The increasing frequency and sophistication of cyber attacks have posed significant challenges for digital financial organisations, particularly in quantifying their multidimensional impacts. These challenges are largely attributed to the lack of a standardised cyber impact taxonomy, limited data availability, and the evolving nature of technological threats. As a result, organisations often struggle with ineffective security investment prioritisation, reactive incident response planning, and the inability to implement robust, risk-based controls. Hence, an efficient and comprehensive approach is needed to quantify the diverse impacts of cyber attacks in digital financial services. This paper presents a systematic review and examination of the state of the art in cyber impact quantification, with a particular focus on digital financial organisations. Based on a structured search strategy, 44 articles (out of 637) were selected for in-depth analysis. The review investigates the terminologies used to describe cyber impacts, categorises current quantification techniques (pre-attack and post-attack), and identifies the most commonly utilised internal and external data sources. Furthermore, it explores the application of Machine Learning (ML) and Deep Learning (DL) techniques in cyber security risk quantification. Our findings reveal a significant lack of standardised taxonomy for describing and quantifying the multidimensional impact of cyberattacks across physical, digital, economic, psychological, reputational, and societal dimensions. Lastly, open issues and future research directions are discussed. This work provides insights for researchers and professionals by consolidating and identifying quantification technique gaps in cyber security risk quantification.
Large Language Models (LLMs) have emerged as powerful tools in cyber security, enabling automation, threat detection, and adaptive learning. Their ability to process unstructured data and generate context-aware outputs supports both operational tasks and educational initiatives. Despite their growing adoption, current research often focuses on isolated applications, lacking a systematic understanding of how LLMs align with domain-specific requirements and pedagogical effectiveness. This highlights a pressing need for comprehensive evaluations that address the challenges of integration, generalization, and ethical deployment in both operational and educational cyber security environments. Therefore, this paper provides a comprehensive and State-of-the-Art review of the significant role of LLMs in cyber security, addressing both operational and educational dimensions. It introduces a holistic framework that categorizes LLM applications into six key cyber security domains, examining each in depth to demonstrate their impact on automation, context-aware reasoning, and adaptability to emerging threats. The paper highlights the potential of LLMs to enhance operational performance and educational effectiveness while also exploring emerging technical, ethical, and security challenges. The paper also uniquely addresses the underexamined area of LLMs in cyber security education by reviewing recent studies and illustrating how these models support personalized learning, hands-on training, and awareness initiatives. The key findings reveal that while LLMs offer significant potential in automating tasks and enabling personalized learning, challenges remain in model generalization, ethical deployment, and production readiness. Finally, the paper discusses open issues and future research directions for the application of LLMs in both operational and educational contexts. This paper serves as a valuable reference for researchers, educators, and practitioners aiming to develop intelligent, adaptive, scalable, and ethically responsible LLM-based cyber security solutions.
Epileptic seizures, a leading cause of global morbidity and mortality, pose significant challenges in timely diagnosis and management. Epilepsy, a chronic neurological disorder characterized by recurrent and unpredictable seizures, affects over 70 million people worldwide, according to the World Health Organization (WHO). Despite significant advances in medical science, accurate and timely diagnosis of epileptic seizures remains a challenge, with misdiagnosis rates reported to be as high as 30%. The consequences of misdiagnosis or delayed diagnosis can be severe, leading to increased morbidity, mortality, and reduced quality of life for patients. Therefore, this paper presents a novel approach to enhancing epileptic seizure detection through the integration of Synthetic Minority Over-Sampling Technique (SMOTE) for data balancing and a Hybrid Feature Selection Technique—Principal Component Analysis (PCA) and Discrete Wavelet Transform (DWT). The proposed model aims to improve the accuracy and reliability of seizure detection systems by addressing data imbalance and extracting discriminative features from electroencephalograms (EEG) signals. Experimental results demonstrate substantial performance gains, with the Support Vector Machine (SVM) classifier achieving 97.30% accuracy, 99.62% Area Under the Curve (AUC), and 93.08% F1 score, which outperform the results of the existing studies from the literature. The results highlight the effectiveness of the proposed model in advancing seizure detection systems, highlighting the potential to improve diagnostic capabilities and patient outcomes.
