The integration of Electronic Medical Records (EMRs) into the healthcare industry has revolutionized patient data management by enabling the storage of highly sensitive information. However, the continuous exchange of this information among health institutions to ensure accurate patient care introduces significant challenges related to data dissemination and security. Blockchain technology, with its inherent properties of decentralization, immutability, and transparency, offers a robust solution to these challenges, facilitating secure and efficient data sharing among stakeholders. In this paper, we present MedBlockSync, a robust blockchain system designed for improved data integrity across multi-institutional healthcare organizations. The framework is developed to achieve three key objectives: (1) safeguarding EMR data against cyberattacks, (2) enabling seamless and secure sharing of healthcare information among various stakeholders, and (3) facilitating Internet of Medical Things (IoMT) communication, including real-time data transmission from smart sensors to the blockchain network and EMRs through a secure channel. By incorporating advanced security features into EMRs without necessitating modifications to existing digital health infrastructures, MedBlockSync enhances interoperability among healthcare systems, ensuring both scalability and adaptability in the digital health landscape.
Increasing cybercrime rates means identifying potential victims is critically important. Social discounting tasks show that individuals share less personally identifying information as social distance increases. However, the test-retest reliability and uniqueness of this measure is unclear. The current study assessed social discounting for personally identifying information (SDPII), delay discounting, risk taking, and personality at two measurement waves 30 days apart for 64 undergraduate students. Test-retest reliability was statistically significant for the SDPII and all other measures, replicating previous studies. SDPII rates were not significantly correlated with other measures during both measurement waves, showing discriminant validity. SDPII rates were lower than those reported in a previous study but were still well described by a hyperbolic discounting function, suggesting replicability across studies. The high test-retest reliability, uniqueness, and replicability of the SDPII suggests that it may quantitatively identify cybercrime victimization. Future research should test which measure or combination of measures can accurately predict scam and cybercrime victimization to inform data-based interventions.
Industrial Control Systems (ICS) are critical to modern critical infrastructure and remain prime targets for cyberattacks. Securing their protocol stacks, such as the Common Industrial Protocol (CIP), is challenging due to tight coupling between cyber and physical domains and limited runtime observability. Existing fuzzing and intrusion detection approaches typically treat Programmable Logic Controllers (PLCs) as opaque black boxes, hindering the ability to correlate protocol-level anomalies with their physical effects. We present CYPHER (CYber–PHysical fuzzER), a cross-layer security framework that bridges this gap by integrating CIP-aware protocol parsing, PLC current sensing, and Human–Machine Interface (HMI) telemetry into a unified, feedback-driven fuzzing loop. CYPHER evaluates protocol mutations through network responses and their control-layer and physical impacts, enabling semantic and behavior-aware fuzzing. Deployed on a hybrid testbed with Allen–Bradley PLCs and an Emulate3D virtual plant, CYPHER uncovered logic-driven faults, undocumented service behaviors, and reproducible control-state deviations in ControlLogix systems. Compared to Boofuzz, CYPHER achieved higher protocol coverage and more precise identification of control-relevant anomalies, demonstrating its potential to expose previously invisible cyber–physical vulnerabilities in ICS environments.
