Backdoor attacks on 3D Point Clouds (PCs) pose a serious threat by embedding hidden triggers into a subset of the training data. These triggers cause targeted misclassifications at inference time while leaving the model’s behavior unaffected in the absence of triggers, making them stealthy and difficult to detect. In distributed learning settings, where a central trainer aggregates data from multiple sources and offers only black-box access to the model, a single malicious contributor can compromise the model’s integrity if defenses are not in place. We propose a novel client-side defense that empowers individual contributors to act as vigilante defenders. By injecting benign ‘vaccination’ triggers—identified via Particle Swarm Optimization—into their local training data, defenders can proactively neutralize potential backdoors without prior knowledge of their location or structure. Experiments on standard benchmarks with PointNet and DGCNN show our method significantly reduces attack success while preserving classification accuracy, outperforming existing defenses.
Is it secure to measure the reliability of local models by similarity in federated learning (FL)? This paper delves into an unexplored security threat concerning applying similarity metrics, such as the L_2 norm, Euclidean distance, and cosine similarity, in protecting FL. We first uncover the deficiencies of similarity metrics that high-dimensional local models, including benign and poisoned models, may be evaluated to have the same similarity while being significantly different in the parameter values. We then leverage this finding to devise a novel untargeted model poisoning attack, Faker, which launches the attack by simultaneously maximizing the evaluated similarity of the poisoned local model and the difference in the parameter values. Experimental results based on seven datasets and eight defenses show that Faker outperforms the state-of-the-art benchmark attacks by 1.1-9.0X in reducing accuracy and 1.2-8.0X in saving time cost, which even holds for the case of a single malicious client with limited knowledge about the FL system. Moreover, Faker can degrade the performance of the global model by attacking only once. We also preliminarily explore extending Faker to other attacks, such as backdoor attacks and Sybil attacks. Lastly, we provide a model evaluation strategy, called the similarity of partial parameters (SPP), to defend against Faker. Given that numerous mechanisms in FL utilize similarity metrics to assess local models, this work suggests that we should be vigilant regarding the potential risks of using these metrics.
The Three Gorges Region (TGR) of the Yangtze River basin exhibited warm and dry climatic characteristics in 2024. The annual mean temperature in the TGR was 18.6 degrees C, which was 1.2 degrees C above normal and marked the highest level since 1961. All four seasons were warmer than normal, with spring and autumn both recording their highest temperatures since 1961. Additionally, the TGR recorded 57.2 high-temperature days in 2024, reaching a historic high since 1961 and exceeding the previous record set in 2022 by 2.4 days. Annual rainfall was 11.2 % below normal, with spring, summer, and autumn all being drier than normal. However, the number of heavy rain days was slightly higher than normal. The annual mean wind speed in the TGR ranked as the second-highest since 1961, only slightly lower than in 2022. The annual mean relative humidity was below normal and the number of fog days across large areas of the TGR decreased compared to 2023. In 2024, the TGR experienced extreme high-temperature events characterized by exceptional intensity and prolonged duration, accompanied by generally severe meteorological drought conditions. During the year, the TGR also experienced frequent and intense cooling events, an early onset of heavy rainfall (including severe convective weather), and exceptionally extreme rainstorm events.
The prolonged COVID-19 pandemic during the 2020 U.S. general election highlighted the significant challenges and risks associated with voting in person at booths, leading to frustration, pain, and even life-threatening consequences. This unexpected crisis underscored the urgent need for a secure, accessible, and robust voting platform that enables voters to cast their ballots remotely with peace of mind. Building on our previous work [1], this paper presents a practical and resilient e-voting system designed to ensure enduring privacy through secret sharing. Voters can cast their ballots remotely without needing to visit a voting booth, while also having the ability to verify their individual plain/clear votes. The system allows anyone to tally and verify vote counts for all candidates both visually and technically, making the entire process—from ballot casting to tallying and verification—transparent and publicly accessible. The system is resistant to both insider misbehavior and external attacks. Additionally, the new e-voting technique incorporates an all-or-nothing principle, ensuring that no partial results are disclosed, and trust is evenly distributed among all participants. As a result, this technique provides a secure and fair solution for public elections.
To become a DHS/NSA Center of Academic Excellence in Cyber Defense (CAE-CD), academic institutions must satisfy several specific Knowledge Units (KUs). How they achieve this is up to the institutions. In this case study, we follow the methodology of an earlier work to demonstrate how key parts of an electronic voting (E-voting)-oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, maps into the DHS/NSA KUs supporting the CAE-CD designation, from two aspects: E-voting principle based topics, i.e., from theory and a plug-and-play e-voting system's composing components, i.e., from practice. We grouped CAE-CD KUs into those required as prerequisites, closely related, related/supported, and not covered by the E-voting curriculum. Teachers can then choose which KUs they will use and teach using only the parts of the E-voting-oriented curriculum they deem relevant, and in a depth they find appropriate to their educational objectives, while meeting the requirements of the selected KUs. We conclude with a discussion of how LLMs (Large Language Models) and quantum computing might be added to the E-voting-oriented curriculum.
