Skip to Content

Journal of Cybersecurity and Privacy

Journal of Cybersecurity and Privacy is an international, peer-reviewed, open access journal on all aspects of computer, systems, and information security, published bimonthly online by MDPI.

Get Alerted

Add your email address to receive forthcoming issues of this journal.

All Articles (453)

  • Article
  • Open Access

Quantum Encryption Resilience Score (QERS): A System-Level Evaluation Framework

  • Jonatan Rassekhnia,
  • Karl Andersson and
  • Ahmed Afif Monrat

The transition to post-quantum cryptography (PQC) presents significant challenges for modern computing environments due to increased computational overhead, communication latency, and implementation complexity. Existing evaluation methods typically focus on isolated cryptographic performance metrics and do not provide a unified framework for assessing the overall resilience of PQC deployments across heterogeneous systems. This paper introduces the Quantum Encryption Resilience Score (QERS), a novel system-level evaluation framework designed to quantify the resilience of post-quantum cryptographic implementations by integrating computational, network, and operational performance metrics into a single composite score. QERS provides a standardized methodology for comparing PQC algorithms across diverse deployment scenarios. In this study, the framework is experimentally evaluated using a heterogeneous ESP32-based embedded and IoT testbed with gateway-assisted post-quantum cryptographic processing. The proposed framework is validated through experimental implementations of the NIST-standardized ML-KEM key encapsulation mechanism and the ML-DSA digital signature algorithm under multiple communication protocols and heterogeneous hardware configurations. Experimental results demonstrate that QERS effectively distinguishes the trade-offs between security, computational efficiency, resource utilization, and communication performance, providing a practical decision-support framework for selecting appropriate PQC implementations. The proposed framework contributes a reproducible and extensible methodology for the system-level evaluation of post-quantum cryptography and establishes a foundation for future research into standardized resilience and trust assessment of quantum-resistant systems.

J. Cybersecur. Priv.

22 September 2026

Conceptual architecture of the proposed Quantum Encryption Resilience Score (QERS). The framework integrates communication, computational, cryptographic, and operational metrics into a unified composite evaluation for assessing the resilience of post-quantum cryptographic deployments.
  • Article
  • Open Access

The Adaptive Deficit: An Evolutionary Governance Perspective on Information Security

  • Emmanouil Mavrofidis,
  • Aikaterini Tsatsaroni and
  • Achilles D. Kameas

Despite growing regulation and mature security tooling, cyberattacks continue to rise. This study examines how information security professionals perceive the challenges of securing modern systems. More specifically, we consider increasing technological complexity, the human factor, organizational change, and resilience through Evolutionary Governance Theory (EGT) and explore whether information security governance (ISG) co-evolves with the same velocity as the systems it manages. A closed-ended, five-point Likert questionnaire was developed, which was completed by 65 information security professionals recruited through the Global Information Assurance Certification (GIAC) Advisory Board and LinkedIn between October 2024 and March 2025. Responses were analyzed using descriptive statistics and Spearman correlations. Respondents were near-unanimous that technological evolution has increased complexity and interdependence, and that resilience is essential. 41.5% of respondents consider that governance lacks the processes to detect and respond to environmental changes, identifying a gap in governance capacity. Within this sample, no item was significantly associated with tenure, experience, or organization size, though the analysis is underpowered for small effects. This study applies EGT in the domain of information security, and reports practitioner evidence consistent with an interpretation of the ISG gap as an adaptive deficit of co-evolving systems rather than as an implementation failure.

J. Cybersecur. Priv.

17 September 2026

Gender. Source: authors’ own survey data (N = 65).
  • Article
  • Open Access

Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We propose MetaGNN-Sec, a graph-augmented neural framework that detects metamorphic malware from program structure rather than surface bytes. The framework composes four components, each addressing a distinct facet of the problem: (i) control-flow graph (CFG) extraction with semantic opcode embeddings; (ii) a heterogeneous graph neural network (hGNN) operating over program-dependence graphs that capture mutation-stable control- and data-flow invariants; (iii) an adversarial training loop derived from the Wasserstein generative adversarial network (WGAN) that hardens the classifier against adaptive evasion mutations; and (iv) a quantum-kernel anomaly layer implemented in PennyLane for separation of heavily obfuscated outliers in a high-dimensional feature space. Results: Experiments are conducted on two public corpora—VirusShare 2024 and a SOREL-20M subset—comprising 200,175 binary samples in total (155,175 malware and 45,000 benign), in agreement with the corpus totals reported in Datasets Section of this paper. MetaGNN-Sec achieves a detection rate of 97.83%, a false-positive rate of 0.41%, and an F1 score of 0.978 on held-out metamorphic families, exceeding the next-best baseline (MalConv+) by 4.6 percentage points on clean data and degrading by only 5.4 points under adaptive adversarial evasion (versus 17–31 points for the baselines). The quantum-kernel module contributes a further 1.2 pp reduction in false-negative rate, concentrated on the most heavily mutated families. Conclusions: The framework provides a heterogeneous PDG representation with a conditional score-shift bound under graph-edit-bounded mutations, a WGAN hardening loop that delivers measurable adversarial robustness, a quantum-kernel pre-filter with an explicit cost/benefit characterization, and a reproducible, near-real-time pipeline suitable for enterprise endpoint deployment.

J. Cybersecur. Priv.

17 September 2026

MetaGNN-Sec end-to-end architecture. The dashed red arrow indicates the adversarial feedback loop from the WGAN critic to the hGNN encoder.
  • Article
  • Open Access

Retrieval-Augmented Generation (RAG) over vulnerability databases is widely expected to improve LLM-based vulnerability detection. We report a pre-specified evaluation in which it does not, and derive from it an evaluation protocol. On a near-balanced benchmark of 100 Python 3.12 snippets, raw CVE/CWE retrieval never measurably beat four open-weight models (8B–480B) without retrieval (pooled ΔF1 = +0.006, 95% CI [−0.042; +0.051]; per-model deltas all ≤0). This article makes three contributions. First, the pre-specified null itself: bounded by its confidence interval, homogeneous across models, and invariant to tie-break, model-subset, and pair-dependence conventions. Second, a knowledge-base-overlap audit protocol—exposure identification, retrieval-trace (dose) verification, class-conditional splits, and stratified re-analysis—applied first to our own results, where it localises the null-sized advantage onto the nine snippets exposed to their own CVE entry, eight of which have retrieval traces confirming the entry actually reached the model. Third, exploratory evidence from 164 functions of real advisory-linked fix commits: the null appears there too, and the absolute performance of every tool collapses to near-chance, with a bridge cell attributing that collapse principally to the benchmark rather than to the models. In an exploratory live-corpus arm the pooled retrieval effect remains null, while a benefit appears on the 31% of functions for which the retriever surfaced the matching advisory (dosed ΔF1 = +0.336; dose-stratified difference in recovery, Fisher p < 0.0001), at a specificity cost. Because retrieval dose is confounded with retrievability, we read that benefit as known-vulnerability re-identification rather than as improved detection. We accordingly recommend that RAG security evaluations report overlap strata and retrieval dose as routinely as they report F1. We release both benchmarks, all 19,540 per-run results, and every script.

J. Cybersecur. Priv.

16 September 2026

(a) The containerised RAG pipeline (FastAPI orchestrator, Qdrant vector store, SQLite persistence) and the two baselines. The LLM-only arm bypasses retrieval while holding prompt, parser, and aggregation fixed, which is what makes the H2 contrast an ablation of the retrieval layer alone; Bandit runs directly on the snippet. Per-analysis retrieval traces are persisted and are the prerequisite for the dose audit of Section 3.7 and Section 4.3. (b) The experimental pipeline. Confirmatory claims (H1, H2) rest exclusively on the original campaign over the synthetic benchmark; every other cell is exploratory and is reported as such. The bridge cell runs the current models on the original benchmark, which is what allows the real-code collapse to be separated into benchmark and model components (Section 4.7). Solid connectors carry the retrieval-augmented flow; dashed connectors mark the two baseline feeds that bypass retrieval in (a) and, in (b), the stratum-wise reuse of the paired statistics for the exploratory verdicts. In (b), blue marks the original campaign and orange the current-model cells.

Featured Articles of Last Quarter

Highly Accessed Articles

News & Conferences

Latest Issues

Open for Submission

Journal Sections

Machine Learning and Data Analytics for Cyber Security
Reprint

Machine Learning and Data Analytics for Cyber Security

Editors: Phil Legg, Giorgio Giacinto
Cyber Security and Critical Infrastructures - Volume II
Reprint

Cyber Security and Critical Infrastructures - Volume II

Editors: Leandros Maglaras, Helge Janicke, Mohamed Amine Ferrag
XFacebookLinkedIn
J. Cybersecur. Priv. - ISSN 2624-800X