With cyberspace becoming ever more fiercely contested, blue team operations face a growing demand for more efficient and sophisticated capabilities. One way to meet this demand is by integrating Human-Machine Teaming (HMT) and autonomous cyber defence (ACD), enhancing blue team collaboration with AI-driven machines. A rigorous analysis of their interaction dynamics is essential to ensure these technologies are safely deployed in high-stakes environments.This study employs Systems Theoretic Process Analysis (STPA) to examine the control actions and feedback loops between machines and controlled processors in the context of ACD, identifying potential hazards and losses arising from unsafe control actions. Additionally, it establishes system constraints to mitigate risks and enhance the safety and reliability of AI-driven HMT operations.
Cyberspace has become a domain for state and non-state actors to engage in activities that operate in the area between peace and conflict, often referred to as the “grey zone.” These activities, which range from legal to illegal, exploit the lack of thresholds and norms, creating challenges for understanding impact and managing consequences. This research examines the complexities of cyberspace and grey zone activities, which operate between peace and wartime, using activities ranging from legality to illegality. Addressing the lack of clarity in understanding their impact and management, the study introduces a five-block framework to systematically analyse and triage these activities. The blocks – i) Incident, ii) Technical Analysis, iii) Strategic Context, iv) Operational Preparation, v) Legality and Political Will. This structured approach enables a comprehensive breakdown of situations, assessing strategic significance and providing a benchmark for evaluating proximity to thresholds. The framework is designed to assist policymakers, strategists, and cybersecurity professionals in navigating the complexities of grey zone activities in cyberspace. This study contributes to developing more effective responses to ambiguous and evolving threats by offering a tool for informed decision-making.
Background/Objectives: Transcutaneous electrical acupoint stimulation (TEAS), also known as transcutaneous electroacupuncture stimulation, delivers electrical pulses to the skin over acupuncture points (“acupoints”) via surface electrodes. Electroencephalography (EEG) is an important tool for assessing the changes in the central nervous system (CNS) that may result from applying different TEAS frequencies peripherally—i.e., acting via the peripheral nervous system (PNS)—and determining how these influence cerebral activity and neural plasticity. Methods: A total of 48 healthy volunteers were allocated in a semi-randomized crossover study to receive four different TEAS frequencies: 2.5 pulses per second (pps); 10 pps; 80 pps; and sham (160 pps at a low, clinically ineffective amplitude). TEAS was applied for 20 min to each hand at the acupuncture point Hegu (LI4). The EEG was recorded during an initial 5 min baseline recording, then during TEAS application, and after stimulation for a further 15 min, separated into three periods of 5 min (initial, intermediate, and final) in order to assess post-stimulation changes. Source localization analysis was conducted for the traditional five EEG frequency bands: delta (0.1–3.9 Hz), theta (4–7.9 Hz), alpha (8–13 Hz), beta (14–30 Hz), and gamma (30.1–45 Hz). Results: Within-group source localization analyses of EEG data showed that during the initial 5 min post-stimulation, theta oscillations in the 2.5 pps TEAS group increased over the parahippocampal gyrus (t = 4.42, p < 0.01). The 10 pps TEAS group exhibited decreased alpha rhythms over the inferior parietal gyrus (t = −4.20, p < 0.05), whereas the sham (160 pps) TEAS group showed decreased delta rhythms over the postcentral gyrus (t = −3.97, p < 0.05). During the intermediate 5 min post-stimulation, the increased theta activity over the left parahippocampal gyrus (BA27) remained in the 2.5 pps TEAS group (t = 3.97, p < 0.05). However, diminished alpha rhythms were observed in the 10 pps TEAS group over the postcentral gyrus (t = −4.20, p < 0.01), as well as in the delta rhythms in the sham (160 pps) TEAS group in the same area (t = −4.35, p < 0.01). In the final 5 min post-stimulation, reduced alpha rhythms were exhibited over the insula in the 10 pps TEAS group (t = −4.07, p < 0.05). Interaction effects of condition by group demonstrate decreased alpha rhythms in the 10 pps TEAS group over the supramarginal gyrus during the initial 5 min post-stimulation (t = −4.31, p < 0.05), and decreased delta rhythms over the insula in the sham TEAS group during the final 5 min post-stimulation (t = −4.42, p < 0.01). Conclusions: This study revealed that low TEAS frequencies of 2.5 pps and 10 pps modulate theta and alpha oscillations over the brain areas related to emotional and attentional processes driven by external stimuli, as well as neural synchronization of delta rhythms in the sham group in brain areas related to stimulus expectation at baseline. It is hoped that these findings will stimulate further research in order to evaluate such TEAS modulation effects in clinical patients.