Healthcare systems are increasingly vulnerable to security threats due to their reliance on digital platforms. Traditional access control models like Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) have limitations in mitigating evolving risks in these systems. Despite their unique features, these models face limitations in mitigating evolving risks in healthcare systems. Traditional models are primarily oriented towards allocating permissions according to predetermined roles or policies, which results in challenges in effectively adapting to the dynamic complexities of modern healthcare ecosystems. Therefore, this paper proposes a novel risk-aware RBAC and ABAC access control model to enhance the flexibility, adaptability and security issues associated with healthcare systems. The proposed model integrates RBAC for role-based categorization, ABAC for fine-grained control based on user attributes and environmental factors, and Risk-Based Access Control (RiBAC) for dynamic risk assessment. The proposed model dynamically adjusts access permissions based on risk values, ensuring accurate and adaptable access control decisions. The experimental results demonstrate the feasibility and effectiveness of the proposed model in granting access to authorized users while denying access to unauthorized users. Through a series of 43 experiments that simulate various scenarios of access control operations in the healthcare system, the proposed model demonstrates significant improvement in the accuracy, precision, and recall of access control decisions compared to traditional models. The proposed model’s ability to dynamically assess risk and adjust access permissions based on contextual factors significantly enhances its ability to mitigate threats and protect sensitive medical data.
With the proliferation of blockchain technology, ensuring the security and integrity of permissionless Proof-of-Stake (PoS) blockchain networks has become imperative. This paper addresses the persistent need for an effective system to detect and mitigate malicious nodes in such environments. Leveraging Deep Learning (DL) techniques, specifically Multi-Layer Perceptron (MLP), a novel model is proposed for real-time identification and detection of malicious nodes in PoS blockchain networks. The model integrates components for data collection, feature extraction, and model training using MLP. The proposed model is trained on labelled data representing both benign and malicious node activities, utilising transaction volumes, frequencies, timestamps, and node reputation scores to identify anomalous behaviour indicative of malicious activity. The experimental results validate the efficacy of the proposed model in distinguishing between normal and malicious nodes within blockchain networks. The model demonstrates exceptional performance in classification tasks with an accuracy of 99%, precision, recall, and F1-score values hovering around 0.99 for both classes. The experimental results verify the proposed model as a dependable tool for enhancing the security and integrity of PoS blockchain networks, offering superior performance in real-time detection and mitigation of malicious activities.
In the current era, satisfying the appetite of data hungry models is becoming an increasingly challenging task. This challenge is particularly magnified in research areas characterised by sensitivity, where the quest for genuine data proves to be elusive. The study of violence serves as a poignant example, entailing ethical considerations and compounded by the scarcity of authentic, real-world data that is predominantly accessible only to law enforcement agencies. Existing datasets in this field often resort to using content from movies or open-source video platforms like YouTube, further emphasising the scarcity of authentic data. To address this, our dataset aims to pioneer a new approach by creating the first synthetic virtual dataset for violence detection, named the Weapon Violence Dataset (WVD). The dataset is generated by creating virtual violence scenarios inside the photo-realistic video game namely: Grand Theft Auto-V (GTA-V). This dataset includes carefully selected video clips of person-to-person fights captured from a frontal view, featuring various weapons—both hot and cold across different times of the day. Specifically, WVD contains three categories: Hot violence and Cold violence (representing the violence category) as well as No violence (constituting the control class). The dataset is designed and created in a way that will enable the research community to train deep models on such synthetic data with the ability to increase the data corpus if the needs arise. The dataset is publicly available on Kaggle and comprises normal RGB and optic flow videos.
Video deepfake detection has emerged as a critical field within the broader domain of digital technologies driven by the rapid proliferation of AI-generated media and the increasing threat of its misuse for deception and misinformation. The integration of Convolutional Neural Network (CNN) with Long Short-Term Memory (LSTM) has proven to be a promising approach for improving video deepfake detection, achieving near-perfect accuracy. CNNs enable the effective extraction of spatial features from video frames, such as facial textures and lighting, while LSTM analyses temporal patterns, detecting inconsistencies over time. This hybrid model enhances the ability to detect deepfakes by combining spatial and temporal analysis. However, the existing research lacks systematic evaluations that comprehensively assess their effectiveness and optimal configurations. Therefore, this paper provides a comprehensive review of video deepfake detection techniques utilising hybrid CNN-LSTM models. It systematically investigates state-of-the-art techniques, highlighting common feature extraction approaches and widely used datasets for training and testing. This paper also evaluates model performance across different datasets, identifies key factors influencing detection accuracy, and explores how CNN-LSTM models can be optimised. It also compares CNN-LSTM models with non-LSTM approaches, addresses implementation challenges, and proposes solutions for them. Lastly, open issues and future research directions of video deepfake detection using CNN-LSTM will be discussed. This paper provides valuable insights for researchers and cyber security professionals by reviewing CNN-LSTM models for video deepfake detection contributing to the advancement of robust and effective deepfake detection systems.
