<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
 xmlns:dcterms="http://purl.org/dc/terms/"
 xmlns:cc="http://web.resource.org/cc/"
 xmlns:prism="http://prismstandard.org/namespaces/basic/2.0/"
 xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
 xmlns:admin="http://webns.net/mvcb/"
 xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel rdf:about="https://www.mdpi.com/rss/journal/jcp">
		<title>Journal of Cybersecurity and Privacy</title>
		<description>Latest open access articles published in J. Cybersecur. Priv. at https://www.mdpi.com/journal/jcp</description>
		<link>https://www.mdpi.com/journal/jcp</link>
		<admin:generatorAgent rdf:resource="https://www.mdpi.com/journal/jcp"/>
		<admin:errorReportsTo rdf:resource="mailto:support@mdpi.com"/>
		<dc:publisher>MDPI</dc:publisher>
		<dc:language>en</dc:language>
		<dc:rights>Creative Commons Attribution (CC-BY)</dc:rights>
						<prism:copyright>MDPI</prism:copyright>
		<prism:rightsAgent>support@mdpi.com</prism:rightsAgent>
		<image rdf:resource="https://pub.mdpi-res.com/img/design/mdpi-pub-logo.png?13cf3b5bd783e021?1786364601"/>
				<items>
			<rdf:Seq>
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/134" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/133" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/132" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/131" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/130" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/129" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/128" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/127" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/126" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/125" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/124" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/123" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/122" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/121" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/120" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/119" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/118" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/117" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/116" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/115" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/114" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/113" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/112" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/111" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/110" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/109" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/108" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/107" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/4/106" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/105" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/104" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/103" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/102" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/101" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/100" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/99" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/98" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/97" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/96" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/95" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/94" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/93" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/92" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/90" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/91" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/89" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/88" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/87" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/86" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/85" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/84" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/83" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/82" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/81" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/80" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/79" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/78" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/3/77" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/76" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/75" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/74" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/73" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/72" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/71" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/70" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/69" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/68" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/67" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/66" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/65" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/64" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/62" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/63" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/61" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/60" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/59" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/58" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/57" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/56" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/55" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/54" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/53" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/52" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/51" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/50" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/49" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/48" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/47" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/46" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/45" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/44" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/42" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/43" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/41" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/2/40" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/1/39" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/1/38" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/1/37" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/1/36" />
            				<rdf:li rdf:resource="https://www.mdpi.com/2624-800X/6/1/35" />
                    	</rdf:Seq>
		</items>
				<cc:license rdf:resource="https://creativecommons.org/licenses/by/4.0/" />
	</channel>

        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/134">

	<title>JCP, Vol. 6, Pages 134: Quishing: A Sociotechnical Framework for Understanding QR-Code Phishing Risks and User-Centered Protection Strategies</title>
	<link>https://www.mdpi.com/2624-800X/6/4/134</link>
	<description>The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A structured literature review and narrative synthesis were conducted using four documented search strings. Following deduplication, screening, retrieval, and full-text assessment, 27 studies were included from 71 identified records. Two reviewers independently evaluated methodological quality using six criteria. The corpus comprised 16 technical-detection studies, five user-centered or behavioral studies, two attack demonstrations or simulations, and four reviews or preventive frameworks. The mean consensus quality score was 10.04 out of 12; 19 studies were classified as high quality and eight as moderate quality. The synthesis indicates that quishing exploits the interaction of contextual legitimacy, routine scanning, limited destination visibility, and insufficient verification before navigation or disclosure of sensitive information. These findings informed an attack lifecycle, a sociotechnical model, a user security decision flow, a risk&amp;amp;ndash;protection mapping, and multilevel recommendations. These literature-derived artifacts are conceptual and heuristic rather than empirically validated. Effective mitigation therefore requires QR-specific verification mechanisms combined with behavioral and technical safeguards for users, interfaces, organizations, and platforms, followed by expert, usability, and experimental validation.</description>
	<pubDate>2026-08-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 134: Quishing: A Sociotechnical Framework for Understanding QR-Code Phishing Risks and User-Centered Protection Strategies</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/134">doi: 10.3390/jcp6040134</a></p>
	<p>Authors:
		Pedro-David Filio-Aguilar
		Rubén Mil-Martínez
		Lourdes López-García
		</p>
	<p>The widespread use of Quick Response (QR) codes increases exposure to QR-code-based phishing, or quishing. This study examines the mechanisms, user behaviors, and contextual conditions that shape QR-mediated risk from a sociotechnical perspective. A structured literature review and narrative synthesis were conducted using four documented search strings. Following deduplication, screening, retrieval, and full-text assessment, 27 studies were included from 71 identified records. Two reviewers independently evaluated methodological quality using six criteria. The corpus comprised 16 technical-detection studies, five user-centered or behavioral studies, two attack demonstrations or simulations, and four reviews or preventive frameworks. The mean consensus quality score was 10.04 out of 12; 19 studies were classified as high quality and eight as moderate quality. The synthesis indicates that quishing exploits the interaction of contextual legitimacy, routine scanning, limited destination visibility, and insufficient verification before navigation or disclosure of sensitive information. These findings informed an attack lifecycle, a sociotechnical model, a user security decision flow, a risk&amp;amp;ndash;protection mapping, and multilevel recommendations. These literature-derived artifacts are conceptual and heuristic rather than empirically validated. Effective mitigation therefore requires QR-specific verification mechanisms combined with behavioral and technical safeguards for users, interfaces, organizations, and platforms, followed by expert, usability, and experimental validation.</p>
	]]></content:encoded>

	<dc:title>Quishing: A Sociotechnical Framework for Understanding QR-Code Phishing Risks and User-Centered Protection Strategies</dc:title>
			<dc:creator>Pedro-David Filio-Aguilar</dc:creator>
			<dc:creator>Rubén Mil-Martínez</dc:creator>
			<dc:creator>Lourdes López-García</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040134</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>134</prism:startingPage>
		<prism:doi>10.3390/jcp6040134</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/134</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/133">

	<title>JCP, Vol. 6, Pages 133: Poisoning Attacks in Federated Learning: An Accountability- Oriented Survey with Centralized Learning as a Baseline</title>
	<link>https://www.mdpi.com/2624-800X/6/4/133</link>
	<description>Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains, where poisoning attacks can corrupt training data, manipulate model updates, or implant covert backdoors. This survey examines poisoning attacks in federated learning (FL), using centralized learning as a baseline to explain how distributed data, client heterogeneity, privacy-preserving aggregation, and untrusted coordination expand the threat surface. It positions prior surveys and synthesizes representative primary studies through an accountability-oriented lens focused on attribution, audit evidence, traceability, and forensic readiness. The review compares major attack classes, including data poisoning, model poisoning, backdoor insertion, server-side manipulation, Sybil behavior, collusion, and multi-round poisoning. It also evaluates countermeasures such as Byzantine-robust aggregation, anomaly detection, validation-based filtering, malicious-secure aggregation, authenticated update handling, provenance mechanisms, ledger-based evidence, and verifiable aggregation protocols. The analysis shows that robustness alone is insufficient for trustworthy FL unless defenses also preserve evidence that supports independent verification, post-incident reconstruction, and governance review. Persistent gaps remain in causal forensic attribution, privacy-preserving evidence governance, malicious-server threat modeling, scalable verifiability tooling, recovery after poisoning, and deployment-ready benchmarks. The survey concludes that accountable FL should be designed as an evidence-producing system, not merely as a privacy-preserving or attack-resistant training architecture, especially for regulated, cross-silo, and high-risk real-world deployments.</description>
	<pubDate>2026-08-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 133: Poisoning Attacks in Federated Learning: An Accountability- Oriented Survey with Centralized Learning as a Baseline</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/133">doi: 10.3390/jcp6040133</a></p>
	<p>Authors:
		Safiia Mohammed
		Dima Alhadidi
		Alioune Ngom
		</p>
	<p>Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains, where poisoning attacks can corrupt training data, manipulate model updates, or implant covert backdoors. This survey examines poisoning attacks in federated learning (FL), using centralized learning as a baseline to explain how distributed data, client heterogeneity, privacy-preserving aggregation, and untrusted coordination expand the threat surface. It positions prior surveys and synthesizes representative primary studies through an accountability-oriented lens focused on attribution, audit evidence, traceability, and forensic readiness. The review compares major attack classes, including data poisoning, model poisoning, backdoor insertion, server-side manipulation, Sybil behavior, collusion, and multi-round poisoning. It also evaluates countermeasures such as Byzantine-robust aggregation, anomaly detection, validation-based filtering, malicious-secure aggregation, authenticated update handling, provenance mechanisms, ledger-based evidence, and verifiable aggregation protocols. The analysis shows that robustness alone is insufficient for trustworthy FL unless defenses also preserve evidence that supports independent verification, post-incident reconstruction, and governance review. Persistent gaps remain in causal forensic attribution, privacy-preserving evidence governance, malicious-server threat modeling, scalable verifiability tooling, recovery after poisoning, and deployment-ready benchmarks. The survey concludes that accountable FL should be designed as an evidence-producing system, not merely as a privacy-preserving or attack-resistant training architecture, especially for regulated, cross-silo, and high-risk real-world deployments.</p>
	]]></content:encoded>

	<dc:title>Poisoning Attacks in Federated Learning: An Accountability- Oriented Survey with Centralized Learning as a Baseline</dc:title>
			<dc:creator>Safiia Mohammed</dc:creator>
			<dc:creator>Dima Alhadidi</dc:creator>
			<dc:creator>Alioune Ngom</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040133</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>133</prism:startingPage>
		<prism:doi>10.3390/jcp6040133</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/133</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/132">

	<title>JCP, Vol. 6, Pages 132: Adversarial Machine Learning for Secure and Explainable AI Systems: A Comprehensive Review</title>
	<link>https://www.mdpi.com/2624-800X/6/4/132</link>
	<description>Adversarial machine learning (AML), reinforcement learning (RL), and explainable artificial intelligence (XAI) are increasingly studied as separate problems, yet their interactions under realistic threat conditions remain poorly understood. This review addresses that gap through a systematic analysis of 207 studies selected from 4447 records following the PRISMA 2020 guidelines, covering work published between 2020 and 2026 across cybersecurity and computer vision. A taxonomy of adversarial attacks is constructed across training and inference phases, defense mechanisms are examined with attention to their documented failure modes, and robustness evaluation practices are assessed across the surveyed literature. RL is analyzed in both offensive and defensive roles. Attack agents using RL achieve evasion rates of 74&amp;amp;ndash;97% against ML-based detectors, while RL-based defenses report robustness gains of up to 3&amp;amp;times; over static baselines under comparable threat conditions. XAI receives particular attention because the field treats it almost exclusively as a transparency mechanism, whereas the reviewed evidence shows that it also functions as an attack surface. Attribution methods such as LIME, SHAP, and Grad-CAM produce unreliable explanations under adversarial perturbation, and no system in the reviewed literature certifies that attribution properties are maintained when inputs are manipulated. The review concludes with an analysis of open problems and research directions for building systems that are robust against adaptive adversaries, interpretable under operational constraints, and auditable in environments where AI accountability is a legal requirement.</description>
	<pubDate>2026-08-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 132: Adversarial Machine Learning for Secure and Explainable AI Systems: A Comprehensive Review</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/132">doi: 10.3390/jcp6040132</a></p>
	<p>Authors:
		Hajar Ouazza
		Fadoua Khennou
		Abderrahim Abdellaoui
		</p>
	<p>Adversarial machine learning (AML), reinforcement learning (RL), and explainable artificial intelligence (XAI) are increasingly studied as separate problems, yet their interactions under realistic threat conditions remain poorly understood. This review addresses that gap through a systematic analysis of 207 studies selected from 4447 records following the PRISMA 2020 guidelines, covering work published between 2020 and 2026 across cybersecurity and computer vision. A taxonomy of adversarial attacks is constructed across training and inference phases, defense mechanisms are examined with attention to their documented failure modes, and robustness evaluation practices are assessed across the surveyed literature. RL is analyzed in both offensive and defensive roles. Attack agents using RL achieve evasion rates of 74&amp;amp;ndash;97% against ML-based detectors, while RL-based defenses report robustness gains of up to 3&amp;amp;times; over static baselines under comparable threat conditions. XAI receives particular attention because the field treats it almost exclusively as a transparency mechanism, whereas the reviewed evidence shows that it also functions as an attack surface. Attribution methods such as LIME, SHAP, and Grad-CAM produce unreliable explanations under adversarial perturbation, and no system in the reviewed literature certifies that attribution properties are maintained when inputs are manipulated. The review concludes with an analysis of open problems and research directions for building systems that are robust against adaptive adversaries, interpretable under operational constraints, and auditable in environments where AI accountability is a legal requirement.</p>
	]]></content:encoded>

	<dc:title>Adversarial Machine Learning for Secure and Explainable AI Systems: A Comprehensive Review</dc:title>
			<dc:creator>Hajar Ouazza</dc:creator>
			<dc:creator>Fadoua Khennou</dc:creator>
			<dc:creator>Abderrahim Abdellaoui</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040132</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>132</prism:startingPage>
		<prism:doi>10.3390/jcp6040132</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/132</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/131">

	<title>JCP, Vol. 6, Pages 131: AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey</title>
	<link>https://www.mdpi.com/2624-800X/6/4/131</link>
	<description>Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders&amp;amp;rsquo; perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (&amp;amp;alpha; = 0.868&amp;amp;ndash;0.926; &amp;amp;omega; = 0.870&amp;amp;ndash;0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (&amp;amp;rho; = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.</description>
	<pubDate>2026-08-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 131: AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/131">doi: 10.3390/jcp6040131</a></p>
	<p>Authors:
		Mansour Almalki
		Liqaa Nawaf
		Fiona Carroll
		</p>
	<p>Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders&amp;amp;rsquo; perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (&amp;amp;alpha; = 0.868&amp;amp;ndash;0.926; &amp;amp;omega; = 0.870&amp;amp;ndash;0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (&amp;amp;rho; = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.</p>
	]]></content:encoded>

	<dc:title>AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey</dc:title>
			<dc:creator>Mansour Almalki</dc:creator>
			<dc:creator>Liqaa Nawaf</dc:creator>
			<dc:creator>Fiona Carroll</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040131</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>131</prism:startingPage>
		<prism:doi>10.3390/jcp6040131</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/131</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/130">

	<title>JCP, Vol. 6, Pages 130: Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework</title>
	<link>https://www.mdpi.com/2624-800X/6/4/130</link>
	<description>Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.</description>
	<pubDate>2026-08-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 130: Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/130">doi: 10.3390/jcp6040130</a></p>
	<p>Authors:
		Alessio Faccia
		Somkiat Tangjitsitcharoen
		</p>
	<p>Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.</p>
	]]></content:encoded>

	<dc:title>Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework</dc:title>
			<dc:creator>Alessio Faccia</dc:creator>
			<dc:creator>Somkiat Tangjitsitcharoen</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040130</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>130</prism:startingPage>
		<prism:doi>10.3390/jcp6040130</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/130</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/129">

	<title>JCP, Vol. 6, Pages 129: Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study</title>
	<link>https://www.mdpi.com/2624-800X/6/4/129</link>
	<description>Personalized phishing is difficult to defend against because messages can be tailored to a target&amp;amp;rsquo;s work, interests, and social context. Large language models may make such tailoring faster and easier, but it remains unclear whether messages produced from simple prompts are more convincing than those written by people. This 25-target pilot study compared personalized smishing messages generated by GPT-4 with messages written by novice student authors working under time constraints. Using the proposed Threshold Ranking Approach for Personalized Deception (TRAPD), participants ranked 12 messages written for them, indicated the point at which they would intend to click, explained their reasoning, and judged whether each message was authored by GPT-4 or a human. GPT-4-generated messages elicited an intention to click more often than student-authored messages (28% versus 21%), although the difference was uncertain. More broadly, our findings suggest that a simple prompt can produce personalized messages that participants found comparably convincing within the uncertainty of this pilot study. Job-related messages were significantly more likely to elicit an intention to click than hobby- or social-media-related messages. When asked whether a message was written by a human or generated by AI, participants identified the source no more accurately than chance, although the two study-specific message sets remained computationally distinguishable based on their text. Together, these findings suggest that accessible AI-assisted personalization may increase the practical scale of social-engineering threats, while also demonstrating both the value and current limitations of TRAPD for controlled and ethical comparison.</description>
	<pubDate>2026-08-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 129: Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/129">doi: 10.3390/jcp6040129</a></p>
	<p>Authors:
		Jerson Francia
		Derek Hansen
		Benjamin Schooley
		Matthew Taylor
		Shydra Valynn Murray
		Rebekah Cornelius
		Greg Snow
		</p>
	<p>Personalized phishing is difficult to defend against because messages can be tailored to a target&amp;amp;rsquo;s work, interests, and social context. Large language models may make such tailoring faster and easier, but it remains unclear whether messages produced from simple prompts are more convincing than those written by people. This 25-target pilot study compared personalized smishing messages generated by GPT-4 with messages written by novice student authors working under time constraints. Using the proposed Threshold Ranking Approach for Personalized Deception (TRAPD), participants ranked 12 messages written for them, indicated the point at which they would intend to click, explained their reasoning, and judged whether each message was authored by GPT-4 or a human. GPT-4-generated messages elicited an intention to click more often than student-authored messages (28% versus 21%), although the difference was uncertain. More broadly, our findings suggest that a simple prompt can produce personalized messages that participants found comparably convincing within the uncertainty of this pilot study. Job-related messages were significantly more likely to elicit an intention to click than hobby- or social-media-related messages. When asked whether a message was written by a human or generated by AI, participants identified the source no more accurately than chance, although the two study-specific message sets remained computationally distinguishable based on their text. Together, these findings suggest that accessible AI-assisted personalization may increase the practical scale of social-engineering threats, while also demonstrating both the value and current limitations of TRAPD for controlled and ethical comparison.</p>
	]]></content:encoded>

	<dc:title>Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study</dc:title>
			<dc:creator>Jerson Francia</dc:creator>
			<dc:creator>Derek Hansen</dc:creator>
			<dc:creator>Benjamin Schooley</dc:creator>
			<dc:creator>Matthew Taylor</dc:creator>
			<dc:creator>Shydra Valynn Murray</dc:creator>
			<dc:creator>Rebekah Cornelius</dc:creator>
			<dc:creator>Greg Snow</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040129</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-08-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-08-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>129</prism:startingPage>
		<prism:doi>10.3390/jcp6040129</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/129</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/128">

	<title>JCP, Vol. 6, Pages 128: DITA: A Dynamic Image-Based Authentication Protocol for Secure Network Communication Against Replay and Eavesdropping Attacks</title>
	<link>https://www.mdpi.com/2624-800X/6/4/128</link>
	<description>Tokens are widely used to secure client&amp;amp;ndash;server communications in systems based on automatic authentication. These tokens can be vulnerable to hacking, as an attacker can impersonate a real user by eavesdropping on their communications. In this paper, we propose a new authentication mechanism that generates a random token for each authentication. The token consists of confidential data and is encrypted using random coordinates from a securely stored confidential image. The client uses a random session key to encrypt the confidential image, then encrypts the token using randomly selected coordinates by matching ASCII character values with pixel values. The results and analysis demonstrate improved resistance to credential theft, replay attacks, and passive eavesdropping under the stated security assumptions. Even if hackers crack the encrypted token, decryption is difficult because the encryption method relies on values unrelated to the original authentication data. Comparison results also demonstrate efficiency and reliability compared to existing systems, as well as their ability to withstand brute-force attacks, with the entropy of the probability distribution being the best.</description>
	<pubDate>2026-07-22</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 128: DITA: A Dynamic Image-Based Authentication Protocol for Secure Network Communication Against Replay and Eavesdropping Attacks</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/128">doi: 10.3390/jcp6040128</a></p>
	<p>Authors:
		Seerwan Waleed Jirjees
		Alaa Q. Raheema
		Hanan Ghali Jabbar
		Ahmed M. Hasan
		Amjad Jaleel Humaidi
		</p>
	<p>Tokens are widely used to secure client&amp;amp;ndash;server communications in systems based on automatic authentication. These tokens can be vulnerable to hacking, as an attacker can impersonate a real user by eavesdropping on their communications. In this paper, we propose a new authentication mechanism that generates a random token for each authentication. The token consists of confidential data and is encrypted using random coordinates from a securely stored confidential image. The client uses a random session key to encrypt the confidential image, then encrypts the token using randomly selected coordinates by matching ASCII character values with pixel values. The results and analysis demonstrate improved resistance to credential theft, replay attacks, and passive eavesdropping under the stated security assumptions. Even if hackers crack the encrypted token, decryption is difficult because the encryption method relies on values unrelated to the original authentication data. Comparison results also demonstrate efficiency and reliability compared to existing systems, as well as their ability to withstand brute-force attacks, with the entropy of the probability distribution being the best.</p>
	]]></content:encoded>

	<dc:title>DITA: A Dynamic Image-Based Authentication Protocol for Secure Network Communication Against Replay and Eavesdropping Attacks</dc:title>
			<dc:creator>Seerwan Waleed Jirjees</dc:creator>
			<dc:creator>Alaa Q. Raheema</dc:creator>
			<dc:creator>Hanan Ghali Jabbar</dc:creator>
			<dc:creator>Ahmed M. Hasan</dc:creator>
			<dc:creator>Amjad Jaleel Humaidi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040128</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-22</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-22</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>128</prism:startingPage>
		<prism:doi>10.3390/jcp6040128</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/128</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/127">

	<title>JCP, Vol. 6, Pages 127: AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM</title>
	<link>https://www.mdpi.com/2624-800X/6/4/127</link>
	<description>As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance, operational resilience, and assurance in risk reporting. However, most prevalent cybersecurity risk frameworks vary significantly in their intent, design, and analytical approach. This makes it difficult for organizations to understand how each framework may meet their business needs. This study presents an AI-enhanced multi-criteria decision support approach for evaluating cybersecurity risk frameworks. The model incorporates machine learning-driven risk scoring as a conceptual input layer, enhancing the objectivity and analytical rigor of the comparison without executing new predictive algorithms. The methodology includes a hybrid approach of literature review, document analysis, and multi-criteria decision analysis (MCDA) to compare and rank NIST CSF, ISO 27001, FAIR, OCTAVE, and CRAMM based on eight criteria that are designed to represent modern requirements for risk frameworks, including governance, scalability, quantitative focus, and interoperability. These criteria also reflect differences in security metrics supported by each framework to provide an organized means to compare qualitative versus quantitative measurement methodologies. The results indicate that NIST CSF performs the best overall in agility, business alignment, and interoperability. ISO 27001 outperforms all others in established governance and compliance. FAIR outperforms all others in quantitative risk analysis and provides superior analytical depth that other frameworks do not offer. OCTAVE and CRAMM function well in legacy systems but lack scalability and are not well-suited for modern distributed systems. Robustness analysis shows that the ranking of NIST CSF, ISO 27001, and FAIR is consistent under different weighting combinations and industry types. The result of this research demonstrates that a combined or hybrid approach to cybersecurity risk framework selection, such as using NIST CSF with FAIR, can give organizations a more well-rounded foundation for applying machine learning-enabled risk analytics with cyber controls. This research also offers a reusable decision support tool that organizations can leverage when aligning their risk priorities to the features of cybersecurity risk frameworks.</description>
	<pubDate>2026-07-22</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 127: AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/127">doi: 10.3390/jcp6040127</a></p>
	<p>Authors:
		Oluwatosin J. Olaore
		Abeer F. Alkhwaldi
		</p>
	<p>As organizations lean more heavily on their IT systems, managing cyber risk is gaining increasing importance. Organizations are often challenged to determine which cybersecurity risk framework they should adopt. Choosing the right framework can have a significant impact on the quality of governance, operational resilience, and assurance in risk reporting. However, most prevalent cybersecurity risk frameworks vary significantly in their intent, design, and analytical approach. This makes it difficult for organizations to understand how each framework may meet their business needs. This study presents an AI-enhanced multi-criteria decision support approach for evaluating cybersecurity risk frameworks. The model incorporates machine learning-driven risk scoring as a conceptual input layer, enhancing the objectivity and analytical rigor of the comparison without executing new predictive algorithms. The methodology includes a hybrid approach of literature review, document analysis, and multi-criteria decision analysis (MCDA) to compare and rank NIST CSF, ISO 27001, FAIR, OCTAVE, and CRAMM based on eight criteria that are designed to represent modern requirements for risk frameworks, including governance, scalability, quantitative focus, and interoperability. These criteria also reflect differences in security metrics supported by each framework to provide an organized means to compare qualitative versus quantitative measurement methodologies. The results indicate that NIST CSF performs the best overall in agility, business alignment, and interoperability. ISO 27001 outperforms all others in established governance and compliance. FAIR outperforms all others in quantitative risk analysis and provides superior analytical depth that other frameworks do not offer. OCTAVE and CRAMM function well in legacy systems but lack scalability and are not well-suited for modern distributed systems. Robustness analysis shows that the ranking of NIST CSF, ISO 27001, and FAIR is consistent under different weighting combinations and industry types. The result of this research demonstrates that a combined or hybrid approach to cybersecurity risk framework selection, such as using NIST CSF with FAIR, can give organizations a more well-rounded foundation for applying machine learning-enabled risk analytics with cyber controls. This research also offers a reusable decision support tool that organizations can leverage when aligning their risk priorities to the features of cybersecurity risk frameworks.</p>
	]]></content:encoded>

	<dc:title>AI-Enhanced Multi-Criteria Decision Support for Cybersecurity Risk Framework Selection: A Machine Learning Comparative Analysis of NIST CSF, ISO 27001, FAIR, OCTAVE and CRAMM</dc:title>
			<dc:creator>Oluwatosin J. Olaore</dc:creator>
			<dc:creator>Abeer F. Alkhwaldi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040127</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-22</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-22</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>127</prism:startingPage>
		<prism:doi>10.3390/jcp6040127</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/127</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/126">

	<title>JCP, Vol. 6, Pages 126: Homomorphic Encryption as an Enabler for Secure Multi-Source Data Aggregation and Confidential Analytics</title>
	<link>https://www.mdpi.com/2624-800X/6/4/126</link>
	<description>Homomorphic Encryption plays a key role in secure multi-source data aggregation because it enables computations to be performed directly over encrypted data, allowing distributed parties to contribute sensitive information while preserving confidentiality. However, its use in this context introduces three main challenges: existing approaches often focus on specific operations rather than supporting diverse analytics across multiple encrypted data sources; key generation and management frequently rely on trusted third parties or require private keys to be shared; and TEE-based solutions may avoid trusted third parties but often require computations to be partially executed inside the trusted environment, thereby limiting deployment flexibility. To address these limitations, this work makes three main contributions: (i) the proposal of a complete framework for secure multi-source data aggregation that leverages homomorphic encryption and enables any data consumer to securely run multi-source data aggregations over data previously registered by untrusted data providers; (ii) the integration of secure enclaves for the secure generation, distribution, and management of homomorphic keys, addressing challenges related to coordinated key synchronization in multi-party aggregation environments and removing the need for a trusted third party; and (iii) the introduction of a hybrid key management protocol that combines secure enclave-based key generation with efficient key distribution and secure aggregation outside the enclave, in the data consumer, minimizing trust assumptions and computational overhead. The implementation and evaluation on small-scale aggregated datasets show that the proposed approach effectively addresses the identified challenges by providing, to the best of the authors&amp;amp;rsquo; knowledge, the first practical and privacy-preserving solution that supports different algorithms without relying on any trusted third party, while improving over existing solutions through the integration of secure enclaves and a hybrid key management protocol.</description>
	<pubDate>2026-07-21</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 126: Homomorphic Encryption as an Enabler for Secure Multi-Source Data Aggregation and Confidential Analytics</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/126">doi: 10.3390/jcp6040126</a></p>
	<p>Authors:
		Cristina Regueiro
		Julen Bernabé-Rodríguez
		Iñaki Seco-Aguirre
		Idoia Gamiz
		</p>
	<p>Homomorphic Encryption plays a key role in secure multi-source data aggregation because it enables computations to be performed directly over encrypted data, allowing distributed parties to contribute sensitive information while preserving confidentiality. However, its use in this context introduces three main challenges: existing approaches often focus on specific operations rather than supporting diverse analytics across multiple encrypted data sources; key generation and management frequently rely on trusted third parties or require private keys to be shared; and TEE-based solutions may avoid trusted third parties but often require computations to be partially executed inside the trusted environment, thereby limiting deployment flexibility. To address these limitations, this work makes three main contributions: (i) the proposal of a complete framework for secure multi-source data aggregation that leverages homomorphic encryption and enables any data consumer to securely run multi-source data aggregations over data previously registered by untrusted data providers; (ii) the integration of secure enclaves for the secure generation, distribution, and management of homomorphic keys, addressing challenges related to coordinated key synchronization in multi-party aggregation environments and removing the need for a trusted third party; and (iii) the introduction of a hybrid key management protocol that combines secure enclave-based key generation with efficient key distribution and secure aggregation outside the enclave, in the data consumer, minimizing trust assumptions and computational overhead. The implementation and evaluation on small-scale aggregated datasets show that the proposed approach effectively addresses the identified challenges by providing, to the best of the authors&amp;amp;rsquo; knowledge, the first practical and privacy-preserving solution that supports different algorithms without relying on any trusted third party, while improving over existing solutions through the integration of secure enclaves and a hybrid key management protocol.</p>
	]]></content:encoded>

	<dc:title>Homomorphic Encryption as an Enabler for Secure Multi-Source Data Aggregation and Confidential Analytics</dc:title>
			<dc:creator>Cristina Regueiro</dc:creator>
			<dc:creator>Julen Bernabé-Rodríguez</dc:creator>
			<dc:creator>Iñaki Seco-Aguirre</dc:creator>
			<dc:creator>Idoia Gamiz</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040126</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-21</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-21</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>126</prism:startingPage>
		<prism:doi>10.3390/jcp6040126</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/126</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/125">

	<title>JCP, Vol. 6, Pages 125: ML-Based SMS Messaging Spam Detection: Impacts of Text Feature Extraction Techniques</title>
	<link>https://www.mdpi.com/2624-800X/6/4/125</link>
	<description>Spam detection on SMS messaging has not received as much attention from researchers recently as the spam detection studies on emails or social media platforms. However, spam SMS messaging can be more intrusive, annoying, and harmful. Thus, detecting and filtering spam SMS messages is becoming a priority that saves human productivity. This work aims to introduce a dynamic, accurate, and efficient machine learning-based spam detection technique for SMS messaging. It aims at protecting users and businesses from spam SMS attacks. It aims to detect and identify suspicious messages that contain promotional, misleading, irrelevant, or harmful content. It primarily aims to test and evaluate the impact of feature extraction methods on the performance of machine-learning-based spam detection. Several text feature extraction techniques have been used and tested, including classical, statistical, contextual, and advanced embedding techniques. An extensive set of experiments has been presented on benchmark datasets in this field. From the comparative study, we can infer that all investigated feature extraction techniques have achieved high accuracy (90%+) on the in-domain dataset. However, their performance decreased when they were tested on the out-of-domain dataset (70%+). The advanced embedding techniques achieved the best performance across both datasets compared to the other tested feature extraction models.</description>
	<pubDate>2026-07-18</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 125: ML-Based SMS Messaging Spam Detection: Impacts of Text Feature Extraction Techniques</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/125">doi: 10.3390/jcp6040125</a></p>
	<p>Authors:
		Ahmad Ababneh
		Maram Bani Younes
		</p>
	<p>Spam detection on SMS messaging has not received as much attention from researchers recently as the spam detection studies on emails or social media platforms. However, spam SMS messaging can be more intrusive, annoying, and harmful. Thus, detecting and filtering spam SMS messages is becoming a priority that saves human productivity. This work aims to introduce a dynamic, accurate, and efficient machine learning-based spam detection technique for SMS messaging. It aims at protecting users and businesses from spam SMS attacks. It aims to detect and identify suspicious messages that contain promotional, misleading, irrelevant, or harmful content. It primarily aims to test and evaluate the impact of feature extraction methods on the performance of machine-learning-based spam detection. Several text feature extraction techniques have been used and tested, including classical, statistical, contextual, and advanced embedding techniques. An extensive set of experiments has been presented on benchmark datasets in this field. From the comparative study, we can infer that all investigated feature extraction techniques have achieved high accuracy (90%+) on the in-domain dataset. However, their performance decreased when they were tested on the out-of-domain dataset (70%+). The advanced embedding techniques achieved the best performance across both datasets compared to the other tested feature extraction models.</p>
	]]></content:encoded>

	<dc:title>ML-Based SMS Messaging Spam Detection: Impacts of Text Feature Extraction Techniques</dc:title>
			<dc:creator>Ahmad Ababneh</dc:creator>
			<dc:creator>Maram Bani Younes</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040125</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-18</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-18</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>125</prism:startingPage>
		<prism:doi>10.3390/jcp6040125</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/125</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/124">

	<title>JCP, Vol. 6, Pages 124: Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation</title>
	<link>https://www.mdpi.com/2624-800X/6/4/124</link>
	<description>Cyberattacks have become a routine feature of contemporary security environments, yet policy responses often treat cyber threats as undifferentiated, encouraging generic remedies while obscuring the distinct capabilities needed to address different forms of attack. This article develops an empirical exploratory typology of cyber threats affecting Thailand. Drawing on incident-level data, it uses multiple correspondence analysis and hierarchical clustering to classify attacks by actor type, motive, target industry, event type, event subtype, and attributed actor country. The findings reveal three distinct threat profiles: financial cybercrime, characterised by criminal actors and financial motives; hacktivist disruption, defined by protest motives, disruptive operations, and attacks on public administration; and nation-state political espionage, associated with state-linked actors, China-attributed activity, and exploitation of end hosts. The article argues that distinguishing among these threat profiles provides a more useful basis for threat prioritisation, capability development, and resource allocation than treating cyber insecurity as a single risk category.</description>
	<pubDate>2026-07-16</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 124: Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/124">doi: 10.3390/jcp6040124</a></p>
	<p>Authors:
		Jevon Dixon
		Charupol Ruangsuwan
		Issara Sereewatthanawut
		</p>
	<p>Cyberattacks have become a routine feature of contemporary security environments, yet policy responses often treat cyber threats as undifferentiated, encouraging generic remedies while obscuring the distinct capabilities needed to address different forms of attack. This article develops an empirical exploratory typology of cyber threats affecting Thailand. Drawing on incident-level data, it uses multiple correspondence analysis and hierarchical clustering to classify attacks by actor type, motive, target industry, event type, event subtype, and attributed actor country. The findings reveal three distinct threat profiles: financial cybercrime, characterised by criminal actors and financial motives; hacktivist disruption, defined by protest motives, disruptive operations, and attacks on public administration; and nation-state political espionage, associated with state-linked actors, China-attributed activity, and exploitation of end hosts. The article argues that distinguishing among these threat profiles provides a more useful basis for threat prioritisation, capability development, and resource allocation than treating cyber insecurity as a single risk category.</p>
	]]></content:encoded>

	<dc:title>Cyber Threat Profiles in Thailand: An Empirical Typology for Policy Prioritisation</dc:title>
			<dc:creator>Jevon Dixon</dc:creator>
			<dc:creator>Charupol Ruangsuwan</dc:creator>
			<dc:creator>Issara Sereewatthanawut</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040124</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-16</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-16</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>124</prism:startingPage>
		<prism:doi>10.3390/jcp6040124</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/124</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/123">

	<title>JCP, Vol. 6, Pages 123: A Hardware-Software Complex for the Reconstruction of Unmanned Aerial Vehicle Digital Traces Under Logical Data Damage Using LSTM-Based Telemetry Recovery and Multi-Source Confidence Scoring</title>
	<link>https://www.mdpi.com/2624-800X/6/4/123</link>
	<description>(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and GRYPHON cannot recover telemetry when the flight logs are logically damaged, fragmented or partially deleted and don&amp;amp;rsquo;t offer any quantitative measurement of the confidence of the recovered information. (2) Methods: A unified hardware-software complex, including a forensic workstation, a hardware write-blocker and SD/microSD/eMMC adapters; a set of software modules for extracting artifacts from files, structural parsing of DAT/BIN/CSV log, neural network reconstruction of missing telemetry using a two-layer LSTM architecture; a multi-source correlation module that combines flight logs, telemetry, media metadata and controller artifacts; a module, Confidence Score (CS), that computes a reliability measure in [0,1]; and a visualization module to generate a reconstructed trajectory on an electronic map. (3) Results: The complex has been tested on 105 flights on 10 different UAVs, 492 flight logs were gathered, 10,435 were the media item files and 624 GB was the amount of storage during acquisition. The carving stage recovers 98.7% of artifacts across the eight signature classes, the LSTM module recovers all five telemetry parameters with R2&amp;amp;gt;0.99 and a single-step horizontal position error of 6.8 m, which is reduced to 4.7 m after multi-source correlation (below the 5 m operational target consistent with consumer-GNSS precision); the dependence on gap length is described by the empirical growth law &amp;amp;epsilon;horiz&amp;amp;asymp;4.84&amp;amp;middot;G1.44 m; 46.8% of recovered records fall within the high-confidence band of CS&amp;amp;ge;0.8; and the complex outperforms DatCon, Autopsy + DJI Analyzer and GRYPHON by 22&amp;amp;ndash;35 percentage points in end-to-end record recovery and by a factor of &amp;amp;sim;2.6 in mean horizontal error (4.7 m vs. 12.4&amp;amp;ndash;18.7 m). (4) Conclusions: The combined write-blocked hardware acquisition, neural reconstruction of telemetry, and quantitative confidence index provides a forensically structured pipeline that fills an existing gap in UAV digital forensics; we note that technical reconstruction accuracy does not by itself confer legal admissibility, which remains a function of jurisdiction-specific evidentiary standards discussed in the Conclusions.</description>
	<pubDate>2026-07-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 123: A Hardware-Software Complex for the Reconstruction of Unmanned Aerial Vehicle Digital Traces Under Logical Data Damage Using LSTM-Based Telemetry Recovery and Multi-Source Confidence Scoring</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/123">doi: 10.3390/jcp6040123</a></p>
	<p>Authors:
		Azamat Baibussinov
		Madi Shayakhmetov
		Leila Rzayeva
		Kaisarbek Yesbergenov
		</p>
	<p>(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and GRYPHON cannot recover telemetry when the flight logs are logically damaged, fragmented or partially deleted and don&amp;amp;rsquo;t offer any quantitative measurement of the confidence of the recovered information. (2) Methods: A unified hardware-software complex, including a forensic workstation, a hardware write-blocker and SD/microSD/eMMC adapters; a set of software modules for extracting artifacts from files, structural parsing of DAT/BIN/CSV log, neural network reconstruction of missing telemetry using a two-layer LSTM architecture; a multi-source correlation module that combines flight logs, telemetry, media metadata and controller artifacts; a module, Confidence Score (CS), that computes a reliability measure in [0,1]; and a visualization module to generate a reconstructed trajectory on an electronic map. (3) Results: The complex has been tested on 105 flights on 10 different UAVs, 492 flight logs were gathered, 10,435 were the media item files and 624 GB was the amount of storage during acquisition. The carving stage recovers 98.7% of artifacts across the eight signature classes, the LSTM module recovers all five telemetry parameters with R2&amp;amp;gt;0.99 and a single-step horizontal position error of 6.8 m, which is reduced to 4.7 m after multi-source correlation (below the 5 m operational target consistent with consumer-GNSS precision); the dependence on gap length is described by the empirical growth law &amp;amp;epsilon;horiz&amp;amp;asymp;4.84&amp;amp;middot;G1.44 m; 46.8% of recovered records fall within the high-confidence band of CS&amp;amp;ge;0.8; and the complex outperforms DatCon, Autopsy + DJI Analyzer and GRYPHON by 22&amp;amp;ndash;35 percentage points in end-to-end record recovery and by a factor of &amp;amp;sim;2.6 in mean horizontal error (4.7 m vs. 12.4&amp;amp;ndash;18.7 m). (4) Conclusions: The combined write-blocked hardware acquisition, neural reconstruction of telemetry, and quantitative confidence index provides a forensically structured pipeline that fills an existing gap in UAV digital forensics; we note that technical reconstruction accuracy does not by itself confer legal admissibility, which remains a function of jurisdiction-specific evidentiary standards discussed in the Conclusions.</p>
	]]></content:encoded>

	<dc:title>A Hardware-Software Complex for the Reconstruction of Unmanned Aerial Vehicle Digital Traces Under Logical Data Damage Using LSTM-Based Telemetry Recovery and Multi-Source Confidence Scoring</dc:title>
			<dc:creator>Azamat Baibussinov</dc:creator>
			<dc:creator>Madi Shayakhmetov</dc:creator>
			<dc:creator>Leila Rzayeva</dc:creator>
			<dc:creator>Kaisarbek Yesbergenov</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040123</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>123</prism:startingPage>
		<prism:doi>10.3390/jcp6040123</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/123</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/122">

	<title>JCP, Vol. 6, Pages 122: TALOS: An Ultra-Efficient Area-Space 6G CryptoProcessor Leveraging Reusable Hardware Security Modules</title>
	<link>https://www.mdpi.com/2624-800X/6/4/122</link>
	<description>This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting heterogeneous strong symmetric primitives without duplicating complete cipher cores. TALOS combines a Hierarchical Common Data Path (HCDP) with a three-tier cryptographic encapsulation model spanning AES-256, Snow 5G/SNOW-V-class, and ZUC-256. Tier-1 captures native nonlinear substitutions, Tier-2 compiles bounded arithmetic nonlinearities into exact micro-S-boxes, and Tier-3 consolidates shared permutation, XOR, affine, diffusion, and state-transport fabrics. This decomposition preserves cipher correctness while exposing realistic sharing opportunities across substitution, arithmetic, and linear transport layers. The architecture also supports confidentiality processing and integration with integrity- and authentication-oriented service logic through a common control/resource framework. Compared with monolithic universal-box or loosely aggregated multi-core approaches, TALOS provides a disciplined, RTL-oriented taxonomy for crypto-agile symmetric-core hardware. The proposed framework advances 6G cryptographic hardware design by combining operator-exact reuse, architectural scalability, and implementation-oriented efficiency within a single CryptoProcessor paradigm.</description>
	<pubDate>2026-07-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 122: TALOS: An Ultra-Efficient Area-Space 6G CryptoProcessor Leveraging Reusable Hardware Security Modules</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/122">doi: 10.3390/jcp6040122</a></p>
	<p>Authors:
		Anastasios N. Bikos
		</p>
	<p>This paper presents TALOS, a unified reusable 6G CryptoProcessor architecture for high-assurance symmetric security services under a 256-bit private-key baseline. The design addresses a core hardware challenge in future mobile systems: supporting heterogeneous strong symmetric primitives without duplicating complete cipher cores. TALOS combines a Hierarchical Common Data Path (HCDP) with a three-tier cryptographic encapsulation model spanning AES-256, Snow 5G/SNOW-V-class, and ZUC-256. Tier-1 captures native nonlinear substitutions, Tier-2 compiles bounded arithmetic nonlinearities into exact micro-S-boxes, and Tier-3 consolidates shared permutation, XOR, affine, diffusion, and state-transport fabrics. This decomposition preserves cipher correctness while exposing realistic sharing opportunities across substitution, arithmetic, and linear transport layers. The architecture also supports confidentiality processing and integration with integrity- and authentication-oriented service logic through a common control/resource framework. Compared with monolithic universal-box or loosely aggregated multi-core approaches, TALOS provides a disciplined, RTL-oriented taxonomy for crypto-agile symmetric-core hardware. The proposed framework advances 6G cryptographic hardware design by combining operator-exact reuse, architectural scalability, and implementation-oriented efficiency within a single CryptoProcessor paradigm.</p>
	]]></content:encoded>

	<dc:title>TALOS: An Ultra-Efficient Area-Space 6G CryptoProcessor Leveraging Reusable Hardware Security Modules</dc:title>
			<dc:creator>Anastasios N. Bikos</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040122</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>122</prism:startingPage>
		<prism:doi>10.3390/jcp6040122</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/122</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/121">

	<title>JCP, Vol. 6, Pages 121: Text-to-Unlearn: Robust Concept Removal in GANs via Text Prompts</title>
	<link>https://www.mdpi.com/2624-800X/6/4/121</link>
	<description>State-of-the-art generative models exhibit powerful image-generation capabilities, raising ethical and legal challenges for service providers. Consequently, Content Removal Techniques (CRTs) have emerged to control outputs without requiring full retraining. However, the problem of unlearning in Generative Adversarial Networks (GANs) remains largely unexplored. We propose Text-to-Unlearn, a novel framework that selectively unlearns concepts from pre-trained GANs using only text prompts, enabling feature and identity unlearning, as well as fine-grained tasks such as expression and multi-attribute removal in models trained on human faces. Our approach leverages natural language descriptions to guide unlearning without additional datasets or supervised finetuning, offering a scalable solution. To evaluate the effectiveness of our method, we introduce an automated unlearning assessment method using state-of-the-art image&amp;amp;ndash;text alignment metrics and propose a new metric: degree of unlearning. Additionally, we assess robustness by introducing adversarial attacks to subvert unlearning. Our results demonstrate that Text-to-Unlearn achieves robust unlearning, resisting adversarial attempts to recover erased concepts while preserving model utility. To our knowledge, this is the first cross-modal unlearning framework for GANs, advancing the management of generative model behavior.</description>
	<pubDate>2026-07-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 121: Text-to-Unlearn: Robust Concept Removal in GANs via Text Prompts</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/121">doi: 10.3390/jcp6040121</a></p>
	<p>Authors:
		Piyush Nagasubramaniam
		Neeraj Karamchandani
		Chen Wu
		Sencun Zhu
		</p>
	<p>State-of-the-art generative models exhibit powerful image-generation capabilities, raising ethical and legal challenges for service providers. Consequently, Content Removal Techniques (CRTs) have emerged to control outputs without requiring full retraining. However, the problem of unlearning in Generative Adversarial Networks (GANs) remains largely unexplored. We propose Text-to-Unlearn, a novel framework that selectively unlearns concepts from pre-trained GANs using only text prompts, enabling feature and identity unlearning, as well as fine-grained tasks such as expression and multi-attribute removal in models trained on human faces. Our approach leverages natural language descriptions to guide unlearning without additional datasets or supervised finetuning, offering a scalable solution. To evaluate the effectiveness of our method, we introduce an automated unlearning assessment method using state-of-the-art image&amp;amp;ndash;text alignment metrics and propose a new metric: degree of unlearning. Additionally, we assess robustness by introducing adversarial attacks to subvert unlearning. Our results demonstrate that Text-to-Unlearn achieves robust unlearning, resisting adversarial attempts to recover erased concepts while preserving model utility. To our knowledge, this is the first cross-modal unlearning framework for GANs, advancing the management of generative model behavior.</p>
	]]></content:encoded>

	<dc:title>Text-to-Unlearn: Robust Concept Removal in GANs via Text Prompts</dc:title>
			<dc:creator>Piyush Nagasubramaniam</dc:creator>
			<dc:creator>Neeraj Karamchandani</dc:creator>
			<dc:creator>Chen Wu</dc:creator>
			<dc:creator>Sencun Zhu</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040121</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>121</prism:startingPage>
		<prism:doi>10.3390/jcp6040121</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/121</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/120">

	<title>JCP, Vol. 6, Pages 120: Encryption Failure in Portable Device Storage: Technical-Operational Analysis of the Veterans Affairs Data Breach</title>
	<link>https://www.mdpi.com/2624-800X/6/4/120</link>
	<description>This case study examines an encryption failure incident involving the exposure of sensitive personal data within a governmental information system environment. The analysis is based on the well-documented data breach that occurred within the U.S. Department of Veterans Affairs, in which a government employee stored a large dataset containing veterans&amp;amp;rsquo; personal information on a portable laptop device that lacked adequate encryption protection. Following the theft of the device from the employee&amp;amp;rsquo;s residence, the personal records of approximately 26.5 million individuals were placed at risk of unauthorized exposure. Rather than interpreting the incident as an isolated technical failure, this study analyzes it through the Swiss cheese model, proposed by James Reason, and formalizes them as Portable Device Data Exposure Chain (PDDEC), showing that the breach resulted from the alignment of weaknesses across multiple layers of defense. The model is compared with two post-2010 endpoint-loss incidents to provide a limited historical back-test and is positioned against data-lifecycle, defense-in-depth, and Zero Trust approaches. The analysis shows that full-disk encryption is now a baseline control rather than a sufficient or novel solution. Hardware-backed key protection, verified boot, endpoint compliance, data-loss prevention, continuous monitoring, and controls for data in use are also required because encryption can be weakened by poor recovery-key governance, authenticated malware, sleep-state memory exposure, cold-boot attacks, and direct-memory-access attacks. The study contributes a reproducible control-point model for analyzing how sensitive data becomes exposed when it is moved beyond centrally managed environments, while explicitly limiting its generalizability to analytically comparable endpoint-loss scenarios.</description>
	<pubDate>2026-07-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 120: Encryption Failure in Portable Device Storage: Technical-Operational Analysis of the Veterans Affairs Data Breach</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/120">doi: 10.3390/jcp6040120</a></p>
	<p>Authors:
		Pedro A. R. S. Costa
		Antonio Goncalves
		Mario Monteiro Marques
		</p>
	<p>This case study examines an encryption failure incident involving the exposure of sensitive personal data within a governmental information system environment. The analysis is based on the well-documented data breach that occurred within the U.S. Department of Veterans Affairs, in which a government employee stored a large dataset containing veterans&amp;amp;rsquo; personal information on a portable laptop device that lacked adequate encryption protection. Following the theft of the device from the employee&amp;amp;rsquo;s residence, the personal records of approximately 26.5 million individuals were placed at risk of unauthorized exposure. Rather than interpreting the incident as an isolated technical failure, this study analyzes it through the Swiss cheese model, proposed by James Reason, and formalizes them as Portable Device Data Exposure Chain (PDDEC), showing that the breach resulted from the alignment of weaknesses across multiple layers of defense. The model is compared with two post-2010 endpoint-loss incidents to provide a limited historical back-test and is positioned against data-lifecycle, defense-in-depth, and Zero Trust approaches. The analysis shows that full-disk encryption is now a baseline control rather than a sufficient or novel solution. Hardware-backed key protection, verified boot, endpoint compliance, data-loss prevention, continuous monitoring, and controls for data in use are also required because encryption can be weakened by poor recovery-key governance, authenticated malware, sleep-state memory exposure, cold-boot attacks, and direct-memory-access attacks. The study contributes a reproducible control-point model for analyzing how sensitive data becomes exposed when it is moved beyond centrally managed environments, while explicitly limiting its generalizability to analytically comparable endpoint-loss scenarios.</p>
	]]></content:encoded>

	<dc:title>Encryption Failure in Portable Device Storage: Technical-Operational Analysis of the Veterans Affairs Data Breach</dc:title>
			<dc:creator>Pedro A. R. S. Costa</dc:creator>
			<dc:creator>Antonio Goncalves</dc:creator>
			<dc:creator>Mario Monteiro Marques</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040120</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>120</prism:startingPage>
		<prism:doi>10.3390/jcp6040120</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/120</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/119">

	<title>JCP, Vol. 6, Pages 119: Agile Resilience in Security for Small and Medium-Sized Businesses</title>
	<link>https://www.mdpi.com/2624-800X/6/4/119</link>
	<description>Small businesses face many of the same cyber threats as larger organisations but often lack equivalent budgets, specialist personnel, and formal security operations capability. This paper proposes Agile Resilience in Security for Enterprises (ARISE), a lightweight cyber-resilience framework and maturity model designed for resource-constrained small businesses. ARISE adapts prevention, detection, response, and recovery into an agile lifecycle so that organisations can improve cybersecurity maturity progressively rather than through a single large compliance project. The study combines framework benchmarking, a practical interpretive case used to position ARISE within reflexive thematic analysis (RTA) and maturity-model benchmarking, and quantitative machine-learning experiments using the UNSW-NB15 intrusion-detection dataset. The experimental component evaluates selected Weka classifiers, including J48, JRip, Random Tree, Decision Table, and Naive Bayes, to examine whether low-cost tools can support network intrusion detection in small-business contexts. Results show very high aggregate performance for tree- and rule-based classifiers, while class-level outcomes highlight that overall accuracy can conceal weak detection of minority attack categories. The paper therefore positions ARISE as a practical, iterative, and standards-informed framework that complements, rather than replaces, enterprise-grade security operations. Its value lies in giving small businesses an accessible starting point for identifying risk, selecting controls, improving cyber awareness, detecting suspicious activity, responding consistently, and learning from incidents.</description>
	<pubDate>2026-07-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 119: Agile Resilience in Security for Small and Medium-Sized Businesses</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/119">doi: 10.3390/jcp6040119</a></p>
	<p>Authors:
		Selahattin Hürol Türen
		Kenneth Eustace
		Rafiqul Islam
		Geoffrey Fellows
		</p>
	<p>Small businesses face many of the same cyber threats as larger organisations but often lack equivalent budgets, specialist personnel, and formal security operations capability. This paper proposes Agile Resilience in Security for Enterprises (ARISE), a lightweight cyber-resilience framework and maturity model designed for resource-constrained small businesses. ARISE adapts prevention, detection, response, and recovery into an agile lifecycle so that organisations can improve cybersecurity maturity progressively rather than through a single large compliance project. The study combines framework benchmarking, a practical interpretive case used to position ARISE within reflexive thematic analysis (RTA) and maturity-model benchmarking, and quantitative machine-learning experiments using the UNSW-NB15 intrusion-detection dataset. The experimental component evaluates selected Weka classifiers, including J48, JRip, Random Tree, Decision Table, and Naive Bayes, to examine whether low-cost tools can support network intrusion detection in small-business contexts. Results show very high aggregate performance for tree- and rule-based classifiers, while class-level outcomes highlight that overall accuracy can conceal weak detection of minority attack categories. The paper therefore positions ARISE as a practical, iterative, and standards-informed framework that complements, rather than replaces, enterprise-grade security operations. Its value lies in giving small businesses an accessible starting point for identifying risk, selecting controls, improving cyber awareness, detecting suspicious activity, responding consistently, and learning from incidents.</p>
	]]></content:encoded>

	<dc:title>Agile Resilience in Security for Small and Medium-Sized Businesses</dc:title>
			<dc:creator>Selahattin Hürol Türen</dc:creator>
			<dc:creator>Kenneth Eustace</dc:creator>
			<dc:creator>Rafiqul Islam</dc:creator>
			<dc:creator>Geoffrey Fellows</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040119</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>119</prism:startingPage>
		<prism:doi>10.3390/jcp6040119</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/119</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/118">

	<title>JCP, Vol. 6, Pages 118: Proof-of-Exploit: Cryptographically Verified LLM Cybersecurity Evaluation via Tiered Risk Metrics in the Operational-Risk Framework</title>
	<link>https://www.mdpi.com/2624-800X/6/4/118</link>
	<description>Existing Large Language Model cybersecurity evaluations rely on text-based plausibility scoring systems that fail to validate operational exploit viability. In this paper, we present the Operational Risk Framework (ORF), advancing beyond our prior MalcodeEval work through three (3) innovations: (1) ECDSA-P384 cryptographic execution validation providing non-repudiable proof-of-exploit, (2) MITRE ATT&amp;amp;amp;CK-aligned tiered scoring with CVSS v4.0-derived severity weights, (3) and six-phase progressive validation tracking 217 Indicators of Compromise within isolated VM environments. The utility of this framework is demonstrated through detailed case studies that have revealed granular disparities in capabilities and multi-stage attack progression, often obscured by standard pass/fail binary metrics. This work contributes systematic LLM-to-CVSS mapping and open cryptographic protocols toward NIST AI RMF 2.0 development.</description>
	<pubDate>2026-07-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 118: Proof-of-Exploit: Cryptographically Verified LLM Cybersecurity Evaluation via Tiered Risk Metrics in the Operational-Risk Framework</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/118">doi: 10.3390/jcp6040118</a></p>
	<p>Authors:
		Joshua White
		Kara Zaffarano
		John Stacy
		Xiaomin Bian
		</p>
	<p>Existing Large Language Model cybersecurity evaluations rely on text-based plausibility scoring systems that fail to validate operational exploit viability. In this paper, we present the Operational Risk Framework (ORF), advancing beyond our prior MalcodeEval work through three (3) innovations: (1) ECDSA-P384 cryptographic execution validation providing non-repudiable proof-of-exploit, (2) MITRE ATT&amp;amp;amp;CK-aligned tiered scoring with CVSS v4.0-derived severity weights, (3) and six-phase progressive validation tracking 217 Indicators of Compromise within isolated VM environments. The utility of this framework is demonstrated through detailed case studies that have revealed granular disparities in capabilities and multi-stage attack progression, often obscured by standard pass/fail binary metrics. This work contributes systematic LLM-to-CVSS mapping and open cryptographic protocols toward NIST AI RMF 2.0 development.</p>
	]]></content:encoded>

	<dc:title>Proof-of-Exploit: Cryptographically Verified LLM Cybersecurity Evaluation via Tiered Risk Metrics in the Operational-Risk Framework</dc:title>
			<dc:creator>Joshua White</dc:creator>
			<dc:creator>Kara Zaffarano</dc:creator>
			<dc:creator>John Stacy</dc:creator>
			<dc:creator>Xiaomin Bian</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040118</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>118</prism:startingPage>
		<prism:doi>10.3390/jcp6040118</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/118</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/117">

	<title>JCP, Vol. 6, Pages 117: Microservice-Oriented Cyber Deception Platform with Containerized Honeypots and Real-Time Telemetry</title>
	<link>https://www.mdpi.com/2624-800X/6/4/117</link>
	<description>The growing reliance on cyber deception as a defensive mechanism has revealed persistent limitations in existing deception infrastructures, particularly in their ability to scale, adapt, and provide continuous observability under realistic adversarial workloads. Conventional honeypot deployments are predominantly monolithic and statically configured, which constrains their responsiveness to dynamic attack conditions and limits their applicability in contemporary distributed environments. This work presents a microservice-oriented cyber deception platform that reconceptualizes deception infrastructure as a composition of loosely coupled, independently deployable services. The platform integrates containerized honeypots, a lightweight API-driven orchestration layer, and a centralized telemetry pipeline to enable rapid instantiation, dynamic reconfiguration, and high-resolution monitoring of attacker interactions. Unlike prior approaches that treat deployment, orchestration, and monitoring as separate concerns, the proposed design explicitly unifies these components within a single, measurable system architecture. To support principled reasoning about system behaviour, the paper introduces first-order analytical models that characterize deployment latency, resource utilisation, telemetry throughput, and operational cost as functions of attacker concurrency. These models are not intended as exact predictors, but as tractable abstractions that enable interpretation of system performance and guide capacity planning. Model parameters are empirically derived and validated through controlled experimentation. Evaluation is conducted within a reproducible cyber-range environment using scripted adversarial workloads that emulate reconnaissance, authentication attempts, and sustained interactive sessions. The results indicate that containerised deployment reduces instantiation latency to approximately 1.2 s under warm-start conditions, compared to tens of seconds for virtual machine-based baselines. Resource utilisation exhibits approximately linear scaling under moderate concurrency, while the telemetry pipeline sustains ingestion rates exceeding 18,000 events per minute without observable loss. Stress testing further reveals that telemetry processing, rather than orchestration, constitutes the primary scalability bottleneck. These findings suggest that microservice-based architectures can provide a viable and extensible infrastructure substrate for cyber deception, supporting both operational deployment and integration with higher-level adaptive and learning-based defence mechanisms. The contribution of this work lies not in introducing new deception strategies, but in enabling their practical realisation through a scalable and observable system design.</description>
	<pubDate>2026-07-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 117: Microservice-Oriented Cyber Deception Platform with Containerized Honeypots and Real-Time Telemetry</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/117">doi: 10.3390/jcp6040117</a></p>
	<p>Authors:
		Muhammad Shahzad
		Muhsin Hassanu Saleh
		</p>
	<p>The growing reliance on cyber deception as a defensive mechanism has revealed persistent limitations in existing deception infrastructures, particularly in their ability to scale, adapt, and provide continuous observability under realistic adversarial workloads. Conventional honeypot deployments are predominantly monolithic and statically configured, which constrains their responsiveness to dynamic attack conditions and limits their applicability in contemporary distributed environments. This work presents a microservice-oriented cyber deception platform that reconceptualizes deception infrastructure as a composition of loosely coupled, independently deployable services. The platform integrates containerized honeypots, a lightweight API-driven orchestration layer, and a centralized telemetry pipeline to enable rapid instantiation, dynamic reconfiguration, and high-resolution monitoring of attacker interactions. Unlike prior approaches that treat deployment, orchestration, and monitoring as separate concerns, the proposed design explicitly unifies these components within a single, measurable system architecture. To support principled reasoning about system behaviour, the paper introduces first-order analytical models that characterize deployment latency, resource utilisation, telemetry throughput, and operational cost as functions of attacker concurrency. These models are not intended as exact predictors, but as tractable abstractions that enable interpretation of system performance and guide capacity planning. Model parameters are empirically derived and validated through controlled experimentation. Evaluation is conducted within a reproducible cyber-range environment using scripted adversarial workloads that emulate reconnaissance, authentication attempts, and sustained interactive sessions. The results indicate that containerised deployment reduces instantiation latency to approximately 1.2 s under warm-start conditions, compared to tens of seconds for virtual machine-based baselines. Resource utilisation exhibits approximately linear scaling under moderate concurrency, while the telemetry pipeline sustains ingestion rates exceeding 18,000 events per minute without observable loss. Stress testing further reveals that telemetry processing, rather than orchestration, constitutes the primary scalability bottleneck. These findings suggest that microservice-based architectures can provide a viable and extensible infrastructure substrate for cyber deception, supporting both operational deployment and integration with higher-level adaptive and learning-based defence mechanisms. The contribution of this work lies not in introducing new deception strategies, but in enabling their practical realisation through a scalable and observable system design.</p>
	]]></content:encoded>

	<dc:title>Microservice-Oriented Cyber Deception Platform with Containerized Honeypots and Real-Time Telemetry</dc:title>
			<dc:creator>Muhammad Shahzad</dc:creator>
			<dc:creator>Muhsin Hassanu Saleh</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040117</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>117</prism:startingPage>
		<prism:doi>10.3390/jcp6040117</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/117</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/116">

	<title>JCP, Vol. 6, Pages 116: Digital Forensics and Phishing Defense: A Literature Review and Gap Analysis</title>
	<link>https://www.mdpi.com/2624-800X/6/4/116</link>
	<description>Phishing remains a widespread and evolving cyber threat that targets human and technical vulnerabilities across email, web, mobile, and social media. Meanwhile, digital forensics has developed into a standards-driven discipline dedicated to identifying, preserving, analysing, and presenting digital evidence. Despite overlapping goals, phishing detection research and digital forensics typically operate separately. Detection efforts emphasise classification accuracy and rapid mitigation, while forensic practices prioritise evidential integrity and incident reconstruction. The analysis suggests that incorporating forensic-quality artefacts, such as Simple Mail Transfer Protocol (SMTP) headers, Domain Name System (DNS) and Transport Layer Security (TLS) traces, memory dumps, behavioural logs, metadata, and provenance records, may support attribution analysis, interpretability, and more evidentially robust incident reporting. It covers email, network, endpoint, behavioural, and legal areas to identify common shortcomings in forensic readiness, provenance preservation, and reproducibility. Based on these insights, we propose a conceptual framework that redefines digital forensics as a proactive, ongoing capability integrated into operational phishing defences. The review highlights gaps in research, such as the limited availability and validation of AI-generated phishing datasets, privacy-aware evidence management and deanonymization risks in evidence correlation, and automated workflows for handling evidence. It also suggests future directions for integrating forensic reasoning into advanced phishing mitigation systems.</description>
	<pubDate>2026-07-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 116: Digital Forensics and Phishing Defense: A Literature Review and Gap Analysis</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/116">doi: 10.3390/jcp6040116</a></p>
	<p>Authors:
		Indah Octaviani Laleb
		John Le
		Chau Nguyen
		</p>
	<p>Phishing remains a widespread and evolving cyber threat that targets human and technical vulnerabilities across email, web, mobile, and social media. Meanwhile, digital forensics has developed into a standards-driven discipline dedicated to identifying, preserving, analysing, and presenting digital evidence. Despite overlapping goals, phishing detection research and digital forensics typically operate separately. Detection efforts emphasise classification accuracy and rapid mitigation, while forensic practices prioritise evidential integrity and incident reconstruction. The analysis suggests that incorporating forensic-quality artefacts, such as Simple Mail Transfer Protocol (SMTP) headers, Domain Name System (DNS) and Transport Layer Security (TLS) traces, memory dumps, behavioural logs, metadata, and provenance records, may support attribution analysis, interpretability, and more evidentially robust incident reporting. It covers email, network, endpoint, behavioural, and legal areas to identify common shortcomings in forensic readiness, provenance preservation, and reproducibility. Based on these insights, we propose a conceptual framework that redefines digital forensics as a proactive, ongoing capability integrated into operational phishing defences. The review highlights gaps in research, such as the limited availability and validation of AI-generated phishing datasets, privacy-aware evidence management and deanonymization risks in evidence correlation, and automated workflows for handling evidence. It also suggests future directions for integrating forensic reasoning into advanced phishing mitigation systems.</p>
	]]></content:encoded>

	<dc:title>Digital Forensics and Phishing Defense: A Literature Review and Gap Analysis</dc:title>
			<dc:creator>Indah Octaviani Laleb</dc:creator>
			<dc:creator>John Le</dc:creator>
			<dc:creator>Chau Nguyen</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040116</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>116</prism:startingPage>
		<prism:doi>10.3390/jcp6040116</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/116</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/115">

	<title>JCP, Vol. 6, Pages 115: Security by Light in Sensor Networks: A Structured Review of Optical and Photonic Security Mechanisms</title>
	<link>https://www.mdpi.com/2624-800X/6/4/115</link>
	<description>Sensor networks increasingly combine exposed sensing nodes, optical communication, photonic hardware, near-sensor inference, and distributed infrastructure monitoring. This changes the security problem from protecting packets alone to establishing device provenance, measurement integrity, link confidentiality and availability, trustworthy inference, physical situational awareness, lifecycle control, and governance. This structured review with documented scoping searches examines security by light: mechanisms in which optical or photonic phenomena directly realize, constrain, compute, or observe a security-relevant function. The review synthesizes screened evidence across photonic roots of trust, visible-light communication and LiFi security, photonic intelligence, reservoir and chaotic photonics, and distributed photonic sensing infrastructure. Searches across arXiv, IEEE Xplore, ACM Digital Library, and Scopus yielded 228 deduplicated candidate records, of which 187 were retained as core evidence and eight as contextual evidence. To avoid overstating heterogeneous photonic work, retained records were separated into direct security evidence, security-adjacent capability evidence, background/framework evidence, and excluded records. The central result is architectural: light-enabled mechanisms are most defensible when they provide explicit, confidence-rated evidence to conventional security engineering. In this paper, confidence-rated evidence means evidence whose security interpretation is tied to a stated asset, adversary or failure mode, evidence role, validation setting, robustness limits, deployment fit, and reproducibility condition. This avoids treating optical novelty, spatial confinement, analog complexity, or high-dimensional dynamics as assurance by themselves. The paper develops an auditable taxonomy, evidence appraisal rubric, mechanism-family synthesis, integration architecture, maturity analysis, and research agenda for incorporating light-enabled mechanisms into secure sensor-networked systems.</description>
	<pubDate>2026-07-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 115: Security by Light in Sensor Networks: A Structured Review of Optical and Photonic Security Mechanisms</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/115">doi: 10.3390/jcp6040115</a></p>
	<p>Authors:
		Ramin Irani
		Siamak Khatibi
		Shahryar Eivazzadeh
		</p>
	<p>Sensor networks increasingly combine exposed sensing nodes, optical communication, photonic hardware, near-sensor inference, and distributed infrastructure monitoring. This changes the security problem from protecting packets alone to establishing device provenance, measurement integrity, link confidentiality and availability, trustworthy inference, physical situational awareness, lifecycle control, and governance. This structured review with documented scoping searches examines security by light: mechanisms in which optical or photonic phenomena directly realize, constrain, compute, or observe a security-relevant function. The review synthesizes screened evidence across photonic roots of trust, visible-light communication and LiFi security, photonic intelligence, reservoir and chaotic photonics, and distributed photonic sensing infrastructure. Searches across arXiv, IEEE Xplore, ACM Digital Library, and Scopus yielded 228 deduplicated candidate records, of which 187 were retained as core evidence and eight as contextual evidence. To avoid overstating heterogeneous photonic work, retained records were separated into direct security evidence, security-adjacent capability evidence, background/framework evidence, and excluded records. The central result is architectural: light-enabled mechanisms are most defensible when they provide explicit, confidence-rated evidence to conventional security engineering. In this paper, confidence-rated evidence means evidence whose security interpretation is tied to a stated asset, adversary or failure mode, evidence role, validation setting, robustness limits, deployment fit, and reproducibility condition. This avoids treating optical novelty, spatial confinement, analog complexity, or high-dimensional dynamics as assurance by themselves. The paper develops an auditable taxonomy, evidence appraisal rubric, mechanism-family synthesis, integration architecture, maturity analysis, and research agenda for incorporating light-enabled mechanisms into secure sensor-networked systems.</p>
	]]></content:encoded>

	<dc:title>Security by Light in Sensor Networks: A Structured Review of Optical and Photonic Security Mechanisms</dc:title>
			<dc:creator>Ramin Irani</dc:creator>
			<dc:creator>Siamak Khatibi</dc:creator>
			<dc:creator>Shahryar Eivazzadeh</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040115</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>115</prism:startingPage>
		<prism:doi>10.3390/jcp6040115</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/115</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/114">

	<title>JCP, Vol. 6, Pages 114: Privacy Usability Evaluation of IoT Smart Home Companion Application: A Pilot Study of the ABCDE Privacy Framework with an Industrial Multidisciplinary Team</title>
	<link>https://www.mdpi.com/2624-800X/6/4/114</link>
	<description>Privacy usability in IoT smart home companion applications remains an underexplored domain despite mounting regulatory requirements and accelerating user adoption. Heuristic evaluation offers a scalable pathway to privacy usability assessment, yet validated frameworks for applying such methods are scarce. This study presents the first empirical application of the ABCDE Privacy Framework, a ten-heuristic instrument grounded in Nielsen&amp;amp;rsquo;s usability principles and Privacy by Design, to an IoT companion application developed with a major European home appliance manufacturer. A structured workshop was conducted with a multidisciplinary team of seven participants (five industry professionals and two researchers) following a two-round protocol: a qualitative heuristic discussion phase (Round 1) and an individual scoring phase (Round 2). Data were analysed through MAXQDA (VERBI Software, Berlin, Germany). Average heuristic scores ranged from 3.6 (H9: error recovery) to 4.8 (H6: recognition; H10: documentation), with an overall mean of 4.32. Six second-order themes were identified, including Transparency Asymmetry, Centralised but Decontextualised Privacy, and Shared Household Complexity. This first pilot application suggests that the ABCDE Privacy Framework is feasible, time-efficient, and analytically productive in this industrial context, generating design-relevant insights and enabling cross-role team alignment within a two-hour session. These preliminary findings indicate its potential as a tool for Privacy-by-Design practice in IoT product development and provide a basis for future replication and validation.</description>
	<pubDate>2026-07-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 114: Privacy Usability Evaluation of IoT Smart Home Companion Application: A Pilot Study of the ABCDE Privacy Framework with an Industrial Multidisciplinary Team</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/114">doi: 10.3390/jcp6040114</a></p>
	<p>Authors:
		Amparo Coiduras-Sanagustín
		Eduardo Manchado-Pérez
		César García-Hernández
		</p>
	<p>Privacy usability in IoT smart home companion applications remains an underexplored domain despite mounting regulatory requirements and accelerating user adoption. Heuristic evaluation offers a scalable pathway to privacy usability assessment, yet validated frameworks for applying such methods are scarce. This study presents the first empirical application of the ABCDE Privacy Framework, a ten-heuristic instrument grounded in Nielsen&amp;amp;rsquo;s usability principles and Privacy by Design, to an IoT companion application developed with a major European home appliance manufacturer. A structured workshop was conducted with a multidisciplinary team of seven participants (five industry professionals and two researchers) following a two-round protocol: a qualitative heuristic discussion phase (Round 1) and an individual scoring phase (Round 2). Data were analysed through MAXQDA (VERBI Software, Berlin, Germany). Average heuristic scores ranged from 3.6 (H9: error recovery) to 4.8 (H6: recognition; H10: documentation), with an overall mean of 4.32. Six second-order themes were identified, including Transparency Asymmetry, Centralised but Decontextualised Privacy, and Shared Household Complexity. This first pilot application suggests that the ABCDE Privacy Framework is feasible, time-efficient, and analytically productive in this industrial context, generating design-relevant insights and enabling cross-role team alignment within a two-hour session. These preliminary findings indicate its potential as a tool for Privacy-by-Design practice in IoT product development and provide a basis for future replication and validation.</p>
	]]></content:encoded>

	<dc:title>Privacy Usability Evaluation of IoT Smart Home Companion Application: A Pilot Study of the ABCDE Privacy Framework with an Industrial Multidisciplinary Team</dc:title>
			<dc:creator>Amparo Coiduras-Sanagustín</dc:creator>
			<dc:creator>Eduardo Manchado-Pérez</dc:creator>
			<dc:creator>César García-Hernández</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040114</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-07-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-07-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>114</prism:startingPage>
		<prism:doi>10.3390/jcp6040114</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/114</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/113">

	<title>JCP, Vol. 6, Pages 113: Digitalized Quality Management for Cybersecurity Conformity Assessment: ISO/IEC 17025-Based Automated Workflows, Evidence Analytics, and EN 18031 Readiness for the Radio Equipment Directive</title>
	<link>https://www.mdpi.com/2624-800X/6/4/113</link>
	<description>Cybersecurity conformity assessment is increasingly shaped by the Radio Equipment Directive (RED) delegated act, the EN 18031 harmonized standards, the Cyber Resilience Act, and industrial standards such as International Electrotechnical Commission (IEC) 62443. ISO/IEC 17025:2017 provides a general laboratory competence framework, but its application to qualitative cybersecurity testing, rapidly changing toolchains, and automation-assisted evidence workflows remains under-specified. This paper proposes a digitalized quality-management framework that translates ISO/IEC 17025 clauses into cybersecurity-native controls for scope definition, method governance, toolchain control, evidence traceability, decision rules, technical review, and corrective-action feedback. An accreditation-style single-laboratory case study integrates a European Telecommunications Standards Institute (ETSI) TS 103 701 assessment workbook, an IEC 62443 corrective-action dataset, ISO/IEC 17025 internal audit findings, and laboratory governance records. In the ETSI workbook, the Conformity Statement Ambiguity Index (CSAI) decreases from 0.976 in the draft state to 0.050 after review, with 37 previously inconclusive provisions moving to PASS. This result is interpreted as improved determinability within the assessed workflow, not as cross-laboratory validation. The study contributes a clause-to-workflow operationalization of ISO/IEC 17025, an analytic design for heterogeneous assurance artefacts, and an EN 18031 evidence-mapping approach for Radio Equipment Directive readiness.</description>
	<pubDate>2026-06-30</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 113: Digitalized Quality Management for Cybersecurity Conformity Assessment: ISO/IEC 17025-Based Automated Workflows, Evidence Analytics, and EN 18031 Readiness for the Radio Equipment Directive</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/113">doi: 10.3390/jcp6040113</a></p>
	<p>Authors:
		Aymen Gatri
		David Lübeck
		Mukayil Kilic
		</p>
	<p>Cybersecurity conformity assessment is increasingly shaped by the Radio Equipment Directive (RED) delegated act, the EN 18031 harmonized standards, the Cyber Resilience Act, and industrial standards such as International Electrotechnical Commission (IEC) 62443. ISO/IEC 17025:2017 provides a general laboratory competence framework, but its application to qualitative cybersecurity testing, rapidly changing toolchains, and automation-assisted evidence workflows remains under-specified. This paper proposes a digitalized quality-management framework that translates ISO/IEC 17025 clauses into cybersecurity-native controls for scope definition, method governance, toolchain control, evidence traceability, decision rules, technical review, and corrective-action feedback. An accreditation-style single-laboratory case study integrates a European Telecommunications Standards Institute (ETSI) TS 103 701 assessment workbook, an IEC 62443 corrective-action dataset, ISO/IEC 17025 internal audit findings, and laboratory governance records. In the ETSI workbook, the Conformity Statement Ambiguity Index (CSAI) decreases from 0.976 in the draft state to 0.050 after review, with 37 previously inconclusive provisions moving to PASS. This result is interpreted as improved determinability within the assessed workflow, not as cross-laboratory validation. The study contributes a clause-to-workflow operationalization of ISO/IEC 17025, an analytic design for heterogeneous assurance artefacts, and an EN 18031 evidence-mapping approach for Radio Equipment Directive readiness.</p>
	]]></content:encoded>

	<dc:title>Digitalized Quality Management for Cybersecurity Conformity Assessment: ISO/IEC 17025-Based Automated Workflows, Evidence Analytics, and EN 18031 Readiness for the Radio Equipment Directive</dc:title>
			<dc:creator>Aymen Gatri</dc:creator>
			<dc:creator>David Lübeck</dc:creator>
			<dc:creator>Mukayil Kilic</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040113</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-30</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-30</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>113</prism:startingPage>
		<prism:doi>10.3390/jcp6040113</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/113</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/112">

	<title>JCP, Vol. 6, Pages 112: Robust Stealthy High-Impact Malicious Hardware Attacks on Deep Neural Networks</title>
	<link>https://www.mdpi.com/2624-800X/6/4/112</link>
	<description>The rapid advancement of modern deep neural networks (DNNs) has played a crucial role in aiding humans across many real-world applications; yet, their hardware accelerators have been proven to be vulnerable to malicious attacks. One particularly severe and serious attack involves inserting a hardware Trojan (HT) into DNN accelerator hardware in order to enable attackers to stealthily manipulate model predictions during the supply chain. In this paper, we present a possible stealthy HT architecture that is difficult to detect and has a significant impact on the performance of DNN models. To successfully achieve this goal, we introduce the Sensitivity-Based Weight Selection (SBWS) algorithm, a novel technique that adapts machine learning (ML) sensitivity analysis to identify and modify a small number of weights that have the highest impact on DNN performance, compared to previous work. We evaluate the proposed attack on five DNN model tests (two distinct DNN models and four different datasets) using two designed payload types (weight zeroing and sign-flipping) and record the results based on various security metrics. The experimental results show average accuracy reductions of 26.7% for the zeroing attack and 48.1% for the sign-flipping attack, yielding an overall average of 37.4%, calculated over five independent runs per dataset with standard deviation &amp;amp;lt;2%. The sign-flipping technique consistently outperforms zeroing because it preserves the magnitudes of the attacked weights while inverting their signs, thereby disrupting the learned decision boundaries more severely and amplifying error propagation in subsequent layers. These results significantly exceed those of previous random-weight perturbation attacks (typically 12&amp;amp;ndash;20% drops) and other targeted HT approaches while incurring lower computational and hardware resource overheads. This work provides a more effective and scalable method for assessing the vulnerability of DNN accelerators under real supply chain threat models.</description>
	<pubDate>2026-06-30</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 112: Robust Stealthy High-Impact Malicious Hardware Attacks on Deep Neural Networks</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/112">doi: 10.3390/jcp6040112</a></p>
	<p>Authors:
		Maath Frman
		Kholood J. Moulood
		Mustafa Noori
		Ekram H. Hasan
		Oqbah Salim Atiyah
		Qutaiba Alasad
		</p>
	<p>The rapid advancement of modern deep neural networks (DNNs) has played a crucial role in aiding humans across many real-world applications; yet, their hardware accelerators have been proven to be vulnerable to malicious attacks. One particularly severe and serious attack involves inserting a hardware Trojan (HT) into DNN accelerator hardware in order to enable attackers to stealthily manipulate model predictions during the supply chain. In this paper, we present a possible stealthy HT architecture that is difficult to detect and has a significant impact on the performance of DNN models. To successfully achieve this goal, we introduce the Sensitivity-Based Weight Selection (SBWS) algorithm, a novel technique that adapts machine learning (ML) sensitivity analysis to identify and modify a small number of weights that have the highest impact on DNN performance, compared to previous work. We evaluate the proposed attack on five DNN model tests (two distinct DNN models and four different datasets) using two designed payload types (weight zeroing and sign-flipping) and record the results based on various security metrics. The experimental results show average accuracy reductions of 26.7% for the zeroing attack and 48.1% for the sign-flipping attack, yielding an overall average of 37.4%, calculated over five independent runs per dataset with standard deviation &amp;amp;lt;2%. The sign-flipping technique consistently outperforms zeroing because it preserves the magnitudes of the attacked weights while inverting their signs, thereby disrupting the learned decision boundaries more severely and amplifying error propagation in subsequent layers. These results significantly exceed those of previous random-weight perturbation attacks (typically 12&amp;amp;ndash;20% drops) and other targeted HT approaches while incurring lower computational and hardware resource overheads. This work provides a more effective and scalable method for assessing the vulnerability of DNN accelerators under real supply chain threat models.</p>
	]]></content:encoded>

	<dc:title>Robust Stealthy High-Impact Malicious Hardware Attacks on Deep Neural Networks</dc:title>
			<dc:creator>Maath Frman</dc:creator>
			<dc:creator>Kholood J. Moulood</dc:creator>
			<dc:creator>Mustafa Noori</dc:creator>
			<dc:creator>Ekram H. Hasan</dc:creator>
			<dc:creator>Oqbah Salim Atiyah</dc:creator>
			<dc:creator>Qutaiba Alasad</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040112</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-30</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-30</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>112</prism:startingPage>
		<prism:doi>10.3390/jcp6040112</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/112</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/111">

	<title>JCP, Vol. 6, Pages 111: QR-MetaSSI: A Quantum-Resistant Self-Sovereign Identity Framework for Metaverse Platforms</title>
	<link>https://www.mdpi.com/2624-800X/6/4/111</link>
	<description>Quantum computing presents a critical threat to the cryptographic basis of metaverse platforms, with Shor&amp;amp;rsquo;s algorithm capable of breaking traditional public-key cryptography and Grover&amp;amp;rsquo;s algorithm significantly weakening symmetric encryption. The present self-sovereign identity (SSI) ecosystems are built on classical cryptographic systems that are susceptible to quantum attacks; hence, there is an immediate need for quantum-secure identity management in persistent virtual environments. This article proposes a solution called Quantum-Resistant MetaSSI (QR-MetaSSI), which is a comprehensive model that integrates NIST-standardized post-quantum cryptography (PQC) with W3C-compliant SSI principles. We design lattice-based decentralized identifiers (PQ-DIDs), hash-based verifiable credentials (PQ-VCs), and a hybrid authentication protocol that meets the needs of the metaverse, such as latency, interoperability, and persistent identities. The framework is subjected to mathematical modeling and simulation studies. Our study indicates that QR-MetaSSI keeps the authentication delay below 150 ms, which is inside the VR comfort range with 128-bit quantum security. Besides that, a comparative evaluation reveals that the proposed solution drastically reduces the risk of a quantum attack compared with classical ECC-based SSI systems at a level of computational overhead that is completely reasonable. QR-MetaSSI is a major step forward in the security of the metaverse, providing not only theoretical bases but also practical implementation instructions for the migration to quantum-resistant identity management. This framework not only addresses the most important breaches in security but also keeps the performance standards that are necessary for the creation of virtual environments that are highly immersive.</description>
	<pubDate>2026-06-29</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 111: QR-MetaSSI: A Quantum-Resistant Self-Sovereign Identity Framework for Metaverse Platforms</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/111">doi: 10.3390/jcp6040111</a></p>
	<p>Authors:
		Faisal Fiaz
		Zia Muhammad
		</p>
	<p>Quantum computing presents a critical threat to the cryptographic basis of metaverse platforms, with Shor&amp;amp;rsquo;s algorithm capable of breaking traditional public-key cryptography and Grover&amp;amp;rsquo;s algorithm significantly weakening symmetric encryption. The present self-sovereign identity (SSI) ecosystems are built on classical cryptographic systems that are susceptible to quantum attacks; hence, there is an immediate need for quantum-secure identity management in persistent virtual environments. This article proposes a solution called Quantum-Resistant MetaSSI (QR-MetaSSI), which is a comprehensive model that integrates NIST-standardized post-quantum cryptography (PQC) with W3C-compliant SSI principles. We design lattice-based decentralized identifiers (PQ-DIDs), hash-based verifiable credentials (PQ-VCs), and a hybrid authentication protocol that meets the needs of the metaverse, such as latency, interoperability, and persistent identities. The framework is subjected to mathematical modeling and simulation studies. Our study indicates that QR-MetaSSI keeps the authentication delay below 150 ms, which is inside the VR comfort range with 128-bit quantum security. Besides that, a comparative evaluation reveals that the proposed solution drastically reduces the risk of a quantum attack compared with classical ECC-based SSI systems at a level of computational overhead that is completely reasonable. QR-MetaSSI is a major step forward in the security of the metaverse, providing not only theoretical bases but also practical implementation instructions for the migration to quantum-resistant identity management. This framework not only addresses the most important breaches in security but also keeps the performance standards that are necessary for the creation of virtual environments that are highly immersive.</p>
	]]></content:encoded>

	<dc:title>QR-MetaSSI: A Quantum-Resistant Self-Sovereign Identity Framework for Metaverse Platforms</dc:title>
			<dc:creator>Faisal Fiaz</dc:creator>
			<dc:creator>Zia Muhammad</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040111</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-29</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-29</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>111</prism:startingPage>
		<prism:doi>10.3390/jcp6040111</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/111</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/110">

	<title>JCP, Vol. 6, Pages 110: Evaluation of Homomorphic Encryption Integration Strategies in Database Management Systems</title>
	<link>https://www.mdpi.com/2624-800X/6/4/110</link>
	<description>Homomorphic Encryption (HE) has emerged as a promising approach for data processing without exposing sensitive information. Despite significant advances, the practical strategies for the integration of HE into widely used database management systems (DBMSs) remain limited due to performance constraints and architectural challenges. This paper explores HE integration strategies within DBMS, focusing on SQL Server, PostgreSQL, and MariaDB. A methodology is proposed to assess the feasibility and performance of multiple HE schemes, including BFV, CKKS, BGV, TFHE, Paillier, and RSA (without padding). The evaluation considers different integration strategies, namely Python-based execution and native C++ extensions, across Windows and Debian environments. Experimental results obtained from four configurations demonstrate that the choice of HE scheme and integration strategy significantly impacts performance. Lattice-based schemes (BFV, CKKS, BGV) provide a balanced trade-off between functionality and efficiency, while TFHE incurs high computational costs due to its bit-level design. Native C++ integrations consistently outperform Python-based approaches, although the latter offer greater flexibility and ease of development. The findings highlight the feasibility of integrating HE into DBMS while emphasizing the importance of selecting appropriate schemes and integration mechanisms to meet application-specific requirements. The proposed evaluation framework provides preliminary insights into the relative behavior of different HE schemes and integration strategies under controlled experimental conditions, supporting future work on privacy-preserving DBMS design.</description>
	<pubDate>2026-06-27</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 110: Evaluation of Homomorphic Encryption Integration Strategies in Database Management Systems</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/110">doi: 10.3390/jcp6040110</a></p>
	<p>Authors:
		Henrique Jorge
		Cristina Wanzeller
		João Henriques
		</p>
	<p>Homomorphic Encryption (HE) has emerged as a promising approach for data processing without exposing sensitive information. Despite significant advances, the practical strategies for the integration of HE into widely used database management systems (DBMSs) remain limited due to performance constraints and architectural challenges. This paper explores HE integration strategies within DBMS, focusing on SQL Server, PostgreSQL, and MariaDB. A methodology is proposed to assess the feasibility and performance of multiple HE schemes, including BFV, CKKS, BGV, TFHE, Paillier, and RSA (without padding). The evaluation considers different integration strategies, namely Python-based execution and native C++ extensions, across Windows and Debian environments. Experimental results obtained from four configurations demonstrate that the choice of HE scheme and integration strategy significantly impacts performance. Lattice-based schemes (BFV, CKKS, BGV) provide a balanced trade-off between functionality and efficiency, while TFHE incurs high computational costs due to its bit-level design. Native C++ integrations consistently outperform Python-based approaches, although the latter offer greater flexibility and ease of development. The findings highlight the feasibility of integrating HE into DBMS while emphasizing the importance of selecting appropriate schemes and integration mechanisms to meet application-specific requirements. The proposed evaluation framework provides preliminary insights into the relative behavior of different HE schemes and integration strategies under controlled experimental conditions, supporting future work on privacy-preserving DBMS design.</p>
	]]></content:encoded>

	<dc:title>Evaluation of Homomorphic Encryption Integration Strategies in Database Management Systems</dc:title>
			<dc:creator>Henrique Jorge</dc:creator>
			<dc:creator>Cristina Wanzeller</dc:creator>
			<dc:creator>João Henriques</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040110</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-27</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-27</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>110</prism:startingPage>
		<prism:doi>10.3390/jcp6040110</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/110</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/109">

	<title>JCP, Vol. 6, Pages 109: Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure</title>
	<link>https://www.mdpi.com/2624-800X/6/4/109</link>
	<description>Cyber Security Incident Response (IR) playbooks are used to capture the steps required to recover from a cyber intrusion. Intrusion modelling focuses on a specific potential cyber intrusion and is used to identify where and what countermeasures are needed. The resulting intrusion models are expected to be used in IR, ideally by feeding IR playbook designs. However, IR playbooks and intrusion models are created in isolation and at varying stages of the system&amp;amp;rsquo;s lifecycle, and there is no systematic approach that allows for their integration. In this article, we present a new approach to integrate intrusion models and IR models by translating intrusion models into a form compatible with IR models. We take nine critical national infrastructure intrusion models&amp;amp;mdash;expressed using Sequential AND Attack Trees&amp;amp;mdash;and transform them into models of the same format as IR playbooks, using a newly devised, automated conversion application. We use the Security Modelling Framework for modelling intrusions and playbooks, and for demonstrating the feasibility of the better integration between them based on operational impact. This results in enhanced intrusion models that are contextualised with respect to operations and, accordingly, can offer tighter coupling with IR playbooks. The main contributions of this paper are (a) a novel way of representing attack trees, (b) a new tool for automatically converting Sequential AND attack trees into models compatible with playbooks, and (c) examples of nine real-world intrusion models.</description>
	<pubDate>2026-06-27</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 109: Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/109">doi: 10.3390/jcp6040109</a></p>
	<p>Authors:
		Peter Maynard
		Yulia Cherdantseva
		Avi Shaked
		Pete Burnap
		</p>
	<p>Cyber Security Incident Response (IR) playbooks are used to capture the steps required to recover from a cyber intrusion. Intrusion modelling focuses on a specific potential cyber intrusion and is used to identify where and what countermeasures are needed. The resulting intrusion models are expected to be used in IR, ideally by feeding IR playbook designs. However, IR playbooks and intrusion models are created in isolation and at varying stages of the system&amp;amp;rsquo;s lifecycle, and there is no systematic approach that allows for their integration. In this article, we present a new approach to integrate intrusion models and IR models by translating intrusion models into a form compatible with IR models. We take nine critical national infrastructure intrusion models&amp;amp;mdash;expressed using Sequential AND Attack Trees&amp;amp;mdash;and transform them into models of the same format as IR playbooks, using a newly devised, automated conversion application. We use the Security Modelling Framework for modelling intrusions and playbooks, and for demonstrating the feasibility of the better integration between them based on operational impact. This results in enhanced intrusion models that are contextualised with respect to operations and, accordingly, can offer tighter coupling with IR playbooks. The main contributions of this paper are (a) a novel way of representing attack trees, (b) a new tool for automatically converting Sequential AND attack trees into models compatible with playbooks, and (c) examples of nine real-world intrusion models.</p>
	]]></content:encoded>

	<dc:title>Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure</dc:title>
			<dc:creator>Peter Maynard</dc:creator>
			<dc:creator>Yulia Cherdantseva</dc:creator>
			<dc:creator>Avi Shaked</dc:creator>
			<dc:creator>Pete Burnap</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040109</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-27</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-27</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>109</prism:startingPage>
		<prism:doi>10.3390/jcp6040109</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/109</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/108">

	<title>JCP, Vol. 6, Pages 108: Account-Holding Proofs Across Multiple Authorities from JWT-Derived Evidence Using RSA-Based Synchronized Aggregate Signatures</title>
	<link>https://www.mdpi.com/2624-800X/6/4/108</link>
	<description>This paper proposes a model for account-holding proofs across multiple authorities and presents a concrete construction from JWT-derived evidence, enabling a verifier to evaluate the resulting artifact under specified system assumptions and acceptance policies. Conventional account linkage approaches often depend on particular identity providers (IdPs) or linkage mechanisms and may expose or correlate more credential information than is necessary for the verifier&amp;amp;rsquo;s policy. To address this, we formalize a scheme-agnostic abstract model and organize its security, disclosure-related, and deployment requirements. As a concrete instantiation, we apply an RSA-based synchronized aggregate signature scheme to encoded messages derived from the RS256 preprocessing step of JWT signing inputs. The resulting artifact is not a standard JWT and is not intended for direct verification by existing JWT/OIDC verifiers; rather, it provides a single aggregate signature component over multiple JWT-derived evidence items. Through analytical and prototype-based evaluation, we show that the signature-component data to be presented is reduced from n individual components to a single aggregate component and that the exponentiation applied to the presented signature component is reduced from O(n) to O(1), while the overall verification remains dominated by per-message public-key terms. The results of prototype implementation indicate that aggregate verification is not faster than ordinary RS256 JWT verification under the evaluated parameters; therefore, the construction is better suited to one-time or low-frequency account-holding proof scenarios in which the additional latency is tolerable.</description>
	<pubDate>2026-06-27</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 108: Account-Holding Proofs Across Multiple Authorities from JWT-Derived Evidence Using RSA-Based Synchronized Aggregate Signatures</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/108">doi: 10.3390/jcp6040108</a></p>
	<p>Authors:
		Kenta Nomura
		Tsunekazu Saito
		Masaki Kamizono
		Yoshiaki Shiraishi
		</p>
	<p>This paper proposes a model for account-holding proofs across multiple authorities and presents a concrete construction from JWT-derived evidence, enabling a verifier to evaluate the resulting artifact under specified system assumptions and acceptance policies. Conventional account linkage approaches often depend on particular identity providers (IdPs) or linkage mechanisms and may expose or correlate more credential information than is necessary for the verifier&amp;amp;rsquo;s policy. To address this, we formalize a scheme-agnostic abstract model and organize its security, disclosure-related, and deployment requirements. As a concrete instantiation, we apply an RSA-based synchronized aggregate signature scheme to encoded messages derived from the RS256 preprocessing step of JWT signing inputs. The resulting artifact is not a standard JWT and is not intended for direct verification by existing JWT/OIDC verifiers; rather, it provides a single aggregate signature component over multiple JWT-derived evidence items. Through analytical and prototype-based evaluation, we show that the signature-component data to be presented is reduced from n individual components to a single aggregate component and that the exponentiation applied to the presented signature component is reduced from O(n) to O(1), while the overall verification remains dominated by per-message public-key terms. The results of prototype implementation indicate that aggregate verification is not faster than ordinary RS256 JWT verification under the evaluated parameters; therefore, the construction is better suited to one-time or low-frequency account-holding proof scenarios in which the additional latency is tolerable.</p>
	]]></content:encoded>

	<dc:title>Account-Holding Proofs Across Multiple Authorities from JWT-Derived Evidence Using RSA-Based Synchronized Aggregate Signatures</dc:title>
			<dc:creator>Kenta Nomura</dc:creator>
			<dc:creator>Tsunekazu Saito</dc:creator>
			<dc:creator>Masaki Kamizono</dc:creator>
			<dc:creator>Yoshiaki Shiraishi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040108</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-27</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-27</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>108</prism:startingPage>
		<prism:doi>10.3390/jcp6040108</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/108</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/107">

	<title>JCP, Vol. 6, Pages 107: A Unified IoT Security Platform for Dynamic Threat-to-Control Mapping</title>
	<link>https://www.mdpi.com/2624-800X/6/4/107</link>
	<description>Cybersecurity risk management is often complicated by fragmented solutions for threat identification and detection, vulnerability assessment, and control selection across multiple frameworks. This paper presents a unified, dynamically updated, threat-based cybersecurity control platform that addresses this challenge by integrating Information Technology (IT), Operational Technology (OT), and Internet of Things (IoT) standards, including ISO/IEC 27001:2022, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0, and IEC 62443-3-3. The platform enables (1) querying a selected threat to identify associated vulnerabilities, (2) recommending applicable security controls across multiple frameworks, and (3) identifying overlapping or unique controls to avoid redundant implementation. Automated integration of Common Vulnerabilities and Exposures (CVEs) from the NIST National Vulnerability Database (NVD) links vulnerabilities to mapped threats and controls, supporting proactive risk management. A structured evaluation was conducted across 100 threat scenarios spanning IT, OT, and IoT domains, producing approximately 1000 threat&amp;amp;ndash;control relationships across 3 integrated frameworks. Performance evaluation demonstrates that the platform is scalable. While integrating additional frameworks, it maintains an average query latency of 0.40 s to 0.43 s, which implies an insignificant incremental latency increase of 0.03 s, while its web-based interface provides dynamic querying and visualization in a user-friendly manner for technical and non-technical users. By unifying threat, vulnerability, and control data, the platform streamlines compliance, reduces control retrieval time, and ensures traceable, consistent, and cross-framework mitigation strategies, enhancing informed cybersecurity decision making.</description>
	<pubDate>2026-06-26</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 107: A Unified IoT Security Platform for Dynamic Threat-to-Control Mapping</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/107">doi: 10.3390/jcp6040107</a></p>
	<p>Authors:
		Fatiha Djebbar
		Ismaila Olatunde Sogbade
		</p>
	<p>Cybersecurity risk management is often complicated by fragmented solutions for threat identification and detection, vulnerability assessment, and control selection across multiple frameworks. This paper presents a unified, dynamically updated, threat-based cybersecurity control platform that addresses this challenge by integrating Information Technology (IT), Operational Technology (OT), and Internet of Things (IoT) standards, including ISO/IEC 27001:2022, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0, and IEC 62443-3-3. The platform enables (1) querying a selected threat to identify associated vulnerabilities, (2) recommending applicable security controls across multiple frameworks, and (3) identifying overlapping or unique controls to avoid redundant implementation. Automated integration of Common Vulnerabilities and Exposures (CVEs) from the NIST National Vulnerability Database (NVD) links vulnerabilities to mapped threats and controls, supporting proactive risk management. A structured evaluation was conducted across 100 threat scenarios spanning IT, OT, and IoT domains, producing approximately 1000 threat&amp;amp;ndash;control relationships across 3 integrated frameworks. Performance evaluation demonstrates that the platform is scalable. While integrating additional frameworks, it maintains an average query latency of 0.40 s to 0.43 s, which implies an insignificant incremental latency increase of 0.03 s, while its web-based interface provides dynamic querying and visualization in a user-friendly manner for technical and non-technical users. By unifying threat, vulnerability, and control data, the platform streamlines compliance, reduces control retrieval time, and ensures traceable, consistent, and cross-framework mitigation strategies, enhancing informed cybersecurity decision making.</p>
	]]></content:encoded>

	<dc:title>A Unified IoT Security Platform for Dynamic Threat-to-Control Mapping</dc:title>
			<dc:creator>Fatiha Djebbar</dc:creator>
			<dc:creator>Ismaila Olatunde Sogbade</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040107</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-26</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-26</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>107</prism:startingPage>
		<prism:doi>10.3390/jcp6040107</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/107</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/4/106">

	<title>JCP, Vol. 6, Pages 106: A Software Platform for Benchmarking, Multi-Criteria Evaluation, and Integrity Validation of Symmetric Encryption Algorithms</title>
	<link>https://www.mdpi.com/2624-800X/6/4/106</link>
	<description>The choice of a symmetric encryption algorithm in practice is rarely as straightforward as it may appear from theoretical comparisons alone. In addition to security considerations, real-world selection often depends on execution time, reliability, entropy-related behavior, resource efficiency, and suitability for different types of data. This paper presents an experimental software platform for benchmarking and multi-criteria recommendation of symmetric encryption algorithms. The platform combines automated encryption and decryption tests, metric collection, comparative analysis, and result visualization within a unified evaluation workflow. It also incorporates a multi-criteria model that transforms raw experimental measurements into an overall ranking and supports context-aware recommendation according to the requirements of a given usage scenario. The experimental study includes repeated tests on different input categories in order to examine algorithm behavior under varied operating conditions. The obtained results show that algorithm performance and overall suitability are strongly dependent on the evaluation perspective and the application context, which suggests that no single symmetric method should be regarded as universally optimal. The proposed platform offers a practical basis for comparative cryptographic analysis and may be useful both for research purposes and for informed decision-making in security-oriented software environments.</description>
	<pubDate>2026-06-25</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 106: A Software Platform for Benchmarking, Multi-Criteria Evaluation, and Integrity Validation of Symmetric Encryption Algorithms</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/4/106">doi: 10.3390/jcp6040106</a></p>
	<p>Authors:
		Diyan Dinev
		Gergana Spasova
		</p>
	<p>The choice of a symmetric encryption algorithm in practice is rarely as straightforward as it may appear from theoretical comparisons alone. In addition to security considerations, real-world selection often depends on execution time, reliability, entropy-related behavior, resource efficiency, and suitability for different types of data. This paper presents an experimental software platform for benchmarking and multi-criteria recommendation of symmetric encryption algorithms. The platform combines automated encryption and decryption tests, metric collection, comparative analysis, and result visualization within a unified evaluation workflow. It also incorporates a multi-criteria model that transforms raw experimental measurements into an overall ranking and supports context-aware recommendation according to the requirements of a given usage scenario. The experimental study includes repeated tests on different input categories in order to examine algorithm behavior under varied operating conditions. The obtained results show that algorithm performance and overall suitability are strongly dependent on the evaluation perspective and the application context, which suggests that no single symmetric method should be regarded as universally optimal. The proposed platform offers a practical basis for comparative cryptographic analysis and may be useful both for research purposes and for informed decision-making in security-oriented software environments.</p>
	]]></content:encoded>

	<dc:title>A Software Platform for Benchmarking, Multi-Criteria Evaluation, and Integrity Validation of Symmetric Encryption Algorithms</dc:title>
			<dc:creator>Diyan Dinev</dc:creator>
			<dc:creator>Gergana Spasova</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6040106</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-25</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-25</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>4</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>106</prism:startingPage>
		<prism:doi>10.3390/jcp6040106</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/4/106</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/105">

	<title>JCP, Vol. 6, Pages 105: An Explainable Hybrid Pipeline for Malware Classification: Benchmark Construction, Feature Reduction, and Security-Oriented Evaluation</title>
	<link>https://www.mdpi.com/2624-800X/6/3/105</link>
	<description>Malware classification increasingly relies on machine learning models that combine static and dynamic evidence, yet their practical use is often limited by dataset inconsistency, high-dimensional feature spaces, and insufficient transparency. This paper presents an explainable hybrid malware-classification pipeline built on an aligned public dataset in which static and dynamic features are matched at sample level and share the same class space. The framework combines a Random Forest static branch, a calibrated XGBoost dynamic branch, and a weighted late-fusion stage whose branch weights are derived from inner-validation weighted-F1 rather than