Federated Learning (FL) enhances model performance for participants with limited data but is highly vulnerable to backdoor attacks. Unlike Byzantine attacks, backdoor attacks infiltrate local models undetected, causing selective misclassification under specific conditions. Existing defenses rely entirely on a trusted central server, raising concerns if the server fails or acts maliciously. This article introduces a novel vaccination-based technique, empowering clients to defend their models independently with minimal computation and no communication overhead. Our approach is effective even when only a subset of benign clients adopt the protocol, offering a practical, client-centric solution to enhance FL security. Experimental results demonstrate that our method reduces the attack success rate (ASR) to as low as 4.17%, compared to over 47% for state-of-the-art defenses like FoolsGold, while maintaining a high main task accuracy of 82.94%, closely matching the baseline accuracy of 83.21%. Furthermore, even when the proportion of malicious participants exceeds 60%, the backdoor trigger is not part of the vaccine trigger or only one client follows the vaccination protocol, the ASR remains below 7.8%.
The year 2024 witnessed remarkable climatic anomalies across China,characterized by pronounced warm and wet conditions.The annual mean temperature soared to a record high since 1951,with seasonal temperatures in spring,summer,and autumn all exceeding historical extremes.Meanwhile,the annual precipitation ranked as the fourth highest on record,with all four seasons experiencing above-average rainfall.Notably,the Yangtze River Basin and Jiangnan region encountered their most intense precipitation event since 1961.Extreme weather events were particularly striking:An unusually early and severe heatwave swept through central and eastern China,becoming the second most intense high-temperature event in recorded history.Autumn typhoon activity also displayed exceptional intensity,with Typhoon Yagi triggering significant impacts in Hainan,Guangdong,and Guangxi.Although drought conditions were generally mild overall,notable seasonal and regional disparities emerged,especially in the winter-spring droughts affecting southwestern China.Conversely,cold outbreaks oc-curred more frequently than usual,and convective weather events exhibited heightened activity.Moreover,dust storm activity remained relatively limited.
Based on daily observation data of the Three Gorges Region (TGR) of the Yangtze River basin and global reanalysis data, the climate characteristics, climate events, and meteorological disasters of the TGR in 2022 and 2023 were analyzed. For the TGR, the average annual temperature for 2022 and 2023 was 0.8 degrees C and 0.4 degrees C higher than normal, respectively, making them the two warmest years in the past decade. In 2022, the TGR experienced its warmest summer on record. The average air temperature was 2.4 degrees C higher than the average, and there were 24.8 days of above-average high temperature days during summer. Rainfall in the TGR varied significantly between 2022 and 2023. Annual rainfall was 18.4 % below normal and drier than normal in most parts of the region. In contrast, the precipitation in 2023 was considerably higher than the long-term average, and above normal for almost the entire year. The average wind speed exhibited minimal variation between the two years. However, the number of foggy days and relative humidity increased in 2023 compared to 2022. In 2022-2023, the TGR mainly experienced meteorological disasters such as extreme high temperatures, regional heavy rain and flooding, overcast rain, and inverted spring chill. Analysis indicates that the abnormal western Pacific subtropical high and the abnormal persistence of the eastward-shifted South Asian high were the two important drivers of the durative enhancement of record-breaking high temperature in the summer of 2022.
Federated Learning (FL) is an emerging subclass of Artificial Intelligence that decentralizes the learning process. Unlike the well-studied Horizontal Federated Learning (HFL), which requires the feature space of all participants to be the same, the newly emerging Vertical Federated Learning (VFL) allows participants to hold different features, provided the sample space is the same. This unique aspect enables VFL to incorporate features from different data modalities, a capability that has not yet been sufficiently explored. Currently, VFL researchers adapt datasets originally used for HFL by splitting the data vertically, whether it is text, tabular, or image data. In this paper, we extend the application of VFL to multimodal datasets, specifically in the field of Intelligent Transportation. We build models by combining local models from participants holding CCTV image datasets and Traffic flow tabular datasets. Due to the absence of suitable existing datasets, we introduce a new dataset, the INDOT traffic dataset, which also supports sequential training across time and distance. Our experiments demonstrate the efficiency of VFL in the multimodal traffic analysis scenario and aim to expand the scope of VFL research.
