Next Issue
Volume 6, August
Previous Issue
Volume 6, April
 
 

J. Cybersecur. Priv., Volume 6, Issue 3 (June 2026) – 29 articles

Cover Story (view full-size image): Managing privacy settings across digital platforms remains a significant challenge for users of all expertise levels. Despite regulatory frameworks such as GDPR, poor interface design continues to hinder users effectively understanding and controlling their personal data. This study evaluates MIDA (My Information and Data Access), a human-centred privacy interface designed to adapt to users with varying levels of digital expertise. A usability study with 44 participants—novice, intermediate, and advanced—demonstrated high usability across all groups, with System Usability Scale scores ranging from 80 to 92, exceeding the accepted threshold. Task completion rates exceeded 80%, confirming MIDA's effectiveness as an expertise-adaptive solution. These findings offer empirical evidence that thoughtful interface design can meaningfully improve users' ability to manage their privacy. View this paper
  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list.
  • You may sign up for e-mail alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.
Order results
Result details
Section
Select all
Export citation of selected articles as:
35 pages, 1751 KB  
Article
An Explainable Hybrid Pipeline for Malware Classification: Benchmark Construction, Feature Reduction, and Security-Oriented Evaluation
by Carmelo Ardito, Giuseppe Loseto, Riccardo Di Pietro, Nicola Epicoco and Alessandro Massaro
J. Cybersecur. Priv. 2026, 6(3), 105; https://doi.org/10.3390/jcp6030105 - 22 Jun 2026
Viewed by 625
Abstract
Malware classification increasingly relies on machine learning models that combine static and dynamic evidence, yet their practical use is often limited by dataset inconsistency, high-dimensional feature spaces, and insufficient transparency. This paper presents an explainable hybrid malware-classification pipeline built on an aligned public [...] Read more.
Malware classification increasingly relies on machine learning models that combine static and dynamic evidence, yet their practical use is often limited by dataset inconsistency, high-dimensional feature spaces, and insufficient transparency. This paper presents an explainable hybrid malware-classification pipeline built on an aligned public dataset in which static and dynamic features are matched at sample level and share the same class space. The framework combines a Random Forest static branch, a calibrated XGBoost dynamic branch, and a weighted late-fusion stage whose branch weights are derived from inner-validation weighted-F1 rather than from test performance. On the corrected no-leak benchmark, static reduction compresses the static space from 771 to 258 features, while sparse-aggressive reduction compresses the dynamic space from 21,918 to 374 features. An early-fusion XGBoost baseline achieves the best multiclass aggregate scores, whereas the validation-weighted calibrated hybrid provides the strongest false-negative-first Benign vs. Malware profile, reaching malware recall 0.9998, benign recall 0.8053, and one false negative on the test set. The study shows that, once leakage is removed and fusion is validation-driven, the preferred hybrid architecture depends on the operational objective rather than on a single aggregate metric. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

27 pages, 6542 KB  
Article
Multidimensional Hill Cipher Substitution–Permutation Network
by Porter E. Coggins III
J. Cybersecur. Priv. 2026, 6(3), 104; https://doi.org/10.3390/jcp6030104 - 17 Jun 2026
Viewed by 691
Abstract
MD-Hill-SPN is the first Hill-based construction to combine a multi-tier diffusion mix layer, a memory-hard KDF, and a simultaneous multi-metric empirical evaluation. Two independent runs of the full metric suite yield: (a) full plaintext avalanche from round 1 (mean 63.97–64.67 of 128 bits, [...] Read more.
MD-Hill-SPN is the first Hill-based construction to combine a multi-tier diffusion mix layer, a memory-hard KDF, and a simultaneous multi-metric empirical evaluation. Two independent runs of the full metric suite yield: (a) full plaintext avalanche from round 1 (mean 63.97–64.67 of 128 bits, ideal 64); (b) the differential-probability sampling floor of 2 × 10−5 reached at round 4 (50,000 of 50,000 output differences distinct, both sessions); (c) algebraic-degree lower-bound saturation at the maximum observable value from round 1; (d) linear-bias indistinguishable from random (combined exceedance 4.40%, below the 4.55% noise floor); and (e) branch numbers at the Singleton (MDS) bound for every tier (B = 5 for 4 × 4, B = 9 for 8 × 8, B = 17 for 16 × 16), computed exhaustively over weight-1 inputs. MD-Hill-SPN therefore moves beyond theoretical construction to a construction that passes a defined empirical evaluation suite: avalanche, differential sampling, linear-bias probing, algebraic-degree lower bounds, and MDS branch numbers under single-key, known-plaintext conditions with fixed parameters, an evaluation no prior Hill cipher variant has reported in full. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

49 pages, 4324 KB  
Systematic Review
Privacy-Preserving Biometric Authentication in Resource-Constrained Environments: A PRISMA Systematic Review of Multimodal and Fuzzy-Vault Methods
by Shadrach Olarewaju, Ali Safaa Sadiq, Omprakash Kaiwartya and Alexandros Konios
J. Cybersecur. Priv. 2026, 6(3), 103; https://doi.org/10.3390/jcp6030103 - 12 Jun 2026
Viewed by 1252
Abstract
As micro, small and medium-sized enterprises (MSMEs) compete with limited resources, lightweight systems are needed to secure their digital assets. Fuzzy vaults (FVs) are useful for protecting secrets and, when applied to biometric systems, provide error-tolerance and privacy to enrolled biometric features. Combining [...] Read more.
As micro, small and medium-sized enterprises (MSMEs) compete with limited resources, lightweight systems are needed to secure their digital assets. Fuzzy vaults (FVs) are useful for protecting secrets and, when applied to biometric systems, provide error-tolerance and privacy to enrolled biometric features. Combining multiple biometric traits also improves performance against attacks like spoofing in multimodal (MM) authentication systems. However, the design of the FV and the biometric-fusion method applied can limit the system’s effectiveness. This study systematically evaluates recent studies on FVs and MM systems and presents an up-to-date review to identify gaps, give directions for future studies, and, ultimately, improve the design of these systems. The research targeting MSMEs was carried out in two parts, with the first search focused on MM systems and the second on FVs, following the PRISMA guidelines. The main findings include the need to optimise the resource intensity of FV systems for the authentication of large numbers of individuals. It also found the need to make the model compatible with other biometric modalities as greater focus is on minutiae features. By reviewing these systems, we aim to foster the development of lightweight MM FV models to provide privacy and security in MSMEs. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