Anomaly-based cyber threat detection using deep learning is on a constant growth in popularity for novel cyber-attack detection and forensics. A robust, efficient, and real-time threat detector in a large-scale operational enterprise network requires high accuracy, high fidelity, and a high throughput model to detect malicious activities. Traditional anomaly-based detection models, however, suffer from high computational overhead and low detection accuracy, making them unsuitable for real-time threat detection. In this work, we propose LogSHIELD, a highly effective graph-based anomaly detection model in host data. We present a real-time threat detection approach using frequency-domain analysis of provenance graphs. To demonstrate the significance of graph-based frequency analysis we proposed two approaches. Approach-I uses a Graph Neural Network (GNN) LogGNN and approach-II performs frequency domain analysis on graph node samples for graph embedding. Both approaches use a statistical clustering algorithm for anomaly detection. The proposed models are evaluated using a large host log dataset consisting of 774M benign logs and 375K malware logs. LogSHIELD explores the provenance graph to extract contextual and causal relationships among logs, exposing abnormal activities. It can detect stealthy and sophisticated attacks with over 98
In Hospital-at-Home settings, there is a growing demand for cost-effective, personalized, and continuous care solutions. Continuous care solutions incorporate wearable sensors and remote monitoring devices to provide comprehensive care. These tools facilitate the seamless collection and transmission of patient data in real time. Additionally, providing inter-connected and in-depth information on an individual's health status, as well as their level of acuity. As healthcare continues to shift towards decentralized in-home models. There is a critical need to ensure confidentiality, integrity, assurance, and privacy of transmitted medical information. This paper proposes a three-tier federated learning architecture designed to detect both physiological anomalies and monitor for unusual patterns in data aggregation that may suggest a cyber intrusion. The proposed architecture offers a scalable, privacy-preserving, and intelligent solution for proactive health monitoring in home care environments, helping to prevent clinician alarm fatigue. By combining the analytical and computational rigor of game theory and AI, a transition towards more proactive and informed decision-making in healthcare systems can be achieved.
The use of Electronic Medical Records (EMRs) in the healthcare industry has proven to be critical for storing highly sensitive information. Disseminating and protecting healthcare data poses major challenges for the current healthcare information system. Blockchain technology provides solutions to these challenges with its inherited properties, such as decentralization, immutability, and transparency. This provides a unique opportunity to improve data sharing among stakeholders. We propose MediLink, a blockchain-based framework for secure collaborative medical storage. MediLink is designed to (1) protect EMR data from cyber attacks, (2) share healthcare information of patients with different stakeholders, and (3) enable the Internet of Medical Things (IoMT) (e.g., smart sensors) communication and real-time data transmission with EMR and the blockchain network through a secured channel. MediLink adds security features to EMRs without requiring modification of current digital health infrastructures, increasing interoperability among healthcare systems.
Source code authorship attribution is an important problem in practical applications such as plagiarism detection, software forensics, and copyright disputes. Recent studies show that existing methods for source code authorship attribution can be significantly affected by time evolution, leading to a decrease in attribution accuracy year by year. To alleviate the problem of Deep Learning (DL)-based source code authorship attribution degrading in accuracy due to time evolution, we propose a new framework called Time Domain Adaptation (TimeDA) by adding new feature extractors to the original DL-based code attribution framework that enhances the learning ability of the original model on source domain features without requiring new or more source data. Moreover, we employ a centroid-based pseudo-labeling strategy using neighborhood clustering entropy for adaptive learning to improve the robustness of DL-based code authorship attribution. Experimental results show that TimeDA can significantly enhance the robustness of DL-based source code authorship attribution to time evolution, with an average improvement of 8.7% on the Java dataset and 5.2% on the C++ dataset. In addition, our TimeDA benefits from employing the centroid-based pseudo-labeling strategy, which significantly reduced the model training time by 87.3% compared to traditional unsupervised domain adaptive methods.
Big data is a computing term used to refer to large and complex data sets, typically consisting of terabytes or more of diverse data that is produced rapidly. The analysis of such complex data sets requires advanced analysis techniques with the capacity to identify patterns and abstract meanings from the vast data. The field of data science combines computer science with mathematics/statistics and leverages artificial intelligence, in particular machine learning, to analyze big data. This field holds great promise for behavior analysis, where both clinical and research studies produce large volumes of diverse data at a rapid pace (i.e., big data). This article presents basic lessons for the behavior analytic researchers and clinicians regarding integration of data science into the field of behavior analysis. We provide guidance on how to collect, protect, and process the data, while highlighting the importance of collaborating with data scientists to select a proper machine learning model that aligns with the project goals and develop models with input from human experts. We hope this serves as a guide to support the behavior analysts interested in the field of data science to advance their practice or research, and helps them avoid some common pitfalls.
