Attackers can embed malicious behaviors into Deep Learning (DL) models and make these contaminated models publicly available. The malfunction of backdoored models does not raise suspicion unless the attacker activates the malicious behavior by triggering it with an embedded trigger in the input data during inference. Unaware users may integrate these contaminated models into their applications, thereby exposing their systems to adversarial attacks with potentially severe outcomes. In many real-world deep learning applications that rely on publicly available or third-party models, existing backdoor detection methods are often impractical because they typically require access to the original training data, the target model’s internal weights, or the confidence scores of its predictions. This paper introduces a novel real-time backdoor defense framework, the Chessboard Masked AutoEncoder (CBMAE), which can reconstruct images and neutralize hidden triggers at runtime, regardless of access to the model’s architecture, parameters, or soft output. We evaluated our framework on benchmark datasets such as CIFAR-10, GTSRB, and ImageNet-16, showing strong resistance to backdoor attacks. While existing defense methods can significantly reduce attack success rates (ASR), they often do so at the cost of substantial accuracy drops on clean or purified data. In contrast, although our method may not reduce ASR as aggressively as some specialized defenses, it strikes a strong balance by effectively lowering ASR while preserving high accuracy on clean and recovered poisoned data. Our source code is available at https://github.com/******/Backdoor.
States employ cyber deterrence strategies to safeguard their sovereignty in cyberspace. Cyber deterrence encompasses various means to prevent serious cyberattacks. This multifaceted approach incorporates various instruments of state power, including diplomatic, informational, military, economic and legal mechanisms. While all these instruments contribute to a state's overarching deterrence strategy in cyberspace, cyber-specific means offer the most rapid deployment options for countering cyberattacks. The challenge lies in credibly signalling cyber capabilities while preserving their secrecy and effectiveness. This challenge can be countered by carefully curating disclosed information, thereby maintaining the state´s strategic advantages and operational integrity. This research examines the technical implementation of deterrence signalling through a concrete example. By analysing the MITRE D3FEND framework, we aim to demonstrate practical application of cyber deterrence signalling and bridge theoretical concepts with operational cybersecurity practices. The MITRE D3FEND framework is a tool designed to describe cybersecurity countermeasure components and capabilities, and relationships between these elements. The research question posed is whether this framework can be used to signal cyber deterrence. This study evaluates the D3FEND framework's categories to determine which features can be signalled without compromising their effectiveness. Through qualitative content analysis, we develop evaluation criteria based on academic cyber deterrence literature. Each category of the D3FEND framework is methodically assessed against the evaluation criteria, to identify the signalling potential of the framework. The main findings of the study show that, of the seven categories of the D3FEND framework, the “Harden” category contains the most elements that can be used in cyber deterrence signalling, while the “Model” and “Deceive” categories have the fewest. The evaluation helps discern not only the elements to be signalled, but also those aspects of the defence, the exposure of which must be avoided. This research contributes to the academic discourse on cyber deterrence by elucidating the technical aspects of deterrence signalling, thereby offering a novel approach to bridging theoretical frameworks with practical cybersecurity implementations.
Quantum computing is a disruptive technology with the potential to transform various fields. It has predicted abilities to solve complex computational problems beyond the reach of classical computers. However, developing quantum software faces significant challenges. Quantum hardware is yet limited in size and unstable with errors and noise. A shortage of skilled developers and a lack of standardization delay adoption. Quantum hardware is in the process of maturing and is constantly changing its characteristics rendering algorithm design increasingly complex, requiring innovative solutions. Project "Towards reliable quantum software development: Approaches and use-cases" TORQS has studied the dilemma of reliable software development and potential for quantum computing for Finnish industries from multidisciplinary points of views. Here we condense the main observations and results of the project into an essay roadmap and timeline for investing in quantum software, algorithms, hardware, and business.
As quantum systems move towards practical deployment, there is a need to prioritize research focused on security risks and mitigation strategies. This paper presents the current literature on vulnerabilities in different hardware implementations of quantum computers and categorizes vulnerabilities based on underlying qubit technology. The review also examines attack methodology, source, impact and mitigation strategies for two types of hardware vulnerabilities: crosstalk and side channel attacks. The aim of this paper is to provide an understanding of the evolution of quantum vulnerability research at hardware level and to highlight the need to implement security into the design of quantum computers from its early stages.
This paper reviews a quantum method for k-means clustering on NISQ computers and proposes a method to improve its accuracy. In addition, a quantum k-means clustering algorithm that efficiently utilizes qubit resources to calculate multiple distances simultaneously is introduced. Experiments on both quantum simulator and real quantum systems were conducted to compare the performance of the method proposed in this paper with the previous method. The results show that the proposed method achieves higher accuracy and efficiency in quantum simulator and even greater improvements in real quantum systems.
Cyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios.
In this paper, we evaluate the feasibility of quantum algorithms for practical applications and categorize them into three types: green, yellow, and red. Green means the most feasible, while red means the least feasible. We select four quantum algorithms from the Algebraic and Number Theoretic fields, four from the Optimization field, six from the Machine Learning field, and four from the Oracular field to assess their feasibility. Our results show that some quantum algorithms can be applied to solve real-life problems in the near future, while other fields may take a long time to be practically applied. The feasibility assessment is obtained by considering whether there are requirements in the quantum algorithms that are hard to satisfy with current quantum technologies and predicting how much time it will require for those requirements to be satisfied in the future. We also provide a table summarizing the feasibility evaluation results of these quantum algorithms.
The emergence of quantum computing proposes a revolutionary paradigm that can radically transform numerous scientific and industrial application domains. However, realizing this promise in industrial applications is far from being practical today. In this paper, we discuss industry experiences with respect to quantum computing, and the gap between quantum software engineering research and state-of-the-practice in industry-scale quantum computing.
The pervasive use of AI assistant systems and machine learning-based applications in various fields and everyday life has significantly shifted. However, this shift is not without its challenges. The emergence of security threats, various attacks, and vulnerabilities in this domain has not only questioned their use but also sparked the interest of security experts and researchers, underlining the urgency and importance of this topic. However, a comprehensive and systematic research endeavor is yet to be undertaken on threat modeling based on violating basic tenets of information security on the various components of a machine learning system and evaluating their security risks. This lack of comprehensive threat modeling for each violation of a machine learning system’s confidentiality, integrity, availability, and privacy for various attacks and their risk analysis is a significant gap in the field. This article aims to bridge this gap by proposing a simple, efficient, and time-saving approach to evaluate potential attacks and their security risks by utilizing the attack tree and a risk analysis method in the Adversarial Machine Learning (AML) field. One of the most important steps in determining the overall risk of the attack is evaluating the risk attached to each node in an attack tree. A systematic approach that includes describing the system architecture and identifying its assets under various operational environment scenarios is also outlined in this paper. This approach can also offer crucial insights to security experts, aiding them in understanding and mitigating potential threats and risk analysis in AML systems. To ensure the validity and reliability of our findings, we have conducted a thorough and rigorous review of academic papers, summarizing different threats and attacks and their root cause analysis.
People and businesses are dependent on the security of the Internet of Things (IoT). Vendor-independent security assessment and certification intends to provide an objective view of the security of an IoT product. Unfortunately, the assessment is often done for a single version and configuration of the product and usually does not yield data to reproduce the assessment. We present the Transparent Security Method , in which product security is described by a machine-readable security statement . A security statement can be verified using tools for automated assessment, which can be repeated for different product versions and configurations to cover the product life-cycle. As a case study, we create an entry-level security statement for a real IoT product and do the verification using common security tools. In the study, 12 out of 15 security claims are verified fully or partially by automation. A security statement can be used in certification or labeling to speed up security assessment, especially in re-certification. Tool-based verification discourages inflated security claims, as they can be scrutinized. Eventually, this should drive product security improvements, as products without security statements are less attractive.
This chapter has the focus on the concepts of Quantum Security and Post-Quantum Cryptography (PQC). The core concepts of both are presented as well as recent developments in standardization of PQC that will have an impact in the 6G development. The main objectives of this chapter are to understand the impact of quantum computing to the security of modern cryptography, quantum security, standardization, and new research directions.
Widely used public key cryptography is threatened by the development of quantum computers. Post-quantum algorithms have been designed for the purpose of protecting sensitive data against attacks with quantum computers. National Institute of Standards and Technology has recently reached the end of the third round of post-quantum standardization process and has published three digital signatures and one key encapsulation mechanism for standardization. Three of the chosen algorithms are based on lattices. When implementing complex cryptographic algorithms, developers commonly use cryptographic libraries in their solutions to avoid mistakes. However, most of the open-source cryptography libraries do not yet have post-quantum algorithms integrated in them. We chose a C++ cryptography library, Crypto++, and created a fork where we integrated four lattice-based post-quantum algorithms. We analyzed the challenges in the process as well as the performance, correctness and security of the implemented algorithms. The performance of the integrated algorithms was overall good, but the integration process had its challenges, many of which were caused by the mathematical complexity of lattice-based algorithms. Different open-source implementations of post-quantum algorithms will be essential to their easier use for developers. Usability of the implementations is also important to avoid possible mistakes when using the algorithms.