Appears in: INTED2024 Proceedings Publication year: 2024Pages: 5435-5441ISBN: 978-84-09-59215-9ISSN: 2340-1079doi: 10.21125/inted.2024.1405Conference name: 18th International Technology, Education and Development ConferenceDates: 4-6 March, 2024Location: Valencia, Spain
Lower leg pain and symptoms, and poor leg circulation are common in older adults. These can significantly affect their function and quality of life. Neuromuscular electrical stimulation (NMES) applied via the feet as ‘foot NMES’ activates the leg musculovenous pump. This study investigated the effects of foot NMES administered at home using Revitive® among community-dwelling older adults with lower leg pain and/or other lower leg symptoms such as cramps, or sensations of tired, aching, and heavy feeling legs. A randomised placebo-controlled study with three groups (2 NMES, 1 Sham) and three assessments (baseline, week 8, week 12 follow-up) was carried out. Self-reported function using Canadian occupational performance measure (COPM), leg pain, overall leg symptoms score (heaviness, tiredness, aching, or cramps), and ankle blood flow were assessed. Analysis of covariance (ANCOVA) and logistic regression were used to compare the groups. Statistical significance was set at p < 0.05 (two-sided 5 https://www.isrctn.com/ISRCTN10576209 . • Eight weeks of daily home-based foot NMES therapy delivered using Revitive devices significantly improved self-reported function, leg pain and other leg symptoms in community-dwelling older adults when compared to a Sham. • Significant improvements in self-reported function and leg symptoms were sustained when measured at the follow-up four weeks after the intervention period. • During use, the foot NMES induced approximately a three-fold increase in ankle blood flow volume and intensity of blood flow when compared to a Sham. • No device-related adverse events were reported. • Compliance with the foot NMES intervention was high.
Communication networks able to withstand hostile environments are critically important for disaster relief operations. In this paper, we consider a challenging scenario where drones have been compromised in the supply chain, during their manufacture, and harbour malicious software capable of wide-ranging and infectious disruption. We investigate multi-agent deep reinforcement learning as a tool for learning defensive strategies that maximise communications bandwidth despite continual adversarial interference. Using a public challenge for learning network resilience strategies, we propose a state-of-the-art symbolic technique and study its superiority over deep reinforcement learning agents. Correspondingly, we identify three specific methods for improving the performance of our neural agents: (1) ensuring each observation contains the necessary information, (2) using symbolic agents to provide a curriculum for learning, and (3) paying close attention to reward. We apply our methods and present a new mixed strategy enabling symbolic and neural agents to work together and improve on all prior results.
The field of signal processing using machine and deep learning algorithms has undergone significant growth in the last few years, with a wide scope of practical applications for electroencephalography (EEG). Transcutaneous electroacupuncture stimulation (TEAS) is a well-established variant of the traditional method of acupuncture that is also receiving increasing research attention. This paper presents the results of using deep learning algorithms on EEG data to investigate the effects on the brain of different frequencies of TEAS when applied to the hands in 66 participants, before, during and immediately after 20 min of stimulation. Wavelet packet decomposition (WPD) and a hybrid Convolutional Neural Network Long Short-Term Memory (CNN-LSTM) model were used to examine the central effects of this peripheral stimulation. The classification results were analysed using confusion matrices, with kappa as a metric. Contrary to expectation, the greatest differences in EEG from baseline occurred during TEAS at 80 pulses per second (pps) or in the 'sham' (160 pps, zero amplitude), while the smallest differences occurred during 2.5 or 10 pps stimulation (mean kappa 0.414). The mean and CV for kappa were considerably higher for the CNN-LSTM than for the Multilayer Perceptron Neural Network (MLP-NN) model. As far as we are aware, from the published literature, no prior artificial intelligence (AI) research appears to have been conducted into the effects on EEG of different frequencies of electroacupuncture-type stimulation (whether EA or TEAS). This ground-breaking study thus offers a significant contribution to the literature. However, as with all (unsupervised) DL methods, a particular challenge is that the results are not easy to interpret, due to the complexity of the algorithms and the lack of a clear understanding of the underlying mechanisms. There is therefore scope for further research that explores the effects of the frequency of TEAS on EEG using AI methods, with the most obvious place to start being a hybrid CNN-LSTM model. This would allow for better extraction of information to understand the central effects of peripheral stimulation.