Correctly recognizing the behaviors of children with Autism Spectrum Disorder (ASD) is of vital importance for the diagnosis of Autism and timely early intervention. However, the observation and recording during the treatment from the parents of autistic children may not be accurate and objective. In such cases, automatic recognition systems based on computer vision and machine learning (in particular deep learning) technology can alleviate this issue to a large extent. Existing human action recognition models can now achieve impressive performance on challenging activity datasets, e.g., daily activity, and sports activity. However, problem behaviors in children with ASD are very different from these general activities, and recognizing these problem behaviors via computer vision is less studied. In this paper, we first evaluate a strong baseline for action recognition, i.e., Video Swin Transformer, on two autism behaviors datasets (SSBD and ESBD) and show that it can achieve high accuracy and outperform the previous methods by a large margin, demonstrating the feasibility of vision-based problem behaviors recognition. Moreover, we propose language-assisted training to further enhance the action recognition performance. Specifically, we develop a two-branch multimodal deep learning framework by incorporating the ”freely available” language description for each type of problem behavior. Experimental results demonstrate that incorporating additional language supervision can bring an obvious performance boost for the autism problem behaviors recognition task as compared to using the video information only (i.e., 3.49% improvement on ESBD and 1.46% on SSBD). Our code and model will be publicly available for reproducing the results.
Voice Control Systems (VCSs) offer a convenient interface for issuing voice commands to smart devices. However, VCS security has yet to be adequately understood and addressed as evidenced by the presence of two classes of attacks: (i) inaudible attacks, which can be waged when the attacker and the victim are in proximity to each other; and (ii) audible attacks, which can be waged remotely by embedding attack signals into audios. In this paper, we introduce a new class of attacks, dubbed near-ultrasound inaudible trojan (NUIT). NUIT attacks achieve the best of the two classes of attacks mentioned above: they are inaudible and can be waged remotely . Moreover, NUIT attacks can achieve end-to-end unnoticeability , which is important but has not been paid due attention in the literature. Another feature of NUIT attacks is that they exploit victim speakers to attack victim microphones and their associated VCSs, meaning the attacker does not need to use any special speaker. We demonstrate the feasibility of NUIT attacks and propose an effective defense against them.
The Internet of Things (IoT) have been widely used to monitor control systems of critical infrastructure. IoT device’s self-localization functionality is important to realize a connected IoT ecosystem. This study proposes a probabilistic approach to evaluate self-localization quantitatively by utilizing network gateway allocation while considering probabilistic loss of WiFi signals from gateways. We use probabilistic model checking to evaluate how probabilistic signal loss affects self-localization accuracy. The investigation of such uncertainty serves as the foundation for real-world IoT self-localization.
Supply Chain Management (SCM) systems provide a digital platform for the supply chain organizations to communicate and exchange information. In the food industry, SCMs provide the essential software components for monitoring food transportation and product handling. However, contemporary SCM systems suffer from non-traceability, non-interoperability and poor resiliency. Global food supply chains are at risks from cyber threats, which will lead to food shortages and poor quality control. In this paper, we present ChainSCAN, a three-layer design of a fully decentralized and blockchain-based SCM system that protects data security, privacy, and remove single point of failures of traditional SCMs. In addition, ChainSCAN provides a transparent environment to protect physical security of assets from stolen and record all activities of the food supply chain. ChainSCAN leverages four smart contracts to automate and regulate interactions of supply chain participants with the ledger, which can enforce the best practices among all supply chain organizations. Furthermore, ChainSCAN contains a notification system that automatically alerts consumers about food recalls and/or potential misbehaviors.