Blockchain technology has gained significant attention in recent years for its potential to revolutionize various sectors, including finance, supply chain management, and digital forensics. While blockchain’s decentralization enhances security, it complicates the identification and tracking of illegal activities, making it challenging to link blockchain addresses to real-world identities. Also, although immutability protects against tampering, it introduces challenges for forensic investigations as it prevents the modification or deletion of evidence, even if it is fraudulent. Hence, this paper provides a systematic literature review and examination of state-of-the-art studies in blockchain forensics to offer a comprehensive understanding of the topic. This paper provides a comprehensive investigation of the fundamental principles of blockchain forensics, exploring various techniques and applications for conducting digital forensic investigations in blockchain. Based on the selected search strategy, 46 articles (out of 672) were chosen for closer examination. The contributions of these articles were discussed and summarized, highlighting their strengths and limitations. This paper examines the selected papers to identify diverse digital forensic frameworks and methodologies used in blockchain forensics, as well as how blockchain-based forensic solutions have enhanced forensic investigations. In addition, this paper discusses the common applications of blockchain-based forensic frameworks and examines the associated legal and regulatory challenges encountered in conducting a forensic investigation within blockchain systems. Open issues and future research directions of blockchain forensics were also discussed. This paper provides significant value for researchers, digital forensic practitioners, and investigators by providing a comprehensive and up-to-date review of existing research and identifying key challenges and opportunities related to blockchain forensics.
As technology advances and cyber threats become increasingly sophisticated, the task of recognising and understanding malicious activities becomes more complex. This persistent issue is widely acknowledged and extensively documented within the cybersecurity community. Attack modelling techniques (AMTs), such as attack graphs, have emerged as valuable tools in aiding cyberattack perception. These visualisation tools offer crucial insights into the complex relationships between various components within a system or network, shedding light on potential attack paths and vulnerabilities. This paper proposes an attack graph visual syntax method to improve cyberattack perception among experts and non-experts. The proposed approach was developed to streamline complexity and enhance clarity, thus augmenting the interpretability for users by enhancing visual structural components, such as hue, chromaticity, and line parameters. The proposed attack graph (pag) was empirically evaluated against the adapted attack graph (aag) presented in the literature. The empirical evaluation (n = 83) was conducted through a 3 × 2 × 2 factorial design and two-way analysis of variance (ANOVA) with repeated measures. The participants were classified according to their respective background cohorts into expert and non-expert (expert n = 37, non-expert n = 46) and then grouped into two groups: proposed attack graph (pag) and adapted attack graph (aag) (pag n = 41, aag n = 42). The empirical results demonstrated that while the proposed attack graph (pag) implemented various visual modifications such as brighter hues, denser line structures, and varied shapes, these enhancements did not significantly improve the perception of cyberattacks among individuals who lack expertise in the field, including corporate executives. Moreover, the use of variables such as colour, tone, and line width/density/structure did not help objects in the graph be distinguished more effectively. This paper provides significant insights into the impact of visual enhancements on cyberattack perception, highlighting that visual enhancements alone may not be sufficient to improve cyberattack perception for individuals lacking expertise in the field.
Manually labelling datasets for training violence detection systems is time-consuming, expensive, and labor-intensive. Mind wandering, boredom, and short attention span can also cause labelling errors. Moreover, collecting and distributing sensitive images containing violence has ethical implications. Automation is the future for labelling sensitive image datasets. Deep labeller is a two-stage Deep Learning (DL) method that uses pre-trained DL object detection methods on MS-COCO for automatic labelling. The Deep Labeller method labels violent and nonviolent images in WVD and USI. In stage 1, WVD generates weak labels using synthetic images. In stage 2, the Deep labeller method is retrained on weak labels. USI dataset is used to test our method on real-world violence. Deep labeller generated weak and strong labels with an IoU of 0.80036 in stage 1 and 0.95 in stage 2 on the WVD. Automatically generated labels. To test our method’s generalisation power, violent and nonviolent image labels on USI dataset had a mean IoU of 0.7450.