This paper presents a systematic literature review (SLR) on cybersecurity in the automotive industry. Using the R tool Bibliometrix, a total of 537 papers related to cybersecurity and the automotive industry were analyzed. First, our paper contributes to academia by showing that research on this topic is grouped into four clusters that correspond to four lines of research: Automotive Security; Vehicle Engineering; Smart Vehicle; IT Security. Second, our paper contributes to the literature by highlighting the existing gaps. On the subject of standards and framework, there are gaps in terms of what the security requirements must be for the vehicle. This is very important since, given the heterogeneity of technology that vehicles from different manufacturers have, the cybersecurity requirements are different. Additionally, a gap can also be observed in the literature on the supply chain, which has a very small number of papers. In general, they do not cover or elaborate on the supply chain security, when, from a manufacturing point of view, it is very important to manage an effective cybersecurity strategy for the vehicles. Moreover, our paper also contributes to managers and policy-makers' understanding of cybersecurity. We show that adequate implementation of cybersecurity in the automotive must involve a multidimensional perspective. First, it should be a multistage model, ranging from the first stages of design in interconnection with the suppliers to the final stages of use by the customer. Second, it should be a multi-level model, as a consequence of the interconnection of the vehicle's control systems. Finally, the model should be multi-feedback, structuring the process design as a feedback system, including incident response, diagnosis services and vehicle updates.
Numerous attempts have been made to create a secure system that meets the criteria and requirements of the vehicle development life cycle. However, there is a critical gap in the secure development lifecycle, especially when it comes to developing software, which is the maintenance phase (involving modifications and upkeep of the solution after the product is launched on the market, with a focus on maintaining security). This step is overlooked by OEMs (Original Equipment Manufacturers), especially after the vehicle has left the dealership, given the cost that it will require to update and test the software and functionality in their vehicles when the warranty period is over. This paper addresses the issues that affect current and future vehicle security, during the maintenance and diffusion and after its warranty period has passed, and how this could end in a hazard to the vehicle owner or other road users. To do this, we will use the technology adoption model (TAM) as a theoretical framework, which is used to understand and predict how organisations adopt the technology. Thus, based on qualitative research, we identify what the main challenges are in the adoption and diffusion of cyber security in the automotive sector supply chain. In addition, we propose possible solutions on how to maintain the level of security that will benefit road users, OEMs and regulators. Covering the cyber security needs for the whole vehicle life and given the vehicle heterogeneity of components and technology, the connectivity, the environmental impact and the cost of production and maintenance of the vehicle.
There is an increasing demand for Internet of Things (IoT) networks consisting of resource-constrained devices executing increasingly complex applications. Due to these resource constraints, IoT devices will not be able to execute expensive tasks. One solution is to offload expensive tasks to resource-rich edge nodes, which requires a framework that facilitates the selection of suitable edge nodes to perform task offloading. Therefore, in this article, we present a novel trust-model-driven system architecture, based on behavioral evidence, that is suitable for resource-constrained IoT devices and supports computation offloading. We demonstrate the viability of the proposed architecture with an example deployment of the Beta Reputation System trust model on real hardware to capture node behaviors. The open environment of edge-based IoT networks means that threats against edge nodes can lead to deviation from expected behavior. Hence, we perform a threat modeling to identify such threats. The proposed system architecture includes threat handling mechanisms that provide security properties such as confidentiality, authentication, and non-repudiation of messages in required scenarios and operate within the resource constraints. We evaluate the efficacy of the threat handling mechanisms and identify future work for the standards used.