26 pages, 6362 KB  
Article
NetGuard: A Hybrid Framework for Intelligent and Scalable Malicious URL Detection
by Saja D. Khudhur, Sama S. Samaan, Omar N. M. Taher, Aymen D. Salman and Amjad J. Humaidi
J. Cybersecur. Priv. 2026, 6(3), 102; https://doi.org/10.3390/jcp6030102 - 10 Jun 2026
Cited by 3 | Viewed by 986
Abstract
Due to the indispensable use of the internet, malicious actors have exploited URLs as a threat source of network information security and integrity. URL detection based on traditional methods has become inefficient against the uncontrolled increase of URLs, especially when facing dynamic and [...] Read more.
Due to the indispensable use of the internet, malicious actors have exploited URLs as a threat source of network information security and integrity. URL detection based on traditional methods has become inefficient against the uncontrolled increase of URLs, especially when facing dynamic and large-scale threats. To address the limitations of traditional methods and to provide intelligent and scalable detection of malicious URLs, this study proposes the hybrid framework (NetGuard) by integrating probabilistic data structures (PDSs) with machine learning (ML) capabilities. The proposed NetGuard utilizes PDSs to develop a Hybrid Scalable Detection Filter (HSDF), which combines the strengths of counting Bloom filters (CBFs) (deletion capability) and Scalable Bloom filters (SBFs). The proposed HSDF provides efficient membership queries under bounded false-positive rates (approximately 0.01) and ensures efficient data management and low-latency lookups on a scale of 10−5 s. On the other hand, NetGuard leverages the ML classifier capabilities to train and package a learned classifier for detecting malicious URLs. The proposed framework utilizes Decision Trees (DTs) and Random Forest (RF) classifiers. The proposed classifiers are trained by a novel SupURLsIdDs dataset which includes fifteen distinctive lexical and structural URL features extracted from four URL classes: benign, defacement, malware, and phishing URLs. The experimental results indicated the effectiveness of the HSDF in insertion and deletion operations, with minimal memory consumption (approximately 2.7 MB for 222,000 URLs) while maintaining a controlled false-positive rate (approximately 0.01 on Real-only subset up to 0.12 with synthetic data). The HSDF memory footprint represents a 99.88% enhancement compared to the RF model (which demands 2253.17 MB); thus, the HSDF complements RF as an ultra-lightweight first line of defense. The ML classifiers showed the superiority of RF, which achieved an overall classification accuracy of approximately 96% on large-scale URL data. These experiments are conducted using benchmark datasets constructed from aggregated real and synthetic data to demonstrate the scalability, adaptability, and resource efficiency of the first phase of NetGuard as a practical foundation for real-time web threat detection. The real-time integration and dynamic updates are presented as a deployment architecture and constitute future work. Full article
Show Figures

Figure 1

30 pages, 17485 KB  
Article
Chaotic Image Encryption by Intra-Channel Diffusion and Inter-Channel Confusion
by Javier Alberto Vargas Valencia, Carlos Alberto Marín Arango, Jairo David García, Rafael Uribe Guerra and Luis Fernando Duque Gómez
J. Cybersecur. Priv. 2026, 6(3), 101; https://doi.org/10.3390/jcp6030101 - 8 Jun 2026
Viewed by 714
Abstract
Most image encryption schemes exhibit one or more of the following limitations: keystream bias, high residual pixel correlation, pattern leakage, low sensitivity to key changes, or a security-efficiency trade-off. We present a robust image encryption framework based on a chaotic system that operates [...] Read more.
Most image encryption schemes exhibit one or more of the following limitations: keystream bias, high residual pixel correlation, pattern leakage, low sensitivity to key changes, or a security-efficiency trade-off. We present a robust image encryption framework based on a chaotic system that operates across the red, green, and blue color channels and mitigates all of the above vulnerabilities. The scheme consists of a novel integration of strong bidirectional modular diffusion, inter-channel confusion using a six-state permutation table, and Secure Hash Algorithm 256-based key derivation. Thus, we achieve the following: lossless reconstruction, near-ideal entropy, negligible adjacency correlation, high sensitivity to infinitesimal changes in both the plaintext and the secret key, a complete diffusion effect confirmed by standard differential metrics, and resilience against known- and chosen-plaintext attacks. Furthermore, the results comply with the National Institute of Standards and Technology randomness tests. These results are obtained with competitive encryption times (∼0.37 s for 512 × 512 images) without any code optimization. All of these features make the scheme promising for secure real-time visual data transmission, particularly in telemedicine and Internet of Things surveillance. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Graphical abstract

21 pages, 311 KB  
Article
Containment Invariants: Securing Intentionally Vulnerable Systems for Education, Training, and Research
by Stanislav Abaimov
J. Cybersecur. Priv. 2026, 6(3), 100; https://doi.org/10.3390/jcp6030100 - 8 Jun 2026
Viewed by 478
Abstract
The rise of capture-the-flag (CTF) competitions and offensive security training requires the deployment of systems that are, by design, flawed. This creates a unique architectural paradox: how does one host a system intended to be compromised without compromising the host itself? This paper [...] Read more.
The rise of capture-the-flag (CTF) competitions and offensive security training requires the deployment of systems that are, by design, flawed. This creates a unique architectural paradox: how does one host a system intended to be compromised without compromising the host itself? This paper classifies the security principles of “range engineering”—the discipline of engineering the environment. This research study synthesizes evidence across the cyber-range, honeypot, ICS/OT testbed, and cloud-isolation literature to derive a containment-focused classification of threat planes, security invariants, boundary mechanisms and properties, and operational controls for intentionally vulnerable environments used in education, training, and research. Five security invariants are derived under the assumption of expected compromise and mapped to boundary families and measurable operational objectives. The analysis further identifies under-evidenced areas, particularly control-plane isolation, corrective controls for cross-tenant failures, and systematic validation of externalization defenses. Full article
(This article belongs to the Section Security Engineering & Applications)
53 pages, 6100 KB  
Article
SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls
by Lalie Arnoud, Victor Breux, Pierre-Henri Thevenon and Éric Gaussier
J. Cybersecur. Priv. 2026, 6(3), 99; https://doi.org/10.3390/jcp6030099 - 6 Jun 2026
Viewed by 1515
Abstract
The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of [...] Read more.
The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings. Full article
Show Figures

Figure 1

31 pages, 1322 KB  
Article
Towards Responsible AI for IoT Network Security Auditing Using Knowledge Graph and RAGAS
by Obrina Briliyant, Amir Javed and Yulia Cherdantseva
J. Cybersecur. Priv. 2026, 6(3), 98; https://doi.org/10.3390/jcp6030098 - 6 Jun 2026
Viewed by 887
Abstract
The trustworthiness of AI-powered network security auditing depends not only on detection accuracy but on the faithfulness of the explanations that support compliance verdicts. In IoT network security, Large Language Models (LLMs) are increasingly utilized to produce natural-language security assessments from raw network [...] Read more.
The trustworthiness of AI-powered network security auditing depends not only on detection accuracy but on the faithfulness of the explanations that support compliance verdicts. In IoT network security, Large Language Models (LLMs) are increasingly utilized to produce natural-language security assessments from raw network traffic, yet the extent to which these explanations are grounded in retrieved evidence is rarely measured. This paper presents the Retrieval-Augmented Generation Assessment Suite (RAGAS) as an evaluation framework that compares three retrieval paradigms—rule-based heuristic scoring, dense vector retrieval, and knowledge graph traversal—on the task of explaining network compliance against ETSI EN 303 645 IoT cybersecurity provisions. Using 30 human expert-validated compliance scenarios derived from the CIC-IoT2023 dataset and three LLMs (DeepSeek-R1, Qwen-2.5, Llama-3.2), we find that graph-based retrieval achieves the highest faithfulness (0.570), outperforming rule-based (0.524) and vector retrieval (0.509). All methods, however, exhibit low context recall (≤22.4%), and we highlight that high detection F1 scores do not guarantee faithful explanations; over 40% of statements in compliance answers are unsupported by retrieved evidence. A proof-of-concept prototype, Security Audit Compliance Agent (SACA), demonstrates how knowledge graph traversal can be integrated with interactive visualization to support human auditor oversight. We argue that, in adherence to responsible AI principles, faithfulness measurement should become a standard complement to accuracy reporting for an AI-driven network audit or forensic analysis. Full article
Show Figures