China witnessed a warm and dry climate in 2023. The annual surface air temperature reached a new high of 10.71 degrees C, with the hottest autumn and the second hottest summer since 1961. Meanwhile, the annual precipitation was the second lowest since 2012, at 615.0 mm. Precipitation was less than normal from winter to summer, but more in autumn. Consistent with the annual condition, precipitation in the flood season from May to September was also the second lowest since 2012, which was 4.3% less than normal, with the anomalies in the central and eastern parts of China being higher in central areas and lower in the north and south. On the contrary, the West China Autumn Rain brought much more rainfall than normal, with an earlier start and later end. Although there was less annual precipitation in 2023, China suffered seriously from heavy precipitation events and floods. In particular, from the end of July to the beginning of August, a rare, extremely strong rainstorm caused by Typhoon Dussuri hit Beijing, Tianjin, and Hebei, causing an abrupt alteration from drought to flood conditions in North China. By contrast, Southwest China experienced continuous drought from the previous autumn to current spring. In early summer, North China and the Huanghuai region experienced the strongest high-temperature process since 1961. Nevertheless, there were more cold-air processes than normal impacting China, with the most severe of the year occurring in mid-January. Unexpectedly, in spring, there were more sand and dust occurrences in northern China.
Existing Federated Learning (FL) methods are highly influenced by the training data distribution. In the single global model FL systems, users with highly non-IID data do not improve the global model, and neither does the global model work well on their local data distribution. Even with the clustering-based FL approaches, not all participants get clustered adequately enough for the models to fulfill their local demands. In this work, we design a modified subjective logic-based FL system utilizing the distribution-based similarity among users. Each participant has complete control over their own aggregated model, with handpicked contributions from other participants. The existing clustered model only satisfies a subset of clients, while our individual aggregated models satisfy all the clients. We design a decentralized FL approach, which functions without a trusted central server; the communication and computation overhead is distributed among the clients. We also develop a layer-wise secret-sharing scheme to amplify privacy. We experimentally show that our approach improves the performance of each participant’s aggregated model on their local distribution over the existing single global model and clustering-based approach.
Network Intrusions are an ever present threat in the modern age of instant transmission of data over the cyberspace. Ideally, an effective cybersecurity mechanism will detect an attack before it affects a given network. Hence, organizations utilize Network Intrusion Detection Systems (NIDS) to monitor incoming network traffic for all potential misuses. For this research, we present a novel method for aggregating network traffic into a graph for representation learning capable of outperforming existing NIDS in literature. We apply and validate our methods on numerous publically available network flow datasets for demonstrable and concrete performance evaluation.
China experienced a warm and dry climate in 2022. The average annual surface air temperature (SAT) was 10.51 degrees C, which was the second highest since 1961. The annual average rainfall was 606.1 mm, which was the lowest since 2012. The seasonal SAT broke the record in spring, summer, and autumn, while the SAT in winter was slightly cooler. More rainfall was observed in winter and spring, but less in summer and autumn. During the flood season from May to September, rainfall was 11.9% less than normal, which was the third lowest since 1961. The spatial distribution of rainfall anomalies exhibited a wet/dry pattern in the north/south of central and eastern China. The onset of the rainy season was generally earlier but with significant differences in rainfall. More rainfall was observed in the pre-flood season in South China and the rainy season in North China and Northeast China. In contrast, less rainfall occurred in the Mei-yu season in the middle and lower reaches of the Yangtze and Huaihe River valleys, the southwestern rainy season, and the autumn rainy season in West China. In 2022, China's drought and flood disasters were stark, and heat waves were strong. Severe droughts occurred along the Yangtze River valley during summer and autumn, while heavy rainfall and flooding struck South China in the pre-flood season and Northeast China in June-July. A historically strongest summer heat wave occurred in central and eastern China, while drastic cooling prevailed in most of China at the end of November. Landfalling typhoons were extremely less frequent.
The most cost-effective method of cybersecurity is prevention. Therefore, organizations and individuals utilize Network Intrusion Detection Systems (NIDS) to inspect network flow for potential intrusions. However, Deep Learning based NIDS still struggle with high false alarm rates and detecting novel and unseen attacks. Therefore, in this paper, we propose a novel NIDS framework based on generating images from feature vectors and applying Unsupervised Deep Learning. For evaluation, we apply this method on four publicly available datasets and have demonstrated an accuracy improvement of up to 8.25 % when compared to Deep Learning models applied to the original feature vectors.
