoencoder (PNDetector-VAE) to enhance robustness against evolving adversarial threats. Unlike prior works that focus on isolated defenses, DefendMal employs a cascaded defense strategy that sequentially preprocesses inputs, generates adaptive attacks, hardens the model, and detects poisoned samples. We evaluate DefendMal on a curated malware-inspired adversarial dataset derived from image-based perturbations, serving as a reproducible proxy for malware feature space. Our results demonstrate that DefendMal achieves 97
Automated symbolic analysis for race condition detection is critical for identifying vulnerabilities in consumer off-the-shelf software, where source code is unavailable. However, the triple-threat of symbolic state explosion, thread interleaving complexity, and semantic information loss in binaries often renders these techniques impractical for production scale security analysis. This paper evaluates seminal race condition detection approaches over the last 2 decades against a novel taxonomy which helps determine how they address the challenges mentioned. Through a systematic review of 34 contemporary approaches, we identify a significant disconnect between tool capability and evaluation rigor. Our analysis reveals that 74 ≈ 10 binaries on average) for performance claims. Furthermore, we find that fewer than 10
Malicious URLs are a primary delivery vector for phishing, malware distribution, and various web-based cyberattacks. Their large-scale generation and rapid evolution make automated detection systems essential for modern cybersecurity infrastructures. However, multiclass malicious URL detection remains challenging due to class imbalance and structural similarities among benign and malicious URL categories, which may degrade classifier stability and category-level consistency. To address this challenge, we propose a hierarchical binary classification framework that decomposes the multiclass task into a sequence of structured binary decisions. We evaluate the proposed approach on two benchmark datasets: ISCX-URL2016 and Kaggle Malicious URLs. For feature representation, we extract handcrafted lexical–structural features (MANU), transformer-based contextual embeddings (BERT), and their hybrid fusion (MANU_BERT) to capture complementary URL characteristics. To reduce downstream feature dimensionality, we apply evolutionary feature selection techniques, including Genetic Algorithm (GA), Population-Based Incremental Learning (PBIL), and Grey Wolf Optimization (GWO), and construct compact feature subsets. Comparative experiments with classical machine learning and ANN-based flat multiclass models show that the proposed hierarchical framework provides competitive and feature-efficient classification performance. Using the MANU_BERT_FS representation, the proposed method achieves 0.9954 accuracy and 0.9938 F1-score on ISCX-URL2016, and 0.9887 accuracy with 0.9857 F1-score on the Kaggle dataset.
The rapid growth of the Android application market has been accompanied by a growth in the number of types of malware that use permissions, components and application metadata to filter out malware. Traditional static analysis techniques tend to have problems in dealing with class imbalance, sparse family labels, and overfitting in a multi-class case. This work presents an improved static-analysis machine learning approach based on Android malware analysis that works at the type and family level. Building on permission-centric techniques, the framework is based on activity-level and component-level features extracted from the Android manifest that enhance the discriminativeness of the framework and keep it interpretable. The data set consists of 429 applications that were consolidated into 4 types of malware and 14 families. To control the severe imbalance, conservative resampling and stratified evaluation are implemented. For the type level detection, a stacking ensemble made of Random Forest, Gradient Boosting and Logistic Regression with 92.25
Traditional rule-based intrusion detection systems are increasingly ineffective against modern and rapidly evolving cyber threats, creating the need for intelligent and scalable intrusion detection frameworks supported by realistic datasets. Existing IDS benchmarks often suffer from limitations such as outdated attack scenarios, limited multiclass coverage, and insufficient realism in traffic generation and monitoring environments. Therefore, this paper aims to develop an intelligent end-to-end threat-hunting framework supported by a novel large-scale multiclass intrusion detection dataset generated within a controlled cybersecurity laboratory environment designed to emulate realistic network conditions. The proposed dataset contains more than 7 million labeled network packets, including benign traffic and 15 modern cyberattack categories such as MITM ARP Spoofing, SSH/FTP brute-force attacks, SQL Injection, XSS, Port Scanning, Remote Code Execution, SYN Flood, and multiple DDoS variants. The proposed framework integrates realistic traffic generation, data acquisition, preprocessing, feature engineering, multiclass labeling, and intelligent intrusion detection using several supervised ML and DL models, including Naïve Bayes, Logistic Regression, Random Forest, Decision Trees, Feedforward Neural Networks, Multi-Layer Perceptron, and Convolutional Neural Networks. Traffic generation and monitoring were performed using real-world attacker tools and security platforms, including Kali Linux, Snort, Suricata, Wireshark, pfSense, and OWASP BWA. Experimental results demonstrate that the Decision Tree model achieved the highest overall performance, with detection accuracy reaching 99.9