Figure 1

12 pages, 1608 KB  
Article
Deep Neural Network Architectures for Fake News and Misinformation Detection
by Mariam Ibrahim and Ruba Elhafiz
J. Cybersecur. Priv. 2026, 6(3), 97; https://doi.org/10.3390/jcp6030097 - 5 Jun 2026
Viewed by 576
Abstract
The prompt spread of misleading information through recent information and communication technologies (ICT) admonishes social convention and credence. Developing trustworthy algorithms that can automatically identify fake content becomes increasingly difficult. We investigate a hybrid artificial intelligence (AI) strategy that integrates machine learning (ML) [...] Read more.
The prompt spread of misleading information through recent information and communication technologies (ICT) admonishes social convention and credence. Developing trustworthy algorithms that can automatically identify fake content becomes increasingly difficult. We investigate a hybrid artificial intelligence (AI) strategy that integrates machine learning (ML) and deep learning (DL) to enhance fake news detection. The model’s deep learning entity evaluates confined text arrangements and inclusive text values using a Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) with an attention layer. Conventional machine learning classifiers, mostly Support Vector Machine (SVM), Random Forest (RF), and Logistic Regression (LR), are trained synchronously employing Term Frequency–Inverse Document Frequency (TF-IDF). A simple ensemble averaging strategy is used on both machine learning and deep learning predictions. The model demonstrates strong generalization across various text types when evaluated on the LIAR dataset and a Kaggle-style fake news dataset. The combined system performs noticeably better than each of the separate models in terms of accuracy, precision, recall, F1, and AUC. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

33 pages, 2680 KB  
Article
Enhancing Data Privacy in Large Language Models Through Private Association Editing
by Davide Venditti, Elena Sofia Ruzzetti, Giancarlo A. Xompero, Cristina Giannone, Andrea Favalli, Raniero Romagnoli and Fabio Massimo Zanzotto
J. Cybersecur. Priv. 2026, 6(3), 96; https://doi.org/10.3390/jcp6030096 - 1 Jun 2026
Viewed by 611
Abstract
Large language models (LLMs) require a significant redesign in solutions to preserve privacy in data-intensive applications due to their text-generation capabilities. Indeed, LLMs tend to memorize and emit private information when maliciously prompted. In this paper, we introduce Private Association Editing (PAE) as [...] Read more.
Large language models (LLMs) require a significant redesign in solutions to preserve privacy in data-intensive applications due to their text-generation capabilities. Indeed, LLMs tend to memorize and emit private information when maliciously prompted. In this paper, we introduce Private Association Editing (PAE) as a novel defense approach for private data leakage. PAE is designed to effectively remove Personally Identifiable Information (PII) without retraining the model. We experimented on three open-weight, open-data models—GPT-Neo 1.3B, GPT-Neo 2.7B, and GPT-J—by applying Training Data Extraction (TDE) attacks to retrieve hundreds of PII, including email addresses, phone numbers, and Twitter handles. Since these models were trained on Pile, an openly available pre-training dataset, it is possible to verify the true extent of the data leakage. While all three models tend to leak PII under TDE attacks, experimental results demonstrate the effectiveness of PAE with respect to alternative baseline methods in defending against those attacks. In fact, unlike other techniques that tend to degrade model performance, our experiments show that PAE consistently reduces the number of leakages without affecting the model’s utility. We believe PAE will serve as a practical tool for removing memorized PII from deployed LLMs without retraining. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

29 pages, 10292 KB  
Article
Spectral & Memory Trade-Offs in Multiplexed Fourier Domain Chaotic Image Encryption
by Javier Alberto Vargas Valencia, Luis Fernando Duque Gómez, Carlos Alberto Marín Arango, Mauricio A. Londoño-Arboleda and Hernán David Salinas Jiménez
J. Cybersecur. Priv. 2026, 6(3), 95; https://doi.org/10.3390/jcp6030095 - 29 May 2026
Viewed by 680
Abstract
This work presents a Fourier-domain encryption scheme for multiplexed image databases that integrates virtual-optical multiplexing with chaotic diffusion. By combining chaotic encryption with spectral-domain symmetry reduction, the proposed approach secures large multiplexed image datasets while reducing memory requirements and preserving reconstruction fidelity. A [...] Read more.
This work presents a Fourier-domain encryption scheme for multiplexed image databases that integrates virtual-optical multiplexing with chaotic diffusion. By combining chaotic encryption with spectral-domain symmetry reduction, the proposed approach secures large multiplexed image datasets while reducing memory requirements and preserving reconstruction fidelity. A dataset of 2025 grayscale images (512×512 pixels) is multiplexed and encrypted using linear chaotic transformations applied separately to the amplitude (A) and phase (ϕ) components. To improve storage efficiency, the symmetry conditions of both spectral components are exploited, allowing a reduced portion of the Fourier plane to be stored while preserving accurate reconstruction. A performance landscape relating the correlation coefficient (CC), memory consumption, and the retained Fourier-plane percentage (FPP) is constructed to identify stable operating regions that balance reconstruction fidelity and compression under increasing multiplexing load. The encryption key consists of a 22-symbol ASCII string from which 84 seed parameters for a deterministic pseudorandom chaotic map are derived. Security and sensitivity analyses demonstrate strong key dependence and resistance to statistical attacks, while maintaining high reconstruction fidelity. The proposed scheme provides an efficient and scalable solution for secure large-scale image repositories. Full article
(This article belongs to the Special Issue Applied Cryptography)
Show Figures