We initiate the study on the problem of automated and robust Cyber Security Management (CSM). We exemplify the problem by investigating how CSM should respond to the discovery of cyber intelligence that identifies new attackers, victims, or defense capabilities. Given the complexity of CSM, we divide it into three classes, referred to as Network-centric (N-CSM), Tools-centric (T-CSM) and Application-centric (A-CSM). These lead to a range of functions for examining whether, and to what extent, a network has been compromised. Moreover, we propose to incorporate blockchain (via Hyperledger Fabric) to build a decentralized CSM system, dubbed B2CSM, that ensures the retrieval of valid invocation results for CSM purposes. We also integrate B2CSM with a decentralized storage network (DSN), instantiated by InterPlanetary File System (IPFS), to reduce on-chain storage costs without hindering its robustness. We present the design and implementation of the prototype B2CSM system. Experiments with real-world datasets show that the CSM solutions and system are effective and efficient.
Predictive power of many behavioral measures relies on high test-retest reliability, whereby a measure yields similar data when repeated measure administration occurs at spaced-out intervals. However, major environmental disruptions between measure administration may impact test-retest reliability. The novel coronavirus (COVID-19) pandemic caused just such a major environmental disruption. We collected impulsivity data via a delay discounting task before, during, and after this environmental disruption. Test-retest reliability was generally statistically significant throughout the study even as delay discounting rates changed in the expected direction between the two experimental groups. Importantly, non-significant correlation coefficients (i.e. poor test-retest reliability) typically occurred immediately after the environmental disruption. Participant's anecdotal self-reports corroborated COVID-19's temporary disruptive impact. Although not a planned manipulation, this data provides useful information about whether major environmental disruptions may impact test-retest reliability for events that may not be replicable during a controlled experiment. Social and behavioral scientists attempting behavioral measurement through well-validated measures should be aware of whether large environmental changes can affect measure reliability, and how long such a disruption may last.
Alarm fatigue is a complex phenomenon that needs to be assessed within the context of the clinical setting. Considering that complexity, the available information on how to address alarm fatigue and improve alarm system safety is relatively scarce. This article summarizes the state of science in alarm system safety based on the eight dimensions of a sociotechnical model for studying health information technology in complex adaptive healthcare systems. The summary and recommendations were guided by available systematic reviews on the topic, interventional studies published between January 2019 and February 2022, and recommendations and evidence-based practice interventions published by professional organizations. The current article suggests implications to help researchers respond to the gap in science related to alarm safety, help vendors design safe monitoring systems, and help clinical leaders apply evidence-based strategies to improve alarm safety in their settings. Physiologic monitors in intensive care units—the devices most commonly used in complex care environments and associated with the highest number of alarms and deaths—are the focus of the current work.
As increasingly more vehicles are connected to the Internet, cyber attacks against vehicles are becoming a real threat with devastating consequences. This highlights the importance of detecting vehicle cyber attacks before fatal accidents occur. One natural method for tackling this problem is to adapt existing approaches for detecting attacks in enterprize networks, but which has achieved limited success. In this article, we propose a new approach to treat vehicles as cyber-physical-human systems, leading to a novel framework called exploiting human, physical and driving behaviors to detect vehicle cyber attacks (ExHPD). The framework has four detectors: 1) a human detector; 2) a physical behavior-based detector; 3) a driving behavior-based detector (DBD); and 4) an integrated physical and DBD. As the proof of concept, we recruited 50 drivers to conduct institutional review board-approved simulation-based driving tests. The experimental results show that ExHPD is effective to detect vehicle cyber attacks and avoid deadly crashes by offering drivers adequate time to safely pull over their compromised vehicle. The impact of driver's impulsiveness (one aspect of human factors) on the detectors' effectiveness and limitations of the present study are discussed. Future research directions toward an ultimately usable solution are outlined.