The growing complexity, size, and dynamism of cyber threats have revealed inherent weaknesses of the traditional, static cybersecurity models. Attackers nowadays take advantage of artificial intelligence, automation, and adversarial learning methods to avoid detection, create new variants of attacks, and maintain long-term intrusions. In response, cybersecurity research has turned to self-evolving cyber defense systems that can engage in constant learning, autonomous decision-making, and co-evolution with intelligent attackers. This review includes a systematic synthesis of the studies on self-evolving cyber defense with a focus on the merging of artificial intelligence, autonomy, and adversarial learning. We discuss the evolution of cyber threats, machine learning and deep learning approaches for adaptive threat detection, as well as autonomous defense systems enabled by reinforcement learning and multi-agent systems. The review also explores the adversarial machine learning as a source of emerging threats and a powerful defense foundation with focus on the co-evolution of the attackers and the defenders. In addition to algorithmic views, the paper has provided an overview of system architectures, evaluation measures, ethics and legal aspects, and real-life implementation of industrial applications in critical infrastructures, military systems, financial services, smart cities, and cyber-physical environments. The major issues concerning scalability, resistance to adaptive opponents, lack of information, and the interaction of humans and AI are addressed. Lastly, the review presents directions of future research, such as entirely autonomous defense ecosystems, hybrid neuro-symbolic systems, quantum-resilient AI security, and intelligence sharing across domains. This work brings together dispersed research in various fields to offer a reference and roadmap on how to progress to the next generation of self-evolving cyber defense systems.
To enhance pandemic response in COVID-19, Google and Apple introduced the Exposure Notification (EN) system - a decentralized, Bluetooth-based framework enabling contact tracing applications to evaluate and mitigate exposure risks. As the EN system is expected to evolve in upcoming versions to address future pandemic scenarios, characterizing and addressing its current attack vectors and vulnerabilities is critical to ensuring its effectiveness and robustness in future public health responses. Existing literature studies have revealed vulnerabilities, assessed their impact, and, in some cases, proposed countermeasures to improve the EN’s resilience. However, the current state of the art still lacks a general taxonomy with adequate granularity that includes the most recently disclosed attacks. This paper presents a comprehensive taxonomy of attacks targeting the EN system. Building on existing categorizations, the proposed taxonomy refines and expands previous frameworks to systematically classify 47 known attacks. It adopts a granular, multilevel structure organized into three core categories – Denial of Service, False Alert Injection, and Information Disclosure – based on attack characteristics, objectives, and outcomes. This taxonomy details current EN attack vectors and procedures, highlighting areas and vulnerabilities that warrant further exploration, analysis, and revision. By systematically mapping these threats, this research aims to advance the design of resilient and secure contact tracing frameworks–a basis for strengthening future contact tracing applications.
This paper presents a framework for analyzing and predicting cyber-attack chain risk using MITRE ATT CK-based sequential representations. Unlike conventional ATT CK-driven methods that primarily support descriptive mapping or static detection, the proposed framework explicitly models sequential dependencies and evolving risk in advanced persistent threat (APT) campaigns. Attack chains are first formalized under explicit construction rules and represented in structured forms suitable for learning. Probabilistic risk scores are then estimated for attack sub-chains using empirical occurrence probabilities, technique impact, and documented mitigation coverage, yielding continuous quantitative risk values. Building on these scores, we define two complementary machine-learning tasks: regression for continuous risk estimation and classification for top-k prioritization of the highest-risk chains. Sequence-aware models and conventional baselines are comparatively evaluated on real-world attack data. Results show that sequence-aware models provide strong performance for continuous risk estimation and ranking-oriented regression behavior, while a count-based MLP ensemble achieves the best overall performance for top-5 and top-10 high-risk chain prioritization. Bootstrap confidence intervals further indicate that the main classification and regression findings are stable under resampling. These findings demonstrate the practical value of combining probabilistic risk assessment with predictive modeling to support prioritization, early warning, and proactive cyber defense.
In this paper, we construct the difference for the KB-256 encryption algorithm. The proposed difference for 15 rounds of the algorithm holds with a probability of at least 2^-133.3 . The obtained relation enables the effective application of differential cryptanalysis.