Graphical abstract

34 pages, 4531 KB  
Article
A Multi-Group Usability Evaluation of a Human-Centred Privacy and Permission Management Framework (MIDA)
by Nourah Alshomrani, Steven Furnell, Helena Webb and Alejandro Guerra-Manzanares
J. Cybersecur. Priv. 2026, 6(3), 94; https://doi.org/10.3390/jcp6030094 - 22 May 2026
Viewed by 924
Abstract
Users encounter privacy and permission settings across digital platforms, yet often struggle to understand, locate, and manage them effectively. Despite regulatory efforts such as the General Data Protection Regulation (GDPR) and platform mechanisms like App Tracking Transparency, these challenges persist due to interface [...] Read more.
Users encounter privacy and permission settings across digital platforms, yet often struggle to understand, locate, and manage them effectively. Despite regulatory efforts such as the General Data Protection Regulation (GDPR) and platform mechanisms like App Tracking Transparency, these challenges persist due to interface design limitations rather than solely user capability. This study evaluates the My Information and Data Access (MIDA) framework, a user-centred privacy interface designed to support users with different levels of expertise. A between-subjects usability study was conducted with 44 participants (novice n = 15, intermediate n = 14, advanced n = 15), combining System Usability Scale (SUS) scores, task completion rates, error rates, and think-aloud protocols. The results show high usability across all groups, with SUS scores of 80 (novice), 84 (intermediate), and 92 (advanced), all exceeding the acceptability threshold of 68. Task completion rates exceeded 80%, whilst error rates remained below 25% across most tasks. These findings indicate that MIDA can support users in understanding, configuring, and managing privacy settings across different levels of expertise. This study builds on prior HCI research linking privacy management challenges to interface design limitations and provides empirical evidence that an expertise-adaptive interface can improve users’ ability to understand and manage privacy settings. Full article
(This article belongs to the Special Issue Current Trends in Data Security and Privacy—2nd Edition)
Show Figures

Figure 1

56 pages, 596 KB  
Systematic Review
Systematic Artefact-Based Review of Government Digital Identity Programmes: Alignment, Maturity and Transparency
by Matthew Comb and Andrew Martin
J. Cybersecur. Priv. 2026, 6(3), 93; https://doi.org/10.3390/jcp6030093 - 21 May 2026
Viewed by 768
Abstract
Digital identity is increasingly treated as foundational infrastructure for digital economies and public services, yet national approaches remain fragmented and difficult to compare. This study presents a PRISMA-guided systematic artefact-based review of government digital identity programmes, using programme-relevant government artefacts as the review [...] Read more.
Digital identity is increasingly treated as foundational infrastructure for digital economies and public services, yet national approaches remain fragmented and difficult to compare. This study presents a PRISMA-guided systematic artefact-based review of government digital identity programmes, using programme-relevant government artefacts as the review corpus, including strategies, trust frameworks, guidance, service documentation, and identity-enabled public-service materials. Adapting an NLP pipeline for large-scale digital identity text analysis, the study identifies recurring themes, constructs comparative programme profiles, and operationalises three artefact-based measures: alignment, transparency, and maturity. Rather than assessing innovation performance or operational system quality directly, it examines the documentary layer through which programmes are described, justified, and made comparable. The analysis reveals substantial variation in how highly digitalised societies articulate governance, trust, interoperability, security, privacy, and service delivery. The review contributes a repeatable artefact-based framework for cross-jurisdictional comparison and provides a baseline for ontology development and future triangulation against citizen perception, expert assessment, and technical evaluation. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

18 pages, 19243 KB  
Article
Design and Implementation of a Microgrid Testbed for Cybersecurity Analysis and Resilience Testing
by Joseph Mikkelson, Dominic G. De La Cerda, Yanwei Wu and Xiaoguang Ma
J. Cybersecur. Priv. 2026, 6(3), 92; https://doi.org/10.3390/jcp6030092 - 20 May 2026
Viewed by 879
Abstract
A microgrid is a localized distribution network composed of electricity users who have access to local renewable and other energy sources. While the utility grid plays a critical role in the nation’s economy, security, and the well-being of its residents, connecting microgrids to [...] Read more.
A microgrid is a localized distribution network composed of electricity users who have access to local renewable and other energy sources. While the utility grid plays a critical role in the nation’s economy, security, and the well-being of its residents, connecting microgrids to the wider network via utility substations can introduce significant cybersecurity risks. Unlike most existing studies that rely on simulation, this research designs and implements a physical microgrid testbed to examine cybersecurity vulnerabilities in microgrid systems. We examine the impact of various cyberattacks—including denial of service (DoS) and communication hijacking—on microgrid operations, with a particular focus on system stability and communication networks. The findings reveal critical weaknesses within the existing communication infrastructure, providing valuable insights for designing more resilient and secure microgrids. This work offers a practical framework for addressing cybersecurity challenges in real-world industrial utility networks. Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity)
Show Figures

Figure 1

29 pages, 5329 KB  
Systematic Review
Connecting the Dots: A Systematic Literature Review of Explainable AI, Cybersecurity, Human-Centered Design and Edge Computing
by Gaia Cecchi, Fabrizio Benelli, Mario Caronna, Giulia Palma and Antonio Rizzo
J. Cybersecur. Priv. 2026, 6(3), 91; https://doi.org/10.3390/jcp6030091 - 19 May 2026
Viewed by 1266
Abstract
The incorporation of Artificial Intelligence (AI) into cybersecurity has become widespread, largely propelled by the emergence of Generative AI (GenAI) and Large Language Models (LLMs). While these technologies promise to revolutionize threat detection, they introduce profound challenges regarding explainability, trust, and deployment feasibility [...] Read more.
The incorporation of Artificial Intelligence (AI) into cybersecurity has become widespread, largely propelled by the emergence of Generative AI (GenAI) and Large Language Models (LLMs). While these technologies promise to revolutionize threat detection, they introduce profound challenges regarding explainability, trust, and deployment feasibility in resource-constrained environments. Current research often exhibits a form of technological determinism, prioritizing algorithmic performance over the operational realities of Security Operations Centers (SOCs). This paper presents a hybrid qualitative Systematic Literature Review (SLR) and Mapping Study, adhering to the Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) 2020 guidelines. Our research questions are narrowly focused, seeking to explore how four key domains intersect: (1) Explainable AI (XAI) methods; (2) cybersecurity operations; (3) human-centered design; and (4) the constraints inherent to edge computing. From an initial corpus of 385 records drawn from Scopus and OpenAlex (spanning a search window from 2014 to 2025, with relevant findings heavily clustered in the 2020–2025 period), included studies were evaluated using a quality assessment protocol adapted from Kitchenham’s guidelines, scoring each study on a 0–24 scale across four dimensions (Venue Quality, Methodological Rigor, Dataset Realism, and Depth of XAI/Human Validation). The results reveal a significant “validation gap”: while 63% of studies claim human-centric relevance, only ~22% incorporate empirical validation with human operators. Furthermore, we identify a critical trade-off between the reasoning power of cloud-based LLMs and the privacy requirements of Edge security. We conclude by proposing a research agenda for “Cognitive SOCs”, emphasizing the need for Small Language Models (SLMs), standardized human-centric metrics, and robust hallucination detection mechanisms. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