Unlike conventional servers housed in a centralized and secured indoor environment (e.g., data centers), Internet-of-Things (IoT) devices such as sensor/actuator are geographically distributed and may be closely located to the physical systems where IoT devices are utilized. However, the resource-constrained nature of IoT devices limits their capacity to deploy sophisticated security solutions. The proposed approach assumes that a device can be compromised and hence, the need to be able to automatically isolate the compromised device(s). In order to enforce security policies even when devices are compromised, we propose using blockchain in the monitoring framework. Unlike existing centralized or distributed security solutions (which do not consider the possibility that the solutions themselves can be compromised), the proposed blockchain-based framework can enforce the security policies as long as a majority of the devices are not compromised. By employing the permissioned blockchain (Hyperledger Fabric) and add-on hardware modules, the proposed framework offers significantly lower latency and overhead compared to permissionless blockchain frameworks (e.g., Ethereum) and allows existing IoT devices to join the framework without modification.
Automatically detecting software vulnerabilities in source code is an important problem that has attracted much attention. In particular, deep learning-based vulnerability detectors, or DL-based detectors, are attractive because they do not need human experts to define features or patterns of vulnerabilities. However, such detectors' robustness is unclear. In this paper, we initiate the study in this aspect by demonstrating that DL-based detectors are not robust against simple code transformations, dubbed attacks in this paper, as these transformations may be leveraged for malicious purposes. As a first step towards making DL-based detectors robust against such attacks, we propose an innovative framework, dubbed ZigZag, which is centered at (i) decoupling feature learning and classifier learning and (ii) using a ZigZag-style strategy to iteratively refine them until they converge to robust features and robust classifiers. Experimental results show that the ZigZag framework can substantially improve the robustness of DL-based detectors.
Background Clinical alarm system safety is a national patient safety goal in the United States. Physiologic monitors are associated with the highest number of device alarms and alarm-related deaths. However, research involving nurses’ use of physiologic monitors is rare. Hence, the identification of critical usability issues for monitors, especially those related to patient safety, is a nursing imperative. Objective This study examined nurses’ usability of physiologic monitors in intensive care units with respect to the effectiveness and efficiency of monitor use. Methods In total, 30 nurses from 4 adult intensive care units completed 40 tasks in a simulation environment. The tasks were common monitoring tasks that were crucial for appropriate monitoring and safe alarm management across four categories of competencies: admitting, transferring, and discharging patients using the monitors (7 tasks); managing measurements and monitor settings (23 tasks); performing electrocardiogram (ECG) analysis (7 tasks); and troubleshooting alarm conditions (3 tasks). The nurse-monitor interaction was video-recorded. The principal investigator and two expert intensive care units nurse educators identified, classified, and validated task success (effectiveness) and the time of task completion (efficiency). Results Among the 40 tasks, only 2 (5%) were successfully completed by all the nurses. At least 1-27 (3%-90%) nurses abandoned or did not correctly perform 38 tasks. The task with the shortest completion time was “take monitor out of standby” (mean 0:02, SD 0:01 min:s), whereas the task “record a 25 mm/s ECG strip of any of the ECG leads” had the longest completion time (mean 1:14, SD 0:32 min:s). The total time to complete 37 navigation-related tasks ranged from a minimum of 3 min 57 s to a maximum of 32 min 42 s. Regression analysis showed that it took 6 s per click or step to successfully complete a task. To understand the nurses’ thought processes during monitor navigation, the authors analyzed the paths of the 2 tasks with the lowest successful completion rates, where only 13% (4/30) of the nurses correctly completed these 2 tasks. Although 30% (9/30) of the nurses accessed the correct screen first for task 1 and task 2, they could not find their way easily from there to successfully complete the 2 tasks. Conclusions Usability testing of physiologic monitors revealed major ineffectiveness and inefficiencies in the current nurse-monitor interactions. The results indicate the potential for safety and productivity issues in completing routine tasks. Training on monitor use should include critical monitoring functions that are necessary for safe, effective, efficient, and appropriate monitoring to include knowledge of the shortest navigation path. It is imperative that vendors’ future monitor designs mimic clinicians’ thought processes for successful, safe, and efficient monitor navigation.
Frederick Sheldon合作论文数Computational Science and Engineering
Oak Ridge National Lab3
Ragib Hasan合作论文数University of Alabama at Birmingham2