: The Internet of Things (IoT) is the ecosystem of networked devices encountered in both work and home. IoT security is a great concern and vulnerabilities are reported daily. IoT is mixed into other digital infrastructure both in terms of sharing the same networks and using the same software components. In this paper, we analyze Common Vulnerabilities and Exposures (CVE) entries, including known exploited vulnerabilities, to describe the vulnerabilities in the IoT context. The results indicate that 88% of reported vulnerabilities are relevant to IoT systems. Half of the vulnerabilities are in the backend or frontend systems while 10-20% concern the IoT devices. HTTP servers are the vulnerability hotspots wherever they are located. Software components are used in all IoT subsystems and tracking and updating them is essential for system security. The results can be used to understand where and what kind of vulnerabilities are in IoT systems.
The design and development of security mechanisms, such as authentication, requires analysis techniques that take into account usability along with security. Although techniques that are grounded in the security domain target the identification and mitigation of possible threats, user centered design approaches have been proposed in order to also take into account the user’s perspective and needs. Approaches dealing with both usability and security focus on the extent to which the user can perform the authentication tasks, as well as on the possible types of attacks that may occur and the potential threats on user tasks. However, to some extent, attacker can be considered as user of the system (even if undesirable), and the analysis of attacker tasks provides useful information for the design and development of an authentication mechanism. We propose a models-based approach to analyse both user and attacker tasks. The modeling of attacker tasks enables to go deeper when analysing the threats on an authentication mechanism and the trade-offs between usability and security. We present the results of the application of this models-based approach to the EEVEHAC security mechanism, which enables the setup of a secure communication channel for users of shared public computers.
Measuring the security of cryptographic systems is not a simple task. Nevertheless, there is an increasing need for a cryptographic metric which could assist in decision making when choosing between various candidates. The National Institute of Standards and Technology (NIST) has launched a process to standardize quantum-resistance public key encryption, key encapsulation and digital signature algorithms. This is NIST’s response to the threat posed by quantum computers against classical public key cryptography. In this paper, we apply a metric taxonomy, produced by earlier studies, to two NIST third round finalist digital signature algorithms Dilithium and Falcon in order to asses the effectiveness and extensiveness of the metric. Although, our results show that clear differences can be found with used metrics, we propose some improvements to them to allow more comprehensive analysis.
In this work, we integrated three quantum-safe digital signature algorithms, CRYSTALS-Dilithium, FALCON and Rainbow, into notification messages used in intelligent transport systems. We evaluated the performance of the algorithms by measuring the time required to sign and verify messages, as well as the size of the signed messages, and compared the quantum-safe options to the elliptic curves currently accepted by the standards. Our results show that quantum-safe digital signature algorithms could be used for signing notification messages in intelligent transport systems, with only moderate changes to performance. The results also provide an evaluation of three quantum-safe digital signature algorithms’ suitability for this purpose, thus helping to choose suitable algorithms when migrating intelligent transport systems towards quantum resistance.
The cybersecurity of the Internet of Things (IoT) is an increasing concern and product vendors are advised to follow security standards, best practices, and guidelines. From the many requirement sources, a vendor is likely to choose only a few. How does this selection impact the security requirements of an IoT product? To answer the question, we collect requirements from 16 sources and divide them into categories for comparison. Common categories are identified, with all sources covering Security design, Interface security, Authentication, Data protection, and System updates. The agreement on the high-level categories does not hold in the subcategories and the selection of the sources have a big impact to the requirement details. Consolidation of the IoT security requirements would be desirable and possible.
It is well-known that security issues in medical devices, services and applications have potentially catastrophic consequences. To avoid compromising patient data or information systems, it is essential that healthcare services and products meet the relevant information security and data protection requirements. For these reasons, the Digi-HTA assessment includes information security and data protection assessment domains. The outcome of the Digi-HTA process is a recommendation that decision-makers can use during the procurement process. We present results and experiences from the first assessments made in the Digi-HTA process. We have assessed six products so far and multiple assessments are in progress. The results indicate that healthcare product manufacturers have found the process useful, and usually, the manufacturers have had to improve the security of their product during the Digi-HTA process to get a favourable recommendation for their product. The assessment processes have taken longer than expected due to shortcomings and ambiguities in the provided self-assessment forms, and due to feedback cycles and meetings prompted by assessment findings. Of the six assessed products, four received a green light in information security and data protection, whereas two have received a yellow light due to issues that were not fixed during the process. In addition to shortcomings in adhering to best practices, we have also found exploitable security issues.