Skip to Content

Journal of Cybersecurity and Privacy, Volume 6, Issue 4

2026 August - 34 articles

Cover Story: Text messages that appear to know your job, interests, or your online life can be hard to dismiss. Now, what happens when AI helped create them? We invited participants to compare SMS spear phishing messages written by GPT-4 and by student authors, then explain what made each message feel convincing or suspicious. Participants were not reliably able to tell whether a message was written by a human or AI; yet, a computational classifier distinguished between them with 88.7% balanced accuracy. Messages that are related to their work stood out as especially compelling, and participants found AI-generated messages comparable to human-authored messages within this pilot's uncertainty. Our study shows how simple AI tools and prompting can make personalized social engineering easier to scale, and why cybersecurity education needs to keep pace. View this paper
  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list .
  • You may sign up for email alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.

Articles (34)

  • Article
  • Open Access
353 Views
37 Pages

The increasing dependence of financial supply chains on digital infrastructures has made it more necessary to design secure, resilient, and reliable networks than ever before. This research presents a self-healing framework based on blockchain and di...

(This article belongs to the Special Issue Blockchain for Cybersecurity and Cyber-Risk Management)
  • Article
  • Open Access
361 Views
13 Pages

Separating Probabilistic Inference from Deterministic Governance in Cyber Risk Automation

  • Tope Olufon,
  • Stilianos Vidalis,
  • Deepthi Ratnayake,
  • Alexios Mylonas and
  • Muyiwa Olufon

Risk registers remain static governance artefacts, manually maintained and weakly coupled to operational evidence. While organisations generate continuous security telemetry from vulnerability scanners, incident reports, and audit findings, this evid...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
400 Views
17 Pages

Directive (EU) 2022/2555 (NIS2) designated healthcare a sector of high criticality, with a transposition deadline of 17 October 2024. Only four of twenty-seven Member States met it: Croatia transposed eight months early and Italy one day before the d...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
277 Views
28 Pages

Cilium is among the most widely deployed Container Network Interfaces (CNIs), serving as the default CNI in the Google Kubernetes Engine. It extends standard Kubernetes NetworkPolicy (KNP) with two additional types—CiliumNetworkPolicy (CNP) and...

(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity—2nd Edition)
  • Article
  • Open Access
321 Views
31 Pages

This paper presents a secure data sharing platform that organises KR-IBI, KR-IBE, KR-PEKS, and KR-PAEKS into an end-to-end Rust/Tauri workflow for registration, authentication, encrypted upload, searchable retrieval, and authorised decryption. The wo...

(This article belongs to the Section Cryptography and Cryptology)
  • Article
  • Open Access
830 Views
21 Pages

The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A...

(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust, 2nd Edition)
  • Review
  • Open Access
784 Views
36 Pages

Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains, where poisoning attacks can corrupt training data, manipulate model updates, or implant covert backdoors. This survey examines poisoning attacks in federated learn...

(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
  • Review
  • Open Access
1,181 Views
44 Pages

Adversarial machine learning (AML), reinforcement learning (RL), and explainable artificial intelligence (XAI) are increasingly studied as separate problems, yet their interactions under realistic threat conditions remain poorly understood. This revi...

(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
  • Article
  • Open Access
523 Views
35 Pages

Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeh...

(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
  • Article
  • Open Access
554 Views
18 Pages

Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
715 Views
32 Pages

Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study

  • Jerson Francia,
  • Derek Hansen,
  • Benjamin Schooley,
  • Matthew Taylor,
  • Shydra Valynn Murray,
  • Rebekah Cornelius and
  • Greg Snow

Personalized phishing is difficult to defend against because messages can be tailored to a target’s work, interests, and social context. Large language models may make such tailoring faster and easier, but it remains unclear whether messages pr...

(This article belongs to the Collection Intelligent Security and Privacy Approaches against Cyber Threats)
  • Article
  • Open Access
742 Views
22 Pages

DITA: A Dynamic Image-Based Authentication Protocol for Secure Network Communication Against Replay and Eavesdropping Attacks

  • Seerwan Waleed Jirjees,
  • Alaa Q. Raheema,
  • Hanan Ghali Jabbar,
  • Ahmed M. Hasan and
  • Amjad Jaleel Humaidi

Tokens are widely used to secure client–server communications in systems based on automatic authentication. These tokens can be vulnerable to hacking, as an attacker can impersonate a real user by eavesdropping on their communications. In this...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
1,395 Views
20 Pages

As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have...

(This article belongs to the Collection Machine Learning and Data Analytics for Cyber Security)
  • Article
  • Open Access
739 Views
38 Pages

Homomorphic Encryption as an Enabler for Secure Multi-Source Data Aggregation and Confidential Analytics

  • Cristina Regueiro,
  • Julen Bernabé-Rodríguez,
  • Iñaki Seco-Aguirre and
  • Idoia Gamiz

Homomorphic Encryption plays a key role in secure multi-source data aggregation because it enables computations to be performed directly over encrypted data, allowing distributed parties to contribute sensitive information while preserving confidenti...

(This article belongs to the Special Issue Applied Cryptography)
  • Article
  • Open Access
482 Views
26 Pages

Spam detection on SMS messaging has not received as much attention from researchers recently as the spam detection studies on emails or social media platforms. However, spam SMS messaging can be more intrusive, annoying, and harmful. Thus, detecting...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
787 Views
29 Pages

Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation

  • Jevon Dixon,
  • Charupol Ruangsuwan and
  • Issara Sereewatthanawut

Cyberattacks have become a routine feature of contemporary security environments, yet policy responses often treat cyber threats as undifferentiated, encouraging generic remedies while obscuring the distinct capabilities needed to address different f...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
504 Views
26 Pages

(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical tas...

(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
  • Article
  • Open Access
788 Views
62 Pages

This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting het...

(This article belongs to the Topic Trends and Prospects in Security, Encryption and Encoding: 2nd Edition)
  • Article
  • Open Access
671 Views
26 Pages

Text-to-Unlearn: Robust Concept Removal in GANs via Text Prompts

  • Piyush Nagasubramaniam,
  • Neeraj Karamchandani,
  • Chen Wu and
  • Sencun Zhu

State-of-the-art generative models exhibit powerful image-generation capabilities, raising ethical and legal challenges for service providers. Consequently, Content Removal Techniques (CRTs) have emerged to control outputs without requiring full retr...

(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
  • Article
  • Open Access
587 Views
23 Pages

This case study examines an encryption failure incident involving the exposure of sensitive personal data within a governmental information system environment. The analysis is based on the well-documented data breach that occurred within the U.S. Dep...

(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
  • Article
  • Open Access
694 Views
27 Pages

Agile Resilience in Security for Small and Medium-Sized Businesses

  • Selahattin Hürol Türen,
  • Kenneth Eustace,
  • Rafiqul Islam and
  • Geoffrey Fellows

Small businesses face many of the same cyber threats as larger organisations but often lack equivalent budgets, specialist personnel, and formal security operations capability. This paper proposes Agile Resilience in Security for Enterprises (ARISE),...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
1,099 Views
30 Pages

Existing Large Language Model cybersecurity evaluations rely on text-based plausibility scoring systems that fail to validate operational exploit viability. In this paper, we present the Operational Risk Framework (ORF), advancing beyond our prior Ma...

(This article belongs to the Special Issue Current Trends in Data Security and Privacy—2nd Edition)
  • Article
  • Open Access
807 Views
27 Pages

The growing reliance on cyber deception as a defensive mechanism has revealed persistent limitations in existing deception infrastructures, particularly in their ability to scale, adapt, and provide continuous observability under realistic adversaria...

(This article belongs to the Section Security Engineering & Applications)
  • Review
  • Open Access
1,328 Views
27 Pages

Phishing remains a widespread and evolving cyber threat that targets human and technical vulnerabilities across email, web, mobile, and social media. Meanwhile, digital forensics has developed into a standards-driven discipline dedicated to identifyi...

(This article belongs to the Section Security Engineering & Applications)
  • Review
  • Open Access
632 Views
29 Pages

Sensor networks increasingly combine exposed sensing nodes, optical communication, photonic hardware, near-sensor inference, and distributed infrastructure monitoring. This changes the security problem from protecting packets alone to establishing de...

(This article belongs to the Special Issue Advanced Technologies for Detecting Cybersecurity Attacks in Internet of Things Systems)
  • Article
  • Open Access
582 Views
25 Pages

Privacy usability in IoT smart home companion applications remains an underexplored domain despite mounting regulatory requirements and accelerating user adoption. Heuristic evaluation offers a scalable pathway to privacy usability assessment, yet va...

(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust, 2nd Edition)
  • Article
  • Open Access
613 Views
28 Pages

Cybersecurity conformity assessment is increasingly shaped by the Radio Equipment Directive (RED) delegated act, the EN 18031 harmonized standards, the Cyber Resilience Act, and industrial standards such as International Electrotechnical Commission (...

(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
  • Article
  • Open Access
488 Views
22 Pages

Robust Stealthy High-Impact Malicious Hardware Attacks on Deep Neural Networks

  • Maath Frman,
  • Kholood J. Moulood,
  • Mustafa Noori,
  • Ekram H. Hasan,
  • Oqbah Salim Atiyah and
  • Qutaiba Alasad

The rapid advancement of modern deep neural networks (DNNs) has played a crucial role in aiding humans across many real-world applications; yet, their hardware accelerators have been proven to be vulnerable to malicious attacks. One particularly seve...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
702 Views
53 Pages

Quantum computing presents a critical threat to the cryptographic basis of metaverse platforms, with Shor’s algorithm capable of breaking traditional public-key cryptography and Grover’s algorithm significantly weakening symmetric encrypt...

(This article belongs to the Collection Intelligent Security and Privacy Approaches against Cyber Threats)
  • Article
  • Open Access
715 Views
19 Pages

Homomorphic Encryption (HE) has emerged as a promising approach for data processing without exposing sensitive information. Despite significant advances, the practical strategies for the integration of HE into widely used database management systems...

(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust, 2nd Edition)
  • Article
  • Open Access
509 Views
31 Pages

Cyber Security Incident Response (IR) playbooks are used to capture the steps required to recover from a cyber intrusion. Intrusion modelling focuses on a specific potential cyber intrusion and is used to identify where and what countermeasures are n...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
604 Views
29 Pages

This paper proposes a model for account-holding proofs across multiple authorities and presents a concrete construction from JWT-derived evidence, enabling a verifier to evaluate the resulting artifact under specified system assumptions and acceptanc...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
734 Views
34 Pages

Cybersecurity risk management is often complicated by fragmented solutions for threat identification and detection, vulnerability assessment, and control selection across multiple frameworks. This paper presents a unified, dynamically updated, threat...

(This article belongs to the Section Security Engineering & Applications)
  • Article
  • Open Access
542 Views
22 Pages

The choice of a symmetric encryption algorithm in practice is rarely as straightforward as it may appear from theoretical comparisons alone. In addition to security considerations, real-world selection often depends on execution time, reliability, en...

(This article belongs to the Special Issue Applied Cryptography)
XFacebookLinkedIn
J. Cybersecur. Priv. - ISSN 2624-800X