基于北京、天津、河北、山东、河南5省(直辖市)437个国家级气象站数据和美国气象环境预报中心(National Centers for Environmental Prediction,NCEP)及美国国家大气研究中心(National Center for Atmospheric Research,NCAR)制作的日平均再分析数据,采用气候统计诊断方法,对2023年6-7月我国华北、黄淮高温天气的特点及其成因进行分析.结果表明,2023年6-7月华北、黄淮地区平均气温和平均最高气温均为1961年以来历史同期最高.北京、天津、河北、山东、河南5省(直辖市)的平均气温和平均最高气温均明显高于常年同期,其中北京市、天津市、河北省的平均气温和平均最高气温均为1961年以来历史同期最高.北京市、天津市和河北省的高温日数均为1961年以来历史同期最多.华北、黄淮地区有200个国家级气象观测站日最高气温达到或超过40℃;有126个国家级气象观测站日最高气温达极端事件监测标准,其中河北井陉、河南林州、北京汤河口等26个国家级气象观测站达到或突破历史极值.2023年6月21日至7月9日的华北、黄淮地区高温过程的综合强度,在近33年的中国历次区域性高温过程中排名第1.诊断分析表明,全球变暖是这次极端高温热浪事件发生的大背景,大气环流异常是高温持续且极端性突出的直接原因.
An electronic voting (E-voting) oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, leverages the rich security features of E-voting systems and E-voting process to teach essential concepts of cybersecurity. Existing curricular guidelines describe topics in computer security, but do not instantiate them with examples. This is because their goals are different. In this case study, we map the e-voting curriculum into the CSEC2017 curriculum guidelines, to demonstrate how such a mapping is done. Further, this enables teachers to select the parts of the e-voting curriculum most relevant to their classes, by basing the selection on the relevant CSEC2017 learning objectives. We conclude with a brief discussion on generalizing this mapping to other curricular guidelines.
Federated Learning (FL) provides an opportunity for clients with limited data resources to combine and build better Machine Learning models without compromising their privacy. But aggregating contributions from various clients implies that the errors present in some clients’ resources will also get propagated to all the clients through the combined model. Malicious entities leverage this negative factor to disrupt the normal functioning of the FL system for their gain. A backdoor attack is one such attack where the malicious entities act as clients and implant a small trigger into the global model. Once implanted, the model performs the attacker desired task in the presence of the trigger but acts benignly otherwise. In this paper, we build a GAN-inspired defense mechanism that can detect and defend against the presence of such backdoor triggers. The unavailability of labeled benign and backdoored models has prevented researchers from building detection classifiers. We tackle this problem by utilizing the clients as Generators to construct the required dataset. We place the Discriminator on the server-side, which acts as a backdoored model detecting binary classifier. We experimentally prove the proficiency of our approach with the image-based non-IID datasets, CIFAR10 and CelebA. Our prediction probability-based defense mechanism successfully removes all the influence of backdoors from the global model.
An electronic voting (e-voting) based interactive cybersecurity education curriculum has been proposed recently. It is well-known that assignments and projects are coherent parts of and important for any curriculum. This paper proposes a set of course projects, assignment design, and a coherent online plug-and-play (PnP) platform implementation. The PnP platform and the proposed exemplary assignments and projects, are systematic (derived from the same system), adaptive (smoothly increasing difficulty), flexible (bound to protocols instead of implementations), and interactive (teacher-student and student-student interactions). They allow students to implement parts of the components of this e-voting system, which they can then plug into the PnP system, to run, test and modify their implementations, and to enhance their knowledge and skills on cryptography, cybersecurity, and software engineering.
Biometric Facial Authentication has become a pervasive mode of authentication in recent years. With this surge in popularity, concerns over the security and privacy of biometrics-based systems have grown. Therefore, there is a need for a system that can address security and privacy issues while remaining user-friendly and practical. The BioCapsule scheme is a flexible solution that can be embedded in existing biometrics systems in order to provide robust security and privacy protections. While BioCapsules have been evaluated for their static face authentication capabilities, this paper extends the scheme to Active Authentication, where a user is continuously authenticated throughout a session. We use the MOBIO dataset, which contains video recordings of 150 individuals using mobile devices over several sessions, in order to evaluate the BioCapsule scheme within the domain of Active Authentication. We find that the BioCapsule scheme not only performs comparably to baseline, unsecured system performance, but in some cases exceeds baseline performance in terms of False Acceptance Rate, False Rejection Rate, and Equal Error Rate. Through our experiments, we demonstrate that the BioCapsule scheme is a powerful and practical addition to existing biometrics-based Active Authentication systems to provide robust security and privacy protections.
Eliza Yingzi Du合作论文数Department of Electrical and Computer Engineering, School of Engineering and Technology, Indiana University-Purdue University9