Malware classification using visual representations has emerged as a promising approach for cybersecurity applications, yet existing deep learning methods often suffer from high computational complexity and limited deployment feasibility on resource-constrained devices. This paper introduces HFDNet (Harmonic Feature Decomposition Network), a novel lightweight architecture that leverages mathematically-grounded harmonic decomposition for efficient malware image classification. Unlike conventional spatial-only architectures and attention mechanisms that demand substantial computational resources, HFDNet employs learnable trigonometric functions with adaptive frequency, amplitude, and phase parameters to extract discriminative spectral patterns from malware binary visualizations. Comprehensive evaluation on the MalImg dataset comprising 9,339 samples across 25 malware families, conducted over five independent experimental runs with stratified splitting, demonstrates that HFDNet achieves 96.28
Phishing attacks are one of the significantly evolving cyber threats, where phishing websites serve as the key tool for the attackers to steal sensitive and private information of the users. Thus, there is a need for a robust method for detecting phishing websites because of the evolving nature of phishing attacks. Numerous approaches based on Machine Learning (ML) have been introduced to detect phishing websites, but those methods suffer from certain shortcomings, such as limited adaptability, lower performance, higher false positive rates, and so on. Therefore, the Mixture of Experts Learning based Bidirectional Boosted Recurrent Network (MoE-B2RNet) model is proposed to detect phishing websites by overcoming the limitations of conventional approaches. The utilization of the gradient boosted Gated Recurrent Unit (GRU) within the model facilitates achieving a lower false positive rate by sequentially training the model based on the errors made by the previous ones. Moreover, the employment of Mixture of Experts (MoE) in the dense layer leads to better performance, which activates all the experts for processing each input and improves the model’s generalization capability. The experimental results show the MoE-B2RNet model achieved better results in terms of accuracy of 98.71
This paper presents the cryptanalysis of four recently proposed image encryption algorithms that utilize chaos-based confusion-diffusion techniques. The first algorithm follows a single round of permutation-substitution using a novel one-dimensional chaotic map for medical image encryption. The second method proposes color image encryption that follows two-stage confusion and diffusion at block and pixel levels, using multiple chaotic and hyperchaotic maps on each color plane. The third method follows pixel-bit-level-based permutation-substitution operations for grayscale image encryption. The fourth method employs a single round of cross-channel pixel permutation and block-pixel level substitution for color image encryption. All techniques have been validated for their security performance through some standard security analysis and claims of resilience against common attacks. However, careful cryptanalysis reveals common weaknesses in these techniques, making them vulnerable to attacks. The diffusion functions in all these methods use variants of XOR operations, which can be combined and reduced to linear XOR forms, allowing easy identification of equivalent diffusion keys. Similarly, the permutations in these methods, through key-dependent transpositions, scan patterns, and graycode transformations, produce fixed permutation structures across images with the same encryption key, enabling easy reconstruction of the permutation matrix. Using these observations, we employ chosen-plaintext analysis to compromise these cryptosystems and successfully decrypt and recover the secret images without knowing the original encryption key. Additionally, this paper proposes improvements in the design of chaos-based image encryption algorithms to ensure the required level of security.
Penetration testing is a security technique used to simulate the actions of a malicious attacker, aiming to uncover weaknesses and assess potential consequences of cyber-attacks. However, conducting penetration tests can be challenging, requiring a deep understanding of vulnerabilities and ensuring that their exploitation does not disrupt business continuity. In particular, for exploiting vulnerabilities, security practitioners should reproduce the vulnerable system in a controlled environment, find “exploits”, i.e., software modules that allow the assessment of such vulnerabilities, configure the software modules by installing the required dependencies, and test the exploit. Despite several companies offering exploit databases containing many available exploits, there is no solution that automates all the setup steps in order to provide a collection of ready-to-use “zero-configuration” exploits. Current frameworks support a few manually curated exploits, whereas dependency resolution tools struggle to handle the complexity of real-world exploit code, which often contains ambiguous imports, version conflicts, and undocumented dependencies. Additionally, exploits are often released on public repositories by untrusted developers, which can lead to significant security risks. This paper presents ExploDox, a framework that combines knowledge graph-based dependency inference with lightweight and isolated containerization to enable scalable automation in the generation of sandboxed exploit environments. Our approach automatically resolves complex dependency relationships that traditional parsing methods cannot handle, while providing isolated, reproducible, and secure execution environments. ExploDox generated 2437 working exploits out of a total of 3346 Python exploits from Exploit-DB, achieving a 72.83