37 pages, 10145 KB  
Article
Feature-Engineered Trojan Malware Detection on Windows-Based IoT Gateways Using a Custom Deep Neural Network and Automated Monitoring Pipeline
by Mazdak Maghanaki, Mohammad Shahin, Soraya Keramati, F. Frank Chen and Enrique Contreras
J. Cybersecur. Priv. 2026, 6(3), 90; https://doi.org/10.3390/jcp6030090 - 19 May 2026
Cited by 5 | Viewed by 1541
Abstract
The growth of Internet of Things (IoT) environments has expanded the attack surface of modern systems. Trojan attacks are a major challenge as they evade conventional detection mechanisms and operate silently within legitimate processes. This paper presents an automated Trojan detection framework for [...] Read more.
The growth of Internet of Things (IoT) environments has expanded the attack surface of modern systems. Trojan attacks are a major challenge as they evade conventional detection mechanisms and operate silently within legitimate processes. This paper presents an automated Trojan detection framework for Windows-based IoT gateways. The framework combines custom dataset generation informative feature engineering and deep learning-driven analysis. A dataset of 3000 real world executable samples was created through controlled sandbox execution and forensic monitoring. The process captured behavioral static and network-level characteristics. An initial set contained 146 extracted features. A multi-stage feature selection process identified 33 informative attributes. This step allowed efficient learning and preserved discriminative power. A custom deep neural network model named TrDNN was developed using these features. The model captures complex nonlinear patterns linked to Trojan activity. The framework was evaluated against five classical machine learning models. It was also compared with five deep learning baselines. Results show that TrDNN achieves strong detection performance. The accuracy is 0.975. The precision is 0.972. The recall is 0.969. The F1 score is 0.970. The study also examines inference time and energy consumption. The model shows a balance between detection effectiveness, computational cost and energy efficiency. This makes it suitable for resource-constrained IoT gateway deployment. The detection model was integrated into an automated real-time monitoring pipeline. The system enables continuous process surveillance through Windows command line automation with minimal operational overhead. Statistical validation used paired t tests, Wilcoxon signed rank tests and McNemar chi-square test. The performance gains are statistically significant and do not indicate overfitting. The framework provides a reliable, efficient and deployable solution for Trojan detection in modern IoT systems. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

37 pages, 1721 KB  
Article
Recovering Error-Free Cryptographic Keys from Noisy Quantum Key Distribution and Independent Eavesdropper Detection on the Receiving End
by Dina Ghanai Miandoab, Brit Riggs, Nicholas Paul Navas and Bertrand Cambou
J. Cybersecur. Priv. 2026, 6(3), 89; https://doi.org/10.3390/jcp6030089 - 14 May 2026
Viewed by 1227
Abstract
This work considers the performance and feasibility of a challenge-response pair (CRP)-based key generation method integrated with multi-wavelength Quantum Key Distribution (QKD). In this design, Alice and Bob use independently derived information from the CRP mechanism to encode and recover the key without [...] Read more.
This work considers the performance and feasibility of a challenge-response pair (CRP)-based key generation method integrated with multi-wavelength Quantum Key Distribution (QKD). In this design, Alice and Bob use independently derived information from the CRP mechanism to encode and recover the key without disclosing helper data. Simulations show that even when up to 40% of the data is corrupted, error-free key recovery is possible with longer response lengths. Another new advantage of this method is that eavesdropper detection is performed using only the statistics of the received quantum stream, as opposed to sacrificing a portion of the key for public comparison, as is required in other QKD schemes. The CRP mechanism and encoding scheme are explained, and the results of key recovery and error detection across various levels of data corruption are presented. The results show that according to the studied conditions, reliable key recovery and eavesdropper detection are possible without publicly comparing the key or using helper data, and it suggests that this approach can reduce classical reconciliation reliance and allow for reliable key recovery in noisy settings without extending security thresholds. Full article
Show Figures

Figure 1

43 pages, 752 KB  
Article
Recursive Augmented Fernet (RAF) Token: Alleviating the Pain of Stolen Tokens
by Reza Rahaeimehr and Marten van Dijk
J. Cybersecur. Priv. 2026, 6(3), 88; https://doi.org/10.3390/jcp6030088 - 13 May 2026
Cited by 1 | Viewed by 489
Abstract
A robust authentication and authorization mechanism is imperative in modular system development, where modularity and modular thinking are pivotal. Traditional systems often employ identity modules responsible for authentication and token issuance. Tokens, representing user credentials, offer advantages such as reduced reliance on passwords, [...] Read more.
A robust authentication and authorization mechanism is imperative in modular system development, where modularity and modular thinking are pivotal. Traditional systems often employ identity modules responsible for authentication and token issuance. Tokens, representing user credentials, offer advantages such as reduced reliance on passwords, limited lifespan, and scoped access. Despite these benefits, the “bearer token” problem persists, leaving systems vulnerable to abuse if tokens are compromised. We propose a token-based authentication mechanism addressing the critical bearer token problem in modular systems. The proposed mechanism includes a novel RAF (Recursive Augmented Fernet) token, a blacklist component, and a policy enforcer component. RAF tokens are one-time-use tokens, like tickets. They carry commands, and the receiver of an RAF token can issue new tokens using the received RAF token. The blacklist component guarantees an RAF token cannot be validated more than once, and the policy enforcer checks the compatibility of commands carried by an RAF token. We introduce two variations of RAF tokens: user-tied RAF, offering simplicity and compatibility, and fully-tied RAF, providing enhanced security through service-specific secret keys. We thoroughly discuss the security guarantees, technical definitions, and construction of RAF tokens backed by game-based proofs. We demonstrate a proof of concept in the context of OpenStack, involving modifications to Keystone and the creation of an RAFT library. The experimental results reveal minimal overhead in typical scenarios, establishing the practicality and effectiveness of RAF. Our experiments show that the RAF mechanism outperforms the use of short-life Fernet tokens while providing much better security. Full article
(This article belongs to the Special Issue Applied Cryptography)
Show Figures