The concept of twinning an operational physical system with a functional replica is not new, having been practiced in the space sector for over 50 years. Advances in digitalisation have created opportunities to extract data, obtain insights and achieve greater situational awareness of a physical system’s performance. Increasing interest in the concept has led to a proliferation of digital twin definitions, which are used to frame discussions about specific digital twins. Consequentially comparison of the capabilities of specific digital twins is difficult as they are analysed using different definitions. This paper proposes an analysis framework that enables the characteristics of all digital twins to be matched to this framework. Using this framework, a digital twin may be characterised, or two or more digital twins may be compared. By establishing a framework that contains common functional characteristics, we aim to reduce the confusion caused by the plethora of digital twin definitions and their interpretation by suppliers. By focusing only on functionality and not addressing non-functional requirements the analysis allows comparison of different physical and logical instantiations of digital twins.
Resource-constrained Internet of Things (IoT) devices are executing increasingly sophisticated applications that may require computational or memory intensive tasks to be executed. Due to their resource constraints, IoT devices may be unable to compute these tasks and will offload them to more powerful resource-rich edge nodes. However, as edge nodes may not necessarily behave as expected, an IoT device needs to be able to select which edge node should execute its tasks. This selection problem can be addressed by using a measure of behavioural trust of the edge nodes delivering a correct response, based on historical information about past interactions with edge nodes that are stored in memory. However, due to their constrained memory capacity, IoT devices will only be able to store a limited amount of trust information, thereby requiring an eviction strategy when its memory is full of which there has been limited investigation in the literature. To address this, we develop the concept of the memory profile of an agent and that profile’s utility. We formalise the profile eviction problem in a unified profile memory model and show it is NP-complete. To circumvent the inherent complexity, we study the performance of eviction algorithms in a partitioned profile memory model using our utility metric. Our results show that localised eviction strategies which only consider one specific type of information do not perform well. Thus we propose a novel eviction strategy that globally considers all types of trust information stored and we show that it outperforms local eviction strategies for the majority of memory sizes and agent behaviours. In this paper, we develop a concept of information utility to a trust model and formalise the problem of information eviction, which we prove to be NP-complete. We then investigate the usefulness of different eviction strategies to maximise the utility of information stored to enable trust-based task offloading.
What is it to be trusted? This is an important question as trust is increasingly placed in a system and the degree to which a system is trusted is increasingly being assessed. However, there are issues with how related terms are used. Many definitions focus on one attribute of trust (typically behaviour) preventing that definition from being used for other attributes (e.g., identity). This is confused further by conflating what trustors measure about a trustee and what conclusions a trustor reaches about a trustee. Therefore, in this paper we present definitions of measures (trustiness and trustworthiness) and conclusions (trusted and trustworthy). These definitions are general and do not refer to a specific attribute allowing them to be used with arbitrary attributes which are being assessed (e.g., identity, behaviour, limitation, execution, correctness, data, environment). In addition, in order to demonstrate the complexities of describing if a trustee is designated as trusted or trustworthy, a set of dimensions are defined to describe attributes (time, scale, proactive/reactive, strength, scope, source). Finally, an example system is classified using these attributes and their dimensions in order to highlight the complexities of describing a system as holistically trusted or trustworthy.
Maritime cyber security is an emerging issue that requires immediate attention, according to the International Maritime Organization (IMO). Feedback received from global shipping professionals indicate that a common threat to the industry, such as cyber security, is dealt with differently among industry practitioners around the globe. Data collected from two targeted focus groups (one in Europe and the second in Asia, two leading groups in the maritime transport sector) demonstrated that, based on technology adoption maturity, cyber security is perceived differently between these groups. The COVID-19 pandemic has highlighted these differences. Our findings lead to useful intelligence that will inform key maritime decision makers, both in meeting the IMO requirements and preparing the organization to address cyber risks.
There is an increasing demand for Internet of Things (IoT) systems comprised of resource-constrained sensor and actuator nodes executing increasingly complex applications, possibly simultaneously. IoT devices will not be able to execute computationally expensive tasks and will require more powerful computing nodes, called edge nodes, for such execution, in a process called computation offloading. When multiple powerful nodes are available, a selection problem arises: which edge node should a task be submitted to? This problem is even more acute when the system is subjected to attacks, such as DoS, or network perturbations such as system overload. In this paper, we present a trust model-based system architecture for computation offloading, based on behavioural evidence. The system architecture provides confidentiality, authentication and non-repudiation of messages in required scenarios and will operate within the resource constraints of embedded IoT nodes. We demonstrate the viability of the architecture with an example deployment of Beta Reputation System trust model on real hardware.