Parkinson's disease (PD) is a neurodegenerative condition generated by the dysfunction of brain cells and their 60-80% inability to produce dopamine, an organic chemical responsible for controlling a person's movement. This condition causes PD symptoms to appear. Diagnosis involves many physical and psychological tests and specialist examinations of the patient's nervous system, which causes several issues. The methodology method of early diagnosis of PD is based on analysing voice disorders. This method extracts a set of features from a recording of the person's voice. Then machine-learning (ML) methods are used to analyse and diagnose the recorded voice to distinguish Parkinson's cases from healthy ones. This paper proposes novel techniques to optimize the techniques for early diagnosis of PD by evaluating selected features and hyperparameter tuning of ML algorithms for diagnosing PD based on voice disorders. The dataset was balanced by the synthetic minority oversampling technique (SMOTE) and features were arranged according to their contribution to the target characteristic by the recursive feature elimination (RFE) algorithm. We applied two algorithms, t-distributed stochastic neighbour embedding (t-SNE) and principal component analysis (PCA), to reduce the dimensions of the dataset. Both t-SNE and PCA finally fed the resulting features into the classifiers support-vector machine (SVM), K-nearest neighbours (KNN), decision tree (DT), random forest (RF), and multilayer perception (MLP). Experimental results proved that the proposed techniques were superior to existing studies in which RF with the t-SNE algorithm yielded an accuracy of 97%, precision of 96.50%, recall of 94%, and F1-score of 95%. In addition, MLP with the PCA algorithm yielded an accuracy of 98%, precision of 97.66%, recall of 96%, and F1-score of 96.66%.
Epilepsy is a neurological disorder in the activity of brain cells that leads to seizures. An electroencephalogram (EEG) can detect seizures as it contains physiological information of the neural activity of the brain. However, visual examination of EEG by experts is time consuming, and their diagnoses may even contradict each other. Thus, an automated computer-aided diagnosis for EEG diagnostics is necessary. Therefore, this paper proposes an effective approach for the early detection of epilepsy. The proposed approach involves the extraction of important features and classification. First, signal components are decomposed to extract the features via the discrete wavelet transform (DWT) method. Principal component analysis (PCA) and the t-distributed stochastic neighbor embedding (t-SNE) algorithm were applied to reduce the dimensions and focus on the most important features. Subsequently, K-means clustering + PCA and K-means clustering + t-SNE were used to divide the dataset into subgroups to reduce the dimensions and focus on the most important representative features of epilepsy. The features extracted from these steps were fed to extreme gradient boosting, K-nearest neighbors (K-NN), decision tree (DT), random forest (RF) and multilayer perceptron (MLP) classifiers. The experimental results demonstrated that the proposed approach provides superior results to those of existing studies. During the testing phase, the RF classifier with DWT and PCA achieved an accuracy of 97.96%, precision of 99.1%, recall of 94.41% and F1 score of 97.41%. Moreover, the RF classifier with DWT and t-SNE attained an accuracy of 98.09%, precision of 99.1%, recall of 93.9% and F1 score of 96.21%. In comparison, the MLP classifier with PCA + K-means reached an accuracy of 98.98%, precision of 99.16%, recall of 95.69% and F1 score of 97.4%.
The risk-based access control model is one of the dynamic models that use the security risk as a criterion to decide the access decision for each access request. This model permits or denies access requests dynamically based on the estimated risk value. The essential stage of implementing this model is the risk estimation process. This process is based on estimating the possibility of information leakage and the value of that information. Several researchers utilized different methods for risk estimation but most of these methods were based on qualitative measures, which cannot suit the access control context that needs numeric and precise risk values to decide either granting or denying access. Therefore, this paper presents a novel Adaptive Neuro-Fuzzy Inference System (ANFIS) model for risk estimation in the risk-based access control model for the Internet of Things (IoT). The proposed ANFIS model was implemented and evaluated against access control scenarios of smart homes. The results demonstrated that the proposed ANFIS model provides an efficient and accurate risk estimation technique that can adapt to the changing conditions of the IoT environment. To validate the applicability and effectiveness of the proposed ANFIS model in smart homes, ten IoT security experts were interviewed. The results of the interviews illustrated that all experts confirmed that the proposed ANFIS model provides accurate and realistic results with a 0.713 in Cronbach’s alpha coefficient which indicates that the results are consistent and reliable. Compared to existing work, the proposed ANFIS model provides an efficient processing time as it reduces the processing time from 57.385 to 10.875 Sec per 1000 access requests, which demonstrates that the proposed model provides effective and accurate risk evaluation in a timely manner.
Over the past few years, Blockchain technology has been utilized in various applications to improve privacy and security. Although blockchain has proven its worth as a very powerful technology, research has shown that it is not entirely immune to security and privacy attacks. There was a successful 51% attack on Ethereum Classic back in January 2019 which shows that blockchain still facing security and privacy challenges. This paper aims to develop an anomaly detection solution for the Ethereum blockchain to overcome security challenges using Machine Learning (ML). The proposed solution focuses on using a dynamic approach where the normal operational behaviour of the Ethereum blockchain is used to train ML algorithms and any deviation will be tagged as an anomaly and will be detected by the system. Four ML algorithms including K-Nearest Neighbours (KNN), Gaussian Naive Bayes (GaussianNB), Random Forest, and Stochastic Gradient Descent (SDG) were utilized to train and verify the accuracy of the proposed solution. The experimental results demonstrated that the random forest algorithm provided the best accuracy of 99.84% over other ML algorithms.