Figure 1

36 pages, 814 KB  
Article
Phase-First Gaussian Modulation for Resilient Continuous-Variable Quantum Communication Under Adversarial Disturbances
by José R. Rosas-Bustos, Jesse Van Griensven Thé, Roydon Andrew Fraser, Nadeem Said, Sebastian Ratto Valderrama, Mark Pecen, Alexander Truskovsky and Andy Thanos
J. Cybersecur. Priv. 2026, 6(3), 87; https://doi.org/10.3390/jcp6030087 - 13 May 2026
Viewed by 721
Abstract
Continuous-variable quantum communication (CVQC) operates under finite-resolution inference (finite data windows, calibration uncertainty, and estimator tolerances) and hardware control/readout limits that can be exploited by structured and adversarial disturbances. We study a feedback-inspired phase-space modulation strategy for implementation-layer resilience under DoS-like receiver-observable stress [...] Read more.
Continuous-variable quantum communication (CVQC) operates under finite-resolution inference (finite data windows, calibration uncertainty, and estimator tolerances) and hardware control/readout limits that can be exploited by structured and adversarial disturbances. We study a feedback-inspired phase-space modulation strategy for implementation-layer resilience under DoS-like receiver-observable stress (e.g., fluctuation inflation, phase reference destabilization, or interface non-idealities), rather than proposing a protocol-level security proof. We propose a phase-first framework in which the defender selects a phase-space rotation angle θ (and, in principle, a squeezing parameter r) to minimize a receiver-observable centered second-moment degradation proxy, emphasizing containment rather than disturbance inversion. Because platforms expose different native observables, we evaluate phase-first modulation using two complementary tracks: (i) in theory/simulation, we monitor basis-dependent quadrature variance and covariance-derived summaries formed from mean-subtracted second moments so that ΔEcov reflects covariance inflation rather than coherent displacement; (ii) in the X8_01 hardware workflow, the readout is Fock sampling; thus, we use the shot-to-shot standard deviation σN(θ):=Var^(N(θ)), where N(θ) denotes the shot-level detected count random variable at fixed θ. In the reported hardware workflow, this shot-level count is formed by aggregating the returned Fock counts prior to postprocessing. We emphasize that σN(θ) is not claimed to estimate Tr(V); it is an implementation-layer variability proxy aligned with the available readout. Our experimental validation is restricted to phase-only control instantiated as offline phase selection via one-dimensional grid search over θ. Across numerical simulations and hardware phase-angle scans on Xanadu’s X8_01 photonic quantum processor, we find that static operating points can be brittle under strong DoS-like stress, whereas optimized phase selection can materially reduce a receiver-observed degradation proxy even without real-time feedback. Since Tr(V) is invariant under pure rotations for phase-independent additive noise and ideal photon-number probabilities are invariant under a terminal Fock-basis phase gate, any observed θ-dependence is interpreted operationally as evidence of a phase-dependent effective disturbance/measurement channel at the receiver interface. Simulation-only analyses indicate additional upside when squeezing is available, motivating future extensions incorporating higher-rate re-optimization, feedback-assisted architectures, and extended Gaussian control when available. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

32 pages, 2513 KB  
Article
CryptoKANs+: KAN-Inspired Self-Learning Polynomial Networks for Efficient Privacy-Preserving Machine Learning
by Omar Tahmi, Chamseddine Talhi and Hakima Ould-Slimane
J. Cybersecur. Priv. 2026, 6(3), 86; https://doi.org/10.3390/jcp6030086 - 6 May 2026
Viewed by 884
Abstract
Processing sensitive data in cloud-based neural networks raises privacy concerns, which Homomorphic Encryption addresses by enabling privacy-preserving machine learning. In our previous work, we introduced CryptoKANs, enabling efficient Kolmogorov–Arnold Network (KAN) inference over encrypted data via polynomial approximation of spline-based activation functions using [...] Read more.
Processing sensitive data in cloud-based neural networks raises privacy concerns, which Homomorphic Encryption addresses by enabling privacy-preserving machine learning. In our previous work, we introduced CryptoKANs, enabling efficient Kolmogorov–Arnold Network (KAN) inference over encrypted data via polynomial approximation of spline-based activation functions using KAN symbolization. To avoid performance degradation, CryptoKAN required min–max scaling of pre-activation inputs to a small interval—a requirement that could negatively affect training. In addition, a direct theoretical structural comparison with Multi-Layer Perceptron (MLP)-based solutions, such as CryptoNets, was missing. In this work, we address these limitations by presenting CryptoKAN+, a KAN-inspired network integrating self-learned polynomial activations through a Fully Connected Quadratic Transformation (FCQT) layer. By enforcing polynomial activations during training, this design replaces spline functions without post-training symbolization, eliminates the need for interval scaling, absorbs subsequent linear transformations, and reduces multiplicative depth for efficient encrypted inference. Experiments show that CryptoKAN+ achieves competitive accuracy while slightly improving encrypted inference efficiency—a natural consequence of compacting weights with self-learned activations. Overall, this work provides a formal analysis of the structural relationship between KANs and MLPs and demonstrates how enforcing polynomial activations during training enables efficient encrypted inference while preserving accuracy. Full article
Show Figures

Figure 1

32 pages, 2557 KB  
Article
A Hybrid Blockchain-Based Framework for Adaptive Cyber-Risk Prediction and Multi-Layer Threat Mitigation in Enterprise Networks
by Udit Mamodiya, Indra Kishor, Rahat Naz, Mohammed Almaiah and Amer Alqutaish
J. Cybersecur. Priv. 2026, 6(3), 85; https://doi.org/10.3390/jcp6030085 - 6 May 2026
Cited by 1 | Viewed by 1434
Abstract
The environment of cybersecurity is changing at a higher rate than most automated defensive systems can keep pace with, and most enterprise-level solutions are based on a fixed set of rules or a black box with machine learning results. This leads to a [...] Read more.
The environment of cybersecurity is changing at a higher rate than most automated defensive systems can keep pace with, and most enterprise-level solutions are based on a fixed set of rules or a black box with machine learning results. This leads to a loophole between identifying and controlling responses, particularly where the mitigation should demand accountability, proportionality, and justifiable reliability. Current AI–blockchain models enhance logging and detection and are seldom used to enforce adaptive, understandable, or risk-weighted response automation. It presents AGML, a hybrid governance-based defense framework that integrates blockchain mitigation execution with reinforcement-tuned prediction of cyber-risks. The system scores the risk continuously, mitigates severity depending on the situation, and recalculates behavior via a closed feedback mechanism. The blockchain layer is an enforcement boundary and not a passive ledger as all activities are auditable and not tamperable. The results of the evaluation show that there is a quantifiable increase in comparison with recent baselines: 96.48% detection accuracy, 95.22% precision, 94.65% recall, and a false-positive rate of 2.81. The average response latency was 312 ms and around 26 ms was due to governance validation. The system was also found to be stable in repeated adversarial cycles and exhibited stable convergence as opposed to drifting. These findings indicate that responsible and responsive automation, not rapid but uninhibited automation, could provide a more feasible solution to the resilient enterprise cybersecurity. Full article
(This article belongs to the Special Issue Blockchain for Cybersecurity and Cyber-Risk Management)
Show Figures

Figure 1

40 pages, 551 KB  
Article
Model Context Protocol Threat Modeling and Analysis of Vulnerabilities to Prompt Injection with Tool Poisoning
by Charoes Huang, Xin Huang, Ngoc Phu Tran and Amin Milani Fard
J. Cybersecur. Priv. 2026, 6(3), 84; https://doi.org/10.3390/jcp6030084 - 5 May 2026
Cited by 2 | Viewed by 4529
Abstract
The Model Context Protocol (MCP) has rapidly emerged as a universal standard for connecting AI assistants to external tools and data sources. While the MCP simplifies integration between AI applications and various services, it introduces significant security vulnerabilities, particularly on the client side. [...] Read more.
The Model Context Protocol (MCP) has rapidly emerged as a universal standard for connecting AI assistants to external tools and data sources. While the MCP simplifies integration between AI applications and various services, it introduces significant security vulnerabilities, particularly on the client side. In this work, we conduct threat modelings of MCP implementations using STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and DREAD (Damage, Reproducibility, Exploitability, Affected Users, Discoverability) frameworks across six key components: MCP host, MCP client, LLM, MCP server, external data stores, and authorization server. This comprehensive analysis reveals tool poisoning—where malicious instructions are embedded in tool metadata—as the most prevalent and impactful client-side vulnerability. We therefore focus our empirical evaluation on this critical attack vector, providing a systematic comparison of how seven major MCP clients validate and defend against tool poisoning attacks. Our analysis reveals significant security issues with most tested clients due to insufficient static validation and parameter visibility. We propose a multi-layered defense strategy encompassing static metadata analysis, model decision path tracking, behavioral anomaly detection, and user transparency mechanisms. This research addresses a critical gap in MCP security, which has primarily focused on server-side vulnerabilities, and provides actionable recommendations and mitigation strategies for securing AI agent ecosystems. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

24 pages, 2875 KB  
Article
LDSEGoV: An Efficient Lightweight Digital-Signature Algorithm Based on CDLP and Provable Security for E-Governance Authentication
by Seema Sirpal, Pardeep Singh and Om Pal
J. Cybersecur. Priv. 2026, 6(3), 83; https://doi.org/10.3390/jcp6030083 - 5 May 2026
Viewed by 625
Abstract
Digital signatures serve as a crucial cryptographic primitive in an e-governance system for authenticating citizen-government interactions. Traditional methods (DSA, ECDSA) impose computational overhead on resource-limited endpoints and centralized verification servers. While complex-number cryptography provides theoretical efficiency through the Complex Discrete-Logarithm Problem (CDLP), prior [...] Read more.
Digital signatures serve as a crucial cryptographic primitive in an e-governance system for authenticating citizen-government interactions. Traditional methods (DSA, ECDSA) impose computational overhead on resource-limited endpoints and centralized verification servers. While complex-number cryptography provides theoretical efficiency through the Complex Discrete-Logarithm Problem (CDLP), prior works often fail to meet the requirements for real-world applications. This paper advances the knowledge in lightweight cryptography by introducing LDSEGoV, a lightweight digital signature scheme for e-governance infrastructure. The proposed method overcomes the shortcomings of previous methods by incorporating sound modular arithmetic for consistent verification, using NIST-approved hash functions. Furthermore, we provide a comprehensive security analysis, including formal proofs of existential unforgeability (EUF-CMA) for the proposed scheme in the Random Oracle Model. Additionally, the experimental results show a 6.5× improvement in signing performance and a 24.76× improvement in verification performance over ECDSA, with a 61% reduction in signature size. These results demonstrate computational efficiency suitable for e-governance authentication scenarios. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

20 pages, 3072 KB  
Article
Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study
by Rajkumar Banoth, Santosh Reddy Addula, Aruna Kranthi Godishala, Rithwik Sannapu, Guna Sekhar Sajja, Deepak Kumar, Vinay Kumar Kasula and Chaitanya Tumma
J. Cybersecur. Priv. 2026, 6(3), 82; https://doi.org/10.3390/jcp6030082 - 2 May 2026
Viewed by 1382
Abstract
The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated [...] Read more.
The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated protocol analyses, or hard-to-replicate setups. This paper addresses that gap with two main contributions: a structured review of ten influential IoT security studies from the USENIX Security Symposium and a confirmatory empirical experiment deploying Cowrie and IoTPOT honeypots simultaneously on a Microsoft Azure cloud-based virtual machine. Unlike earlier studies that focus on single protocols or large-scale environments, this work acts as a validation study, confirming well-known IoT botnet behaviors, including credential brute-force attacks, Mirai-style commands, and Telnet dominance, using real-time attack data collected from a reproducible, affordable cloud environment that simulates known IoT vulnerabilities (such as CVE-2016-10401, CVE-2017-17215, and CVE-2014-9222). Rather than revealing new attack methods, this study explicitly verifies the persistence of behaviors first documented almost ten years ago. The data indicates that attackers continue to exploit basic authentication flaws and reuse long-standing command sequences, confirming that core IoT vulnerabilities remain prevalent despite a decade of security research. It also highlights the ongoing gap between research progress and industry implementation. The analysis situates these findings within the broader evolution of IoT botnets, from early centralized command-and-control structures like Mirai to more resilient peer-to-peer networks that use anonymized channels and target high-wattage devices for power-grid manipulation. This study shows that small, cloud-based honeypots are valuable for continuous threat monitoring, model validation, and security assessments, providing a practical, reproducible approach for ongoing IoT security research. Full article
Show Figures

Figure 1

29 pages, 1237 KB  
Article
A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems
by Gizem Erceylan, Doney Abraham, Aida Akbarzadeh, Vasileios Gkioulos and Sandeep Pirbhulal
J. Cybersecur. Priv. 2026, 6(3), 81; https://doi.org/10.3390/jcp6030081 - 1 May 2026
Viewed by 1612
Abstract
Industrial Control Systems (ICSs), which are essential components of critical infrastructures, are inherently complex and vulnerable to cyberattacks. Advanced Persistent Threats (APTs) that target these systems are multi-stage, coordinated attacks that can lead not only to information loss but also to physical damage [...] Read more.
Industrial Control Systems (ICSs), which are essential components of critical infrastructures, are inherently complex and vulnerable to cyberattacks. Advanced Persistent Threats (APTs) that target these systems are multi-stage, coordinated attacks that can lead not only to information loss but also to physical damage and loss of life. Traditional threat modeling approaches fall short in adapting to the dynamic nature of ICSs, necessitating new methodologies to predict and prevent such complex attacks. This work presents a digital twin-assisted dynamic threat modeling framework for ICS environments. The framework leverages a knowledge graph that integrates system data and cyber threat intelligence to predict potential attacks. In addition, the digital twin environment enables the validation of mitigation strategies before deployment in the physical system, while also supporting adaptive response and real-time mitigation. To predict the attacker’s next move, we propose a Relational Graph Convolutional Network (RGCN)-based model that utilizes enriched relational data such as tactics, campaigns, groups, techniques, and assets. The proposed RGCN model achieves a recall of 0.887, an F1-score of 0.893, and an AUC of 0.957 in predicting potential attack sequences. These results demonstrate that the model provides reliable and well-balanced predictive performance. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

20 pages, 462 KB  
Article
The Evaluation of a Double-Spend Attack Probability for Ouroboros-like Proof-of-Stake Consensus
by Lyudmila Kovalchuk, Mariia Rodinko, Roman Oliynykov and Volodymyr Artemchuk
J. Cybersecur. Priv. 2026, 6(3), 80; https://doi.org/10.3390/jcp6030080 - 1 May 2026
Viewed by 1049
Abstract
This paper studies the probability of a double-spend attack in an Ouroboros-like Proof-of-Stake (PoS) setting when confirmation decisions must be made for a finite number of blocks. Existing security analyses of Ouroboros-family protocols are mainly asymptotic and therefore do not directly provide the [...] Read more.
This paper studies the probability of a double-spend attack in an Ouroboros-like Proof-of-Stake (PoS) setting when confirmation decisions must be made for a finite number of blocks. Existing security analyses of Ouroboros-family protocols are mainly asymptotic and therefore do not directly provide the attack probability for a fixed confirmation depth. We consider an analytically tractable model that allows empty slots and multiple slot leaders, and assumes fixed stake distribution within an epoch, one-block growth of the public longest chain in any slot containing at least one honest leader, and next-slot block visibility. These assumptions hold when the time slot length is much greater than the network delay, and are applicable to practical deployment scenarios such as Cardano. Under these assumptions, for the first time, an exact closed-form solution for the success probability of a double-spend attack considering a realistic model with multiple leaders and empty time slots. Numerical examples illustrate how the required confirmation depth depends on the adversarial stake ratio and the active slot coefficient. The results apply to the stated analytical model and do not yet cover delayed fork resolution or the full protocol-level fork-choice and finality mechanisms of Ouroboros Praos. Full article
(This article belongs to the Special Issue Blockchain for Cybersecurity and Cyber-Risk Management)
Show Figures

Figure 1

23 pages, 924 KB  
Article
Vertical Federated XGBoost with Privacy Preservation via Secure Multiparty Computation
by Asma Ramay, Estrid He, Mengmeng Yang, Tabinda Sarwar, Xinqian Wang and Xun Yi
J. Cybersecur. Priv. 2026, 6(3), 79; https://doi.org/10.3390/jcp6030079 - 1 May 2026
Viewed by 940
Abstract
Gradient Boosted Decision Trees (GBDTs) are popular for their strong predictive performance. However, in domains like finance and healthcare, data are often distributed across organizations, making collaborative model training challenging due to privacy concerns. Vertical federated learning (VFL) enables such collaboration when data [...] Read more.
Gradient Boosted Decision Trees (GBDTs) are popular for their strong predictive performance. However, in domains like finance and healthcare, data are often distributed across organizations, making collaborative model training challenging due to privacy concerns. Vertical federated learning (VFL) enables such collaboration when data are split by features, but many existing methods focus on protecting raw data while exposing sensitive model information, such as gradients and Hessians—especially to the label-owning party. Techniques like Homomorphic Encryption and Secret Sharing help, but often rely on trusted or privileged parties and may still leak intermediate statistics. To address this, we propose MPC-XGB, a privacy-preserving framework for training XGBoost under VFL with an honest-but-curious threat model. It uses secure three-party computation with Replicated Secret Sharing, distributing data across non-colluding servers and performing all computations on shares. This ensures that raw data, labels, and model statistics remain hidden, while supporting both secure training and prediction. Experiments show that MPC-XGB achieves strong performance (0.93 accuracy, 0.82 AUC), comparable to that of existing methods, with improved privacy guarantees. Full article
(This article belongs to the Section Privacy)
Show Figures

Figure 1

24 pages, 596 KB  
Article
Empirical Evaluation of Android Browser Forensics and Artifact Persistence
by Paraskevas Giannakopoulos, Christos Smiliotopoulos and Georgios Kambourakis
J. Cybersecur. Priv. 2026, 6(3), 78; https://doi.org/10.3390/jcp6030078 - 1 May 2026
Viewed by 2292
Abstract
The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from [...] Read more.
The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from popular mobile browsers (Chrome, Firefox, Tor, DuckDuckGo, and Brave) on authentic Android 13 devices. By utilizing a rooted environment to bypass application sandboxing, we introduce a standardized scoring framework to quantify and compare the residual digital footprints left across diverse usage scenarios, including standard browsing, manual data deletion, and private/incognito modes. The study details a hybrid acquisition methodology that integrates persistent storage analysis with custom volatile memory extraction routines to capture ephemeral process data. Through a suite of controlled, realistic scenarios—encompassing form filling, virtual transactions, and anti-forensic activities—the results demonstrate that significant portions of user activity remained recoverable within the tested and evaluated experimental environment and browser configurations despite aggressive privacy-enhancing measures. Our findings reveal that while private modes effectively minimize the persistent filesystem footprint, volatile memory remains a fertile source of cleartext credentials and session identifiers. This recovery is particularly pronounced in Chromium-based browsers, whereas privacy-centric alternatives like Tor exhibit higher forensic resilience. Ultimately, this research underscores the importance of volatile memory acquisition in mobile investigations and provides an experimental systematic approach for evaluating the trade-offs between browser usability and forensic traceability in contemporary Android environments, demonstrating potential applicability to subsequent Android iterations. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

40 pages, 892 KB  
Article
IoT-Oriented Digital Signature Defense Against Single-Trace Belief Propagation Attacks in Post-Quantum Cryptography
by Maksim Iavich and Nursulu Kapalova
J. Cybersecur. Priv. 2026, 6(3), 77; https://doi.org/10.3390/jcp6030077 - 27 Apr 2026
Viewed by 1869
Abstract
Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital [...] Read more.
Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital signatures using only a single side-channel trace of the Number Theoretic Transform (NTT). This work introduces the Quantum-Randomized Number Theoretic Transform (QR-NTT), an implementation-level defense mechanism that integrates quantum-derived entropy directly into the execution flow of lattice-based signature algorithms. Rather than treating randomness as a static input, QR-NTT uses quantum entropy to introduce controlled variability in execution ordering, arithmetic factor usage, and memory access behavior while preserving mathematical correctness and constant-time execution. The proposed framework is designed for embedded platforms and remains compatible with existing post-quantum cryptographic standards and IoT communication protocols. A complete implementation on an ARM Cortex-M4 platform, coupled with commercial quantum random number generator (QRNG) hardware, demonstrates that QR-NTT significantly degrades the effectiveness of template matching and belief propagation attacks. Experimental evaluation shows a reduction in single-trace attack success rates from over 90% to below 3% and an increase of approximately two orders of magnitude in the number of traces required for successful key recovery. These security gains are achieved with moderate overheads of 18.3% in execution time and 1.8 KB of additional memory while remaining well within practical IoT constraints. The results indicate that quantum-derived entropy can be leveraged as a practical implementation-level defense against physical attacks, complementing algorithmic post-quantum security. QR-NTT demonstrates a viable path toward strengthening the real-world resilience of post-quantum IoT systems without sacrificing deployability. Full article
(This article belongs to the Section Cryptography and Cryptology)
Show Figures

Figure 1

Previous Issue
Next Issue
Back to TopTop