-
Proof-of-Exploit: Cryptographically Verified LLM Cybersecurity Evaluation via Tiered Risk Metrics in the Operational-Risk Framework -
Security Aspects of Zones and Conduits in IEC 62443 -
Investigating Security Vulnerabilities in 5G Control and User Planes: Attack Patterns and Protection Strategies -
IoT Vulnerability Severity Prediction Using Lightweight Transformer Models
Journal Description
Journal of Cybersecurity and Privacy
Journal of Cybersecurity and Privacy
is an international, peer-reviewed, open access journal on all aspects of computer, systems, and information security, published bimonthly online by MDPI.
- Open Access— free for readers, with article processing charges (APC) paid by authors or their institutions.
- High Visibility: indexed within ESCI (Web of Science), Scopus, EBSCO, and other databases.
- Rapid Publication: manuscripts are peer-reviewed and a first decision is provided to authors approximately 23.7 days after submission; acceptance to publication is undertaken in 5.6 days (median values for papers published in this journal in the first half of 2026).
- Journal Rank: JCR - Q2 (Computer Science, Information Systems) / CiteScore - Q1 (Computer Science (miscellaneous))
- Recognition of Reviewers: APC discount vouchers, optional signed peer review, and reviewer names published annually in the journal.
- Journal Cluster of Information Systems and Technology: Analytics, Applied System Innovation, Cryptography, Data, Digital, Informatics, Information, Journal of Cybersecurity and Privacy and Multimedia.
Impact Factor:
3.8 (2025);
5-Year Impact Factor:
4.2 (2025)
Latest Articles
A Structured NIS2–ISO/IEC 27001:2022 Alignment Framework for Higher Education Institutions
J. Cybersecur. Priv. 2026, 6(5), 140; https://doi.org/10.3390/jcp6050140 (registering DOI) - 22 Aug 2026
Abstract
Higher education institutions operate complex digital environments that combine administrative services, research infrastructures, learning platforms, identity systems, and heterogeneous departmental IT. In the European Union, the NIS2 Directive increases the need for structured cybersecurity governance, while ISO/IEC 27001:2022 provides a mature information security
[...] Read more.
Higher education institutions operate complex digital environments that combine administrative services, research infrastructures, learning platforms, identity systems, and heterogeneous departmental IT. In the European Union, the NIS2 Directive increases the need for structured cybersecurity governance, while ISO/IEC 27001:2022 provides a mature information security management system standard that can support implementation. This paper proposes a design science artefact for aligning NIS2 obligations with ISO/IEC 27001:2022 clauses and Annex A controls in the context of higher education institutions. The framework organizes cybersecurity governance, asset and service scoping, risk management, incident handling, business continuity, supplier and cloud dependencies, access control, awareness, monitoring, and continual improvement into a staged maturity model. The artefact is instantiated for a Romanian public university context and assessed through internal traceability analysis, including mappings between NIS2 Articles 20, 21, and 23, Romanian NIS2 transposition requirements, and ISO/IEC 27001:2022 control areas. The institutional illustration identifies candidate assessment domains and evidence requirements but does not assign maturity levels because the internal records required by the scoring protocol were unavailable; it therefore does not constitute an audit, verified institutional measurement, or empirical validation. The contribution is therefore a structured and reusable compliance design artefact, together with a transparent mapping method that can support future expert validation, institutional pilots, and audit-oriented refinement.
Full article
(This article belongs to the Section Security Engineering & Applications)
►
Show Figures
Open AccessArticle
A Self-Healing Blockchain-Based Digital Twin Framework for Cybersecurity-Aware Fuzzy Multi-Objective Supply Chain Finance Optimization Under Uncertainty
by
Hamed Nozari and Zornitsa Yordanova
J. Cybersecur. Priv. 2026, 6(4), 139; https://doi.org/10.3390/jcp6040139 - 18 Aug 2026
Abstract
The increasing dependence of financial supply chains on digital infrastructures has made it more necessary to design secure, resilient, and reliable networks than ever before. This research presents a self-healing framework based on blockchain and digital twins for multi-objective fuzzy optimization of financial
[...] Read more.
The increasing dependence of financial supply chains on digital infrastructures has made it more necessary to design secure, resilient, and reliable networks than ever before. This research presents a self-healing framework based on blockchain and digital twins for multi-objective fuzzy optimization of financial supply chains under uncertainty. The proposed model, focusing on minimizing financial cost, cyber risk, and recovery time while simultaneously maximizing the level of trust and resilience, enables intelligent decision-making in the face of cyber threats. By combining real-time monitoring, secure transaction validation, fuzzy risk assessment, and automated recovery, the framework identifies the role of each component in maintaining the financial and operational stability of the network. The results showed that the complete model achieved an overall performance score of 0.944 in the component elimination study and increased the level of trust and resilience to 0.95 and 0.96, respectively. The cyber risk index was also maintained at 0.118, indicating the framework’s ability to control threats and maintain network stability. The findings show that the convergence of blockchain, digital twin, fuzzy logic, and self-healing mechanism can provide an effective basis for the development of smart, secure, and resilient financial supply chains.
Full article
(This article belongs to the Special Issue Blockchain for Cybersecurity and Cyber-Risk Management)
►▼
Show Figures

Figure 1
Open AccessArticle
Separating Probabilistic Inference from Deterministic Governance in Cyber Risk Automation
by
Tope Olufon, Stilianos Vidalis, Deepthi Ratnayake, Alexios Mylonas and Muyiwa Olufon
J. Cybersecur. Priv. 2026, 6(4), 138; https://doi.org/10.3390/jcp6040138 - 17 Aug 2026
Abstract
Risk registers remain static governance artefacts, manually maintained and weakly coupled to operational evidence. While organisations generate continuous security telemetry from vulnerability scanners, incident reports, and audit findings, this evidence is rarely synthesised into coherent, evolving risk structures. Existing approaches address fragments of
[...] Read more.
Risk registers remain static governance artefacts, manually maintained and weakly coupled to operational evidence. While organisations generate continuous security telemetry from vulnerability scanners, incident reports, and audit findings, this evidence is rarely synthesised into coherent, evolving risk structures. Existing approaches address fragments of the problem: SIEM systems correlate events but do not construct risk registers; GRC platforms manage risk documentation but depend on manual entry; and LLM applications assist with summarisation but introduce non-determinism incompatible with governance requirements. This paper presents a hybrid architecture that separates stochastic LLM-based extraction from deterministic risk correlation and aggregation. The system ingests heterogeneous evidence, extracts structured claims via schema-bounded LLM processing, and correlates events into stable risk trees using anchor-based tiered matching. All correlation and projection operations are deterministic and replayable. The contribution is an architectural design pattern for integrating probabilistic inference into governance systems without compromising auditability. The walkthroughs run on a reference prototype. Replaying the stored evidence three times rebuilt the same register state, and admission scores matched the values the rules predict. An injected malformed extraction was quarantined; the register did not change.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Figure 1
Open AccessArticle
Regulatory Convergence, Institutional Divergence: Comparing NIS2 Incident-Reporting Transparency in the Healthcare Sectors of Croatia and Italy
by
Tomislav Vazdar and Mario Spremić
J. Cybersecur. Priv. 2026, 6(4), 137; https://doi.org/10.3390/jcp6040137 - 16 Aug 2026
Abstract
Directive (EU) 2022/2555 (NIS2) designated healthcare a sector of high criticality, with a transposition deadline of 17 October 2024. Only four of twenty-seven Member States met it: Croatia transposed eight months early and Italy one day before the deadline. Because the formal regulatory
[...] Read more.
Directive (EU) 2022/2555 (NIS2) designated healthcare a sector of high criticality, with a transposition deadline of 17 October 2024. Only four of twenty-seven Member States met it: Croatia transposed eight months early and Italy one day before the deadline. Because the formal regulatory gap between them is small—and, on the primary instrument, favours Croatia—this paper asks not whether but how two Member States with near-identical transposition timelines diverge in the operational practice and transparency of healthcare-sector incident reporting. Drawing on neo-institutional theory and the economics of information security, it synthesises the literature and compares the two transposition instruments against the primary legal texts. Both reproduce the NIS2 notification timeline faithfully, so divergence cannot be attributed to differing statutory obligations. Public-reporting transparency is therefore operationalised as a measurable dependent variable: Italy’s Agenzia per la Cybersicurezza Nazionale (ACN), an autonomous agency since 2021, publishes healthcare-specific data, whereas Croatia’s National Cybersecurity Centre (NCSC-HR)—competent authority only since 2025—publishes only aggregate figures. The asymmetry is autonomy and mandate, not institutional age. A portable four-indicator transparency index is proposed and demonstrated in a two-coder pilot (κ_w = 0.80); an independent incident-composition cross-check is consistent with the asymmetry.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Figure 1
Open AccessArticle
A Decision-Diagram Framework for Conflict Detection in Multi-Layer Cilium Network Policies
by
Thawatchai Chomsiri and Suwichai Phunsa
J. Cybersecur. Priv. 2026, 6(4), 136; https://doi.org/10.3390/jcp6040136 - 14 Aug 2026
Abstract
Cilium is among the most widely deployed Container Network Interfaces (CNIs), serving as the default CNI in the Google Kubernetes Engine. It extends standard Kubernetes NetworkPolicy (KNP) with two additional types—CiliumNetworkPolicy (CNP) and CiliumClusterwideNetworkPolicy (CCNP)—each with distinct semantics. When all three coexist
[...] Read more.
Cilium is among the most widely deployed Container Network Interfaces (CNIs), serving as the default CNI in the Google Kubernetes Engine. It extends standard Kubernetes NetworkPolicy (KNP) with two additional types—CiliumNetworkPolicy (CNP) and CiliumClusterwideNetworkPolicy (CCNP)—each with distinct semantics. When all three coexist in a cluster, the resulting composition is difficult to reason about formally, leading to misconfiguration and security incidents. Existing verification tools, KANO and VeriKube, address subsets of the problem but share two critical limitations: neither provides a formal denotational semantics that precisely characterizes the three-layer composition, nor a canonical representation enabling policy-equivalence checking with completeness guarantees. We close this gap with three contributions. First, we develop the first formal denotational semantics for Cilium’s three-layer composed policy—KNP (additive), CNP (deny-wins), CCNP (cluster-override)—and prove that the composite function is Hyper-Rectangular Piecewise-Constant (HRPC)-like. Second, we construct a Reduced Ordered Interval Decision Diagram (ROIDD) for the composite policy space and prove a canonicity theorem—canonical for a fixed field order—enabling policy-equivalence checking as structural isomorphism in O(|ROIDD|) time. Third, we develop certified conflict-detection algorithms for shadow, redundancy, and cross-layer conflict anomalies across all three layers with formal proofs of soundness and completeness. Experimental evaluation on synthetic policies confirms zero mismatches between ROIDD evaluation and ground-truth brute force; detection of shadow, redundancy and cross-layer anomalies at precision and recall of 1.000, scored against exhaustive enumeration of the entire packet space; agreement with a live Cilium v1.19.5 data plane on every probe of a scenario built to exercise each clause of the composite semantics; ROIDD compression ratios of 5–15× over the unshared decision tree on the compressed evaluation domain; and low-microsecond (0.74–1.95 µs) per-packet lookup latency that is independent of policy size. A native C++ implementation, evaluated on the same policy dataset, reconstructs the identical decision-diagram structure and classifies each packet in under 60 ns—roughly 30× faster than the Python reference—confirming that sub-microsecond classification is inherent to the algorithm rather than an artifact of the implementation language.
Full article
(This article belongs to the Special Issue Building Community of Good Practice in Cybersecurity—2nd Edition)
►▼
Show Figures

Figure 1
Open AccessArticle
Secure Data Sharing Using k-Resilient Identity-Based Cryptographic Suite: Design, Implementation, and Evaluation
by
Poh-Wen Kho, Syh-Yuan Tan and Swee-Huay Heng
J. Cybersecur. Priv. 2026, 6(4), 135; https://doi.org/10.3390/jcp6040135 - 12 Aug 2026
Abstract
This paper presents a secure data sharing platform that organises KR-IBI, KR-IBE, KR-PEKS, and KR-PAEKS into an end-to-end Rust/Tauri workflow for registration, authentication, encrypted upload, searchable retrieval, and authorised decryption. The work addresses a deployment-level composition problem rather than proposing a new primitive:
[...] Read more.
This paper presents a secure data sharing platform that organises KR-IBI, KR-IBE, KR-PEKS, and KR-PAEKS into an end-to-end Rust/Tauri workflow for registration, authentication, encrypted upload, searchable retrieval, and authorised decryption. The work addresses a deployment-level composition problem rather than proposing a new primitive: practical data sharing requires coordinated credential handling, payload representation, searchable indexing, session control, and record integrity across schemes with distinct interfaces. The platform supports text, file, and image payloads through a hybrid KR-IBE/HKDF-SHA-256/AES-256-GCM layer. Fresh KR-IBE key material is generated by uniformly sampling a nonzero scalar and multiplying the Ed25519 prime-order subgroup generator, providing approximately 252 bits of min-entropy before HKDF derivation. An evaluation with 100 repetitions per configuration over Enron-derived workloads containing 100–10,000 records and 1, 5, 10, or 20 authorised identities achieved 100/100 correctness for authorised retrieval and decryption, wrong-keyword and wrong-scheme rejection, and unauthorised-access rejection. KR-PEKS search latency ranged from 29.26 ms at 100 records to 3023.82 ms at 10,000 records, whereas KR-PAEKS ranged from 775.53 ms to 93,045.52 ms. These results quantify the performance distinction between the lower-latency KR-PEKS mode and the sender-authenticated searchable encryption provided by KR-PAEKS.
Full article
(This article belongs to the Section Cryptography and Cryptology)
►▼
Show Figures

Figure 1
Open AccessArticle
Quishing: A Sociotechnical Framework for Understanding QR-Code Phishing Risks and User-Centered Protection Strategies
by
Pedro-David Filio-Aguilar, Rubén Mil-Martínez and Lourdes López-García
J. Cybersecur. Priv. 2026, 6(4), 134; https://doi.org/10.3390/jcp6040134 - 8 Aug 2026
Abstract
The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A structured literature review and narrative synthesis were conducted using
[...] Read more.
The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A structured literature review and narrative synthesis were conducted using four documented search strings. Following deduplication, screening, retrieval, and full-text assessment, 27 studies were included from 71 identified records. Two reviewers independently evaluated methodological quality using six criteria. The corpus comprised 16 technical-detection studies, five user-centered or behavioral studies, two attack demonstrations or simulations, and four reviews or preventive frameworks. The mean consensus quality score was 10.04 out of 12; 19 studies were classified as high quality and eight as moderate quality. The synthesis indicates that quishing exploits the interaction of contextual legitimacy, routine scanning, limited destination visibility, and insufficient verification before navigation or disclosure of sensitive information. These findings informed an attack lifecycle, a sociotechnical model, a user security decision flow, a risk–protection mapping, and multilevel recommendations. These literature-derived artifacts are conceptual and heuristic rather than empirically validated. Effective mitigation therefore requires QR-specific verification mechanisms combined with behavioral and technical safeguards for users, interfaces, organizations, and platforms, followed by expert, usability, and experimental validation.
Full article
(This article belongs to the Topic Recent Advances in Security, Privacy, and Trust, 2nd Edition)
►▼
Show Figures

Graphical abstract
Open AccessReview
Poisoning Attacks in Federated Learning: An Accountability- Oriented Survey with Centralized Learning as a Baseline
by
Safiia Mohammed, Dima Alhadidi and Alioune Ngom
J. Cybersecur. Priv. 2026, 6(4), 133; https://doi.org/10.3390/jcp6040133 - 7 Aug 2026
Abstract
Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains, where poisoning attacks can corrupt training data, manipulate model updates, or implant covert backdoors. This survey examines poisoning attacks in federated learning (FL), using centralized learning as a baseline to explain how distributed
[...] Read more.
Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains, where poisoning attacks can corrupt training data, manipulate model updates, or implant covert backdoors. This survey examines poisoning attacks in federated learning (FL), using centralized learning as a baseline to explain how distributed data, client heterogeneity, privacy-preserving aggregation, and untrusted coordination expand the threat surface. It positions prior surveys and synthesizes representative primary studies through an accountability-oriented lens focused on attribution, audit evidence, traceability, and forensic readiness. The review compares major attack classes, including data poisoning, model poisoning, backdoor insertion, server-side manipulation, Sybil behavior, collusion, and multi-round poisoning. It also evaluates countermeasures such as Byzantine-robust aggregation, anomaly detection, validation-based filtering, malicious-secure aggregation, authenticated update handling, provenance mechanisms, ledger-based evidence, and verifiable aggregation protocols. The analysis shows that robustness alone is insufficient for trustworthy FL unless defenses also preserve evidence that supports independent verification, post-incident reconstruction, and governance review. Persistent gaps remain in causal forensic attribution, privacy-preserving evidence governance, malicious-server threat modeling, scalable verifiability tooling, recovery after poisoning, and deployment-ready benchmarks. The survey concludes that accountable FL should be designed as an evidence-producing system, not merely as a privacy-preserving or attack-resistant training architecture, especially for regulated, cross-silo, and high-risk real-world deployments.
Full article
(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
►▼
Show Figures

Figure 1
Open AccessReview
Adversarial Machine Learning for Secure and Explainable AI Systems: A Comprehensive Review
by
Hajar Ouazza, Fadoua Khennou and Abderrahim Abdellaoui
J. Cybersecur. Priv. 2026, 6(4), 132; https://doi.org/10.3390/jcp6040132 - 7 Aug 2026
Abstract
Adversarial machine learning (AML), reinforcement learning (RL), and explainable artificial intelligence (XAI) are increasingly studied as separate problems, yet their interactions under realistic threat conditions remain poorly understood. This review addresses that gap through a systematic analysis of 207 studies selected from 4447
[...] Read more.
Adversarial machine learning (AML), reinforcement learning (RL), and explainable artificial intelligence (XAI) are increasingly studied as separate problems, yet their interactions under realistic threat conditions remain poorly understood. This review addresses that gap through a systematic analysis of 207 studies selected from 4447 records following the PRISMA 2020 guidelines, covering work published between 2020 and 2026 across cybersecurity and computer vision. A taxonomy of adversarial attacks is constructed across training and inference phases, defense mechanisms are examined with attention to their documented failure modes, and robustness evaluation practices are assessed across the surveyed literature. RL is analyzed in both offensive and defensive roles. Attack agents using RL achieve evasion rates of 74–97% against ML-based detectors, while RL-based defenses report robustness gains of up to 3× over static baselines under comparable threat conditions. XAI receives particular attention because the field treats it almost exclusively as a transparency mechanism, whereas the reviewed evidence shows that it also functions as an attack surface. Attribution methods such as LIME, SHAP, and Grad-CAM produce unreliable explanations under adversarial perturbation, and no system in the reviewed literature certifies that attribution properties are maintained when inputs are manipulated. The review concludes with an analysis of open problems and research directions for building systems that are robust against adaptive adversaries, interpretable under operational constraints, and auditable in environments where AI accountability is a legal requirement.
Full article
(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
►▼
Show Figures

Figure 1
Open AccessArticle
AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey
by
Mansour Almalki, Liqaa Nawaf and Fiona Carroll
J. Cybersecur. Priv. 2026, 6(4), 131; https://doi.org/10.3390/jcp6040131 - 3 Aug 2026
Abstract
Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a
[...] Read more.
Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (α = 0.868–0.926; ω = 0.870–0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (ρ = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.
Full article
(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
►▼
Show Figures

Figure 1
Open AccessArticle
Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework
by
Alessio Faccia and Somkiat Tangjitsitcharoen
J. Cybersecur. Priv. 2026, 6(4), 130; https://doi.org/10.3390/jcp6040130 - 3 Aug 2026
Abstract
Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability
[...] Read more.
Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Figure 1
Open AccessArticle
Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study
by
Jerson Francia, Derek Hansen, Benjamin Schooley, Matthew Taylor, Shydra Valynn Murray, Rebekah Cornelius and Greg Snow
J. Cybersecur. Priv. 2026, 6(4), 129; https://doi.org/10.3390/jcp6040129 - 1 Aug 2026
Abstract
Personalized phishing is difficult to defend against because messages can be tailored to a target’s work, interests, and social context. Large language models may make such tailoring faster and easier, but it remains unclear whether messages produced from simple prompts are more convincing
[...] Read more.
Personalized phishing is difficult to defend against because messages can be tailored to a target’s work, interests, and social context. Large language models may make such tailoring faster and easier, but it remains unclear whether messages produced from simple prompts are more convincing than those written by people. This 25-target pilot study compared personalized smishing messages generated by GPT-4 with messages written by novice student authors working under time constraints. Using the proposed Threshold Ranking Approach for Personalized Deception (TRAPD), participants ranked 12 messages written for them, indicated the point at which they would intend to click, explained their reasoning, and judged whether each message was authored by GPT-4 or a human. GPT-4-generated messages elicited an intention to click more often than student-authored messages (28% versus 21%), although the difference was uncertain. More broadly, our findings suggest that a simple prompt can produce personalized messages that participants found comparably convincing within the uncertainty of this pilot study. Job-related messages were significantly more likely to elicit an intention to click than hobby- or social-media-related messages. When asked whether a message was written by a human or generated by AI, participants identified the source no more accurately than chance, although the two study-specific message sets remained computationally distinguishable based on their text. Together, these findings suggest that accessible AI-assisted personalization may increase the practical scale of social-engineering threats, while also demonstrating both the value and current limitations of TRAPD for controlled and ethical comparison.
Full article
(This article belongs to the Collection Intelligent Security and Privacy Approaches against Cyber Threats)
►▼
Show Figures

Figure 1
Open AccessArticle
DITA: A Dynamic Image-Based Authentication Protocol for Secure Network Communication Against Replay and Eavesdropping Attacks
by
Seerwan Waleed Jirjees, Alaa Q. Raheema, Hanan Ghali Jabbar, Ahmed M. Hasan and Amjad Jaleel Humaidi
J. Cybersecur. Priv. 2026, 6(4), 128; https://doi.org/10.3390/jcp6040128 - 22 Jul 2026
Abstract
Tokens are widely used to secure client–server communications in systems based on automatic authentication. These tokens can be vulnerable to hacking, as an attacker can impersonate a real user by eavesdropping on their communications. In this paper, we propose a new authentication mechanism
[...] Read more.
Tokens are widely used to secure client–server communications in systems based on automatic authentication. These tokens can be vulnerable to hacking, as an attacker can impersonate a real user by eavesdropping on their communications. In this paper, we propose a new authentication mechanism that generates a random token for each authentication. The token consists of confidential data and is encrypted using random coordinates from a securely stored confidential image. The client uses a random session key to encrypt the confidential image, then encrypts the token using randomly selected coordinates by matching ASCII character values with pixel values. The results and analysis demonstrate improved resistance to credential theft, replay attacks, and passive eavesdropping under the stated security assumptions. Even if hackers crack the encrypted token, decryption is difficult because the encryption method relies on values unrelated to the original authentication data. Comparison results also demonstrate efficiency and reliability compared to existing systems, as well as their ability to withstand brute-force attacks, with the entropy of the probability distribution being the best.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Figure 1
Open AccessArticle
AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM
by
Oluwatosin J. Olaore and Abeer F. Alkhwaldi
J. Cybersecur. Priv. 2026, 6(4), 127; https://doi.org/10.3390/jcp6040127 - 22 Jul 2026
Abstract
As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance,
[...] Read more.
As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance, operational resilience, and assurance in risk reporting. However, most prevalent cybersecurity risk frameworks vary significantly in their intent, design, and analytical approach. This makes it difficult for organizations to understand how each framework may meet their business needs. This study presents an AI-enhanced multi-criteria decision support approach for evaluating cybersecurity risk frameworks. The model incorporates machine learning-driven risk scoring as a conceptual input layer, enhancing the objectivity and analytical rigor of the comparison without executing new predictive algorithms. The methodology includes a hybrid approach of literature review, document analysis, and multi-criteria decision analysis (MCDA) to compare and rank NIST CSF, ISO 27001, FAIR, OCTAVE, and CRAMM based on eight criteria that are designed to represent modern requirements for risk frameworks, including governance, scalability, quantitative focus, and interoperability. These criteria also reflect differences in security metrics supported by each framework to provide an organized means to compare qualitative versus quantitative measurement methodologies. The results indicate that NIST CSF performs the best overall in agility, business alignment, and interoperability. ISO 27001 outperforms all others in established governance and compliance. FAIR outperforms all others in quantitative risk analysis and provides superior analytical depth that other frameworks do not offer. OCTAVE and CRAMM function well in legacy systems but lack scalability and are not well-suited for modern distributed systems. Robustness analysis shows that the ranking of NIST CSF, ISO 27001, and FAIR is consistent under different weighting combinations and industry types. The result of this research demonstrates that a combined or hybrid approach to cybersecurity risk framework selection, such as using NIST CSF with FAIR, can give organizations a more well-rounded foundation for applying machine learning-enabled risk analytics with cyber controls. This research also offers a reusable decision support tool that organizations can leverage when aligning their risk priorities to the features of cybersecurity risk frameworks.
Full article
(This article belongs to the Collection Machine Learning and Data Analytics for Cyber Security)
►▼
Show Figures

Figure 1
Open AccessArticle
Homomorphic Encryption as an Enabler for Secure Multi-Source Data Aggregation and Confidential Analytics
by
Cristina Regueiro, Julen Bernabé-Rodríguez, Iñaki Seco-Aguirre and Idoia Gamiz
J. Cybersecur. Priv. 2026, 6(4), 126; https://doi.org/10.3390/jcp6040126 - 21 Jul 2026
Abstract
Homomorphic Encryption plays a key role in secure multi-source data aggregation because it enables computations to be performed directly over encrypted data, allowing distributed parties to contribute sensitive information while preserving confidentiality. However, its use in this context introduces three main challenges: existing
[...] Read more.
Homomorphic Encryption plays a key role in secure multi-source data aggregation because it enables computations to be performed directly over encrypted data, allowing distributed parties to contribute sensitive information while preserving confidentiality. However, its use in this context introduces three main challenges: existing approaches often focus on specific operations rather than supporting diverse analytics across multiple encrypted data sources; key generation and management frequently rely on trusted third parties or require private keys to be shared; and TEE-based solutions may avoid trusted third parties but often require computations to be partially executed inside the trusted environment, thereby limiting deployment flexibility. To address these limitations, this work makes three main contributions: (i) the proposal of a complete framework for secure multi-source data aggregation that leverages homomorphic encryption and enables any data consumer to securely run multi-source data aggregations over data previously registered by untrusted data providers; (ii) the integration of secure enclaves for the secure generation, distribution, and management of homomorphic keys, addressing challenges related to coordinated key synchronization in multi-party aggregation environments and removing the need for a trusted third party; and (iii) the introduction of a hybrid key management protocol that combines secure enclave-based key generation with efficient key distribution and secure aggregation outside the enclave, in the data consumer, minimizing trust assumptions and computational overhead. The implementation and evaluation on small-scale aggregated datasets show that the proposed approach effectively addresses the identified challenges by providing, to the best of the authors’ knowledge, the first practical and privacy-preserving solution that supports different algorithms without relying on any trusted third party, while improving over existing solutions through the integration of secure enclaves and a hybrid key management protocol.
Full article
(This article belongs to the Special Issue Applied Cryptography)
►▼
Show Figures

Figure 1
Open AccessArticle
ML-Based SMS Messaging Spam Detection: Impacts of Text Feature Extraction Techniques
by
Ahmad Ababneh and Maram Bani Younes
J. Cybersecur. Priv. 2026, 6(4), 125; https://doi.org/10.3390/jcp6040125 - 18 Jul 2026
Abstract
Spam detection on SMS messaging has not received as much attention from researchers recently as the spam detection studies on emails or social media platforms. However, spam SMS messaging can be more intrusive, annoying, and harmful. Thus, detecting and filtering spam SMS messages
[...] Read more.
Spam detection on SMS messaging has not received as much attention from researchers recently as the spam detection studies on emails or social media platforms. However, spam SMS messaging can be more intrusive, annoying, and harmful. Thus, detecting and filtering spam SMS messages is becoming a priority that saves human productivity. This work aims to introduce a dynamic, accurate, and efficient machine learning-based spam detection technique for SMS messaging. It aims at protecting users and businesses from spam SMS attacks. It aims to detect and identify suspicious messages that contain promotional, misleading, irrelevant, or harmful content. It primarily aims to test and evaluate the impact of feature extraction methods on the performance of machine-learning-based spam detection. Several text feature extraction techniques have been used and tested, including classical, statistical, contextual, and advanced embedding techniques. An extensive set of experiments has been presented on benchmark datasets in this field. From the comparative study, we can infer that all investigated feature extraction techniques have achieved high accuracy (90%+) on the in-domain dataset. However, their performance decreased when they were tested on the out-of-domain dataset (70%+). The advanced embedding techniques achieved the best performance across both datasets compared to the other tested feature extraction models.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Figure 1
Open AccessArticle
Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation
by
Jevon Dixon, Charupol Ruangsuwan and Issara Sereewatthanawut
J. Cybersecur. Priv. 2026, 6(4), 124; https://doi.org/10.3390/jcp6040124 - 16 Jul 2026
Abstract
Cyberattacks have become a routine feature of contemporary security environments, yet policy responses often treat cyber threats as undifferentiated, encouraging generic remedies while obscuring the distinct capabilities needed to address different forms of attack. This article develops an empirical exploratory typology of cyber
[...] Read more.
Cyberattacks have become a routine feature of contemporary security environments, yet policy responses often treat cyber threats as undifferentiated, encouraging generic remedies while obscuring the distinct capabilities needed to address different forms of attack. This article develops an empirical exploratory typology of cyber threats affecting Thailand. Drawing on incident-level data, it uses multiple correspondence analysis and hierarchical clustering to classify attacks by actor type, motive, target industry, event type, event subtype, and attributed actor country. The findings reveal three distinct threat profiles: financial cybercrime, characterised by criminal actors and financial motives; hacktivist disruption, defined by protest motives, disruptive operations, and attacks on public administration; and nation-state political espionage, associated with state-linked actors, China-attributed activity, and exploitation of end hosts. The article argues that distinguishing among these threat profiles provides a more useful basis for threat prioritisation, capability development, and resource allocation than treating cyber insecurity as a single risk category.
Full article
(This article belongs to the Section Security Engineering & Applications)
►▼
Show Figures

Graphical abstract
Open AccessArticle
A Hardware-Software Complex for the Reconstruction of Unmanned Aerial Vehicle Digital Traces Under Logical Data Damage Using LSTM-Based Telemetry Recovery and Multi-Source Confidence Scoring
by
Azamat Baibussinov, Madi Shayakhmetov, Leila Rzayeva and Kaisarbek Yesbergenov
J. Cybersecur. Priv. 2026, 6(4), 123; https://doi.org/10.3390/jcp6040123 - 13 Jul 2026
Abstract
(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and
[...] Read more.
(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and GRYPHON cannot recover telemetry when the flight logs are logically damaged, fragmented or partially deleted and don’t offer any quantitative measurement of the confidence of the recovered information. (2) Methods: A unified hardware-software complex, including a forensic workstation, a hardware write-blocker and SD/microSD/eMMC adapters; a set of software modules for extracting artifacts from files, structural parsing of DAT/BIN/CSV log, neural network reconstruction of missing telemetry using a two-layer LSTM architecture; a multi-source correlation module that combines flight logs, telemetry, media metadata and controller artifacts; a module, Confidence Score (CS), that computes a reliability measure in ; and a visualization module to generate a reconstructed trajectory on an electronic map. (3) Results: The complex has been tested on 105 flights on 10 different UAVs, 492 flight logs were gathered, 10,435 were the media item files and 624 GB was the amount of storage during acquisition. The carving stage recovers 98.7% of artifacts across the eight signature classes, the LSTM module recovers all five telemetry parameters with and a single-step horizontal position error of 6.8 m, which is reduced to 4.7 m after multi-source correlation (below the 5 m operational target consistent with consumer-GNSS precision); the dependence on gap length is described by the empirical growth law m; 46.8% of recovered records fall within the high-confidence band of ; and the complex outperforms DatCon, Autopsy + DJI Analyzer and GRYPHON by 22–35 percentage points in end-to-end record recovery and by a factor of ∼2.6 in mean horizontal error (4.7 m vs. 12.4–18.7 m). (4) Conclusions: The combined write-blocked hardware acquisition, neural reconstruction of telemetry, and quantitative confidence index provides a forensically structured pipeline that fills an existing gap in UAV digital forensics; we note that technical reconstruction accuracy does not by itself confer legal admissibility, which remains a function of jurisdiction-specific evidentiary standards discussed in the Conclusions.
Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
►▼
Show Figures

Figure 1
Open AccessArticle
TALOS: An Ultra-Efficient Area-Space 6G CryptoProcessor Leveraging Reusable Hardware Security Modules
by
Anastasios N. Bikos
J. Cybersecur. Priv. 2026, 6(4), 122; https://doi.org/10.3390/jcp6040122 - 13 Jul 2026
Abstract
This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting heterogeneous strong symmetric primitives without duplicating complete cipher cores. TALOS combines
[...] Read more.
This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting heterogeneous strong symmetric primitives without duplicating complete cipher cores. TALOS combines a Hierarchical Common Data Path (HCDP) with a three-tier cryptographic encapsulation model spanning AES-256, Snow 5G/SNOW-V-class, and ZUC-256. Tier-1 captures native nonlinear substitutions, Tier-2 compiles bounded arithmetic nonlinearities into exact micro-S-boxes, and Tier-3 consolidates shared permutation, XOR, affine, diffusion, and state-transport fabrics. This decomposition preserves cipher correctness while exposing realistic sharing opportunities across substitution, arithmetic, and linear transport layers. The architecture also supports confidentiality processing and integration with integrity- and authentication-oriented service logic through a common control/resource framework. Compared with monolithic universal-box or loosely aggregated multi-core approaches, TALOS provides a disciplined, RTL-oriented taxonomy for crypto-agile symmetric-core hardware. The proposed framework advances 6G cryptographic hardware design by combining operator-exact reuse, architectural scalability, and implementation-oriented efficiency within a single CryptoProcessor paradigm.
Full article
(This article belongs to the Topic Trends and Prospects in Security, Encryption and Encoding: 2nd Edition)
►▼
Show Figures

Graphical abstract
Open AccessArticle
Text-to-Unlearn: Robust Concept Removal in GANs via Text Prompts
by
Piyush Nagasubramaniam, Neeraj Karamchandani, Chen Wu and Sencun Zhu
J. Cybersecur. Priv. 2026, 6(4), 121; https://doi.org/10.3390/jcp6040121 - 8 Jul 2026
Abstract
State-of-the-art generative models exhibit powerful image-generation capabilities, raising ethical and legal challenges for service providers. Consequently, Content Removal Techniques (CRTs) have emerged to control outputs without requiring full retraining. However, the problem of unlearning in Generative Adversarial Networks (GANs) remains largely unexplored. We
[...] Read more.
State-of-the-art generative models exhibit powerful image-generation capabilities, raising ethical and legal challenges for service providers. Consequently, Content Removal Techniques (CRTs) have emerged to control outputs without requiring full retraining. However, the problem of unlearning in Generative Adversarial Networks (GANs) remains largely unexplored. We propose Text-to-Unlearn, a novel framework that selectively unlearns concepts from pre-trained GANs using only text prompts, enabling feature and identity unlearning, as well as fine-grained tasks such as expression and multi-attribute removal in models trained on human faces. Our approach leverages natural language descriptions to guide unlearning without additional datasets or supervised finetuning, offering a scalable solution. To evaluate the effectiveness of our method, we introduce an automated unlearning assessment method using state-of-the-art image–text alignment metrics and propose a new metric: degree of unlearning. Additionally, we assess robustness by introducing adversarial attacks to subvert unlearning. Our results demonstrate that Text-to-Unlearn achieves robust unlearning, resisting adversarial attempts to recover erased concepts while preserving model utility. To our knowledge, this is the first cross-modal unlearning framework for GANs, advancing the management of generative model behavior.
Full article
(This article belongs to the Topic Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence)
►▼
Show Figures

Figure 1
Journal Menu
► ▼ Journal Menu-
- JCP Home
- Aims & Scope
- Editorial Board
- Topical Advisory Panel
- Early Career Editorial Board
- Instructions for Authors
- Special Issues
- Topics
- Sections & Collections
- Article Processing Charge
- Indexing & Archiving
- Most Cited & Viewed
- Journal Statistics
- Journal History
- Journal Awards
- Conferences
- Editorial Office
Journal Browser
► ▼ Journal BrowserHighly Accessed Articles
Latest Books
E-Mail Alert
News
Topics
Topic in
Applied Sciences, Automation, Computers, Electronics, Sensors, JCP, Mathematics
Intelligent Optimization, Decision-Making and Privacy Preservation in Cyber–Physical Systems
Topic Editors: Lijuan Zha, Jinliang Liu, Jian LiuDeadline: 31 August 2026
Topic in
JCP, JSAN, Symmetry, Applied Sciences, Cryptography
Trends and Prospects in Security, Encryption and Encoding: 2nd Edition
Topic Editors: Ki-Hyun Jung, Luis Javier García VillalbaDeadline: 31 January 2027
Topic in
Applied Sciences, Electronics, Informatics, JCP, Future Internet, Mathematics, Sensors, Remote Sensing
Recent Advances in Artificial Intelligence for Security and Security for Artificial Intelligence
Topic Editors: Tao Zhang, Xiangyun Tang, Jiacheng Wang, Chuan Zhang, Jiqiang LiuDeadline: 28 February 2027
Topic in
Cryptography, Electronics, IJGI, JCP, MAKE, Mathematics, Sustainability
Recent Advances in Security, Privacy, and Trust, 2nd Edition
Topic Editors: Jun Feng, Changqing LuoDeadline: 31 May 2027
Conferences
Special Issues
Special Issue in
JCP
Cyber Security and Digital Forensics—3rd Edition
Guest Editors: Mario Antunes, Carlos RabadãoDeadline: 30 October 2026
Special Issue in
JCP
Current Trends in Data Security and Privacy—2nd Edition
Guest Editors: Chrysostomos Stylios, Vasiliki Liagkou, Kyriakos StefanidisDeadline: 31 October 2026
Special Issue in
JCP
Blockchain for Cybersecurity and Cyber-Risk Management
Guest Editors: Mohamed Chahine Ghanem, Rejwan Bin Sulaiman, Mohammed AlmaayahDeadline: 1 November 2026
Special Issue in
JCP
Building Community of Good Practice in Cybersecurity—2nd Edition
Guest Editors: Martin Gilje Jaatun, Aunshul Rege, Hanan HindyDeadline: 20 December 2026
Topical Collections
Topical Collection in
JCP
Intelligent Security and Privacy Approaches against Cyber Threats
Collection Editor: Nour Moustafa
Topical Collection in
JCP
Machine Learning and Data Analytics for Cyber Security
Collection Editors: Phil Legg, Giorgio Giacinto