Providing a dynamic access control model that uses real-time features to make access decisions for IoT applications is one of the research gaps that many researchers are trying to tackle. This is because existing access control models are built using static and predefined policies that always give the same result in different situations and cannot adapt to changing and unpredicted situations. One of the dynamic models that utilize real-time and contextual features to make access decisions is the risk-based access control model. This model performs a risk analysis on each access request to permit or deny access dynamically based on the estimated risk value. However, the major issue associated with building this model is providing a dynamic, reliable, and accurate risk estimation technique, especially when there is no available dataset to describe risk likelihood and impact. Therefore, this paper proposes a Neuro-Fuzzy System (NFS) model to estimate the security risk value associated with each access request. The proposed NFS model was trained using three learning algorithms: Levenberg–Marquardt (LM), Conjugate Gradient with Fletcher–Reeves (CGF), and Scaled Conjugate Gradient (SCG). The results demonstrated that the LM algorithm is the optimal learning algorithm to implement the NFS model for risk estimation. The results also demonstrated that the proposed NFS model provides a short and efficient processing time, which can provide timeliness risk estimation technique for various IoT applications. The proposed NFS model was evaluated against access control scenarios of a children’s hospital, and the results demonstrated that the proposed model can be applied to provide dynamic and contextual-aware access decisions based on real-time features.
Smartphone applications have gained popularity in recent years due to the large footprint of mobile phone usage and availability of a large number of value-added applications. The official app stores (google, IOS, Microsoft, Amazon) provide a platform for hosting, publishing, distributing, and managing the mobile applications developed by companies and individuals. This mobile application ecosystem could be used to distribute the malicious apps which are specifically designed to track behavior of users, spy on the activities of users, and could be a threat to the privacy, confidentiality, and integrity of the users. In this paper, we present a novel approach called DEEPSEL (Deep Feature Selection), a deep learning-based method for the identification of malware and malicious codes within android applications. DEEPSEL uses a set of features to characterize the behavior of android applications and classify them as legitimate and malicious. The main contribution is characterized by the usage of particle swarm optimization for performing feature selection. We evaluated our approach on a public malware data-set which is composed of samples collected from 39 unique malware families. Our results show that the proposed method can achieve very good results with an accuracy of around 83.6% and an F-measure of around 82.5%.
One of the major impacts of COVID-19 in the nations is mental health issues. Constant mental health issues can cause disorders, as well as mortality. The growing demand for mental healthcare treatment and limited healthcare resources across the world has shown the need for an inventive framework solution. Artificial Intelligence (AI), Big Data Science, 5G, and Information Communication Technology (ICT) have proven to be able to bring many great improvements and could be the potential way forward to develop such a framework. AI could be a very effective tool to help the healthcare sector to provide more efficient services to patients with mental health issues through their emotions. This paper presents the initial overview and outcomes of the ongoing research programme to develop a proactive multimodal emotion AI recognition framework that detects emotion from various input data sources for early detection of mental health illnesses, as well as provides the required psychological interventions effectively and promptly when required. The data will be collected from various smart wearables and ad-hoc devices, facial expressions, and speech signals. Then, these data will be interpreted using AI into emotions. These emotions will be utilised using AI-based psychological system, which will provide immediate and customized interventions, as well as transmit critical data to the healthcare provider’s central database system for monitoring and supplying the required treatments.
Internet of Things (IoT) is a unique element in the realm of Cybersecurity. It constitutes countless applications, including defense, health, agriculture, finance, amongst other industries. The majority of existing studies focus on various developments of IoT products and services essential to our day-to-day activities, with little emphasis on the security of developed systems. This has led to the proliferation of IoT solutions acquired through rapid development and overlooking the need for a structured security framework during the systems’ development stages. IoT security capability can be improved by using complementary technologies. This paper explores applying Risk-Based Access Control Model using Blockchain to control access to IoT devices. Although current access control models provide efficient security measures to control who can access the system resources, there is no way to detect and prevent malicious attacks after granting access. The proposed solution utilizes smart contracts under the Hyperledger Fabric (HLF) Blockchain Framework to create access permissions and measure the security risks associated with any event in the IoT system and create access permissions to determine what processes may be performed. This will allow the detection of any malicious activity at the early stages of the attack and grant or deny access based on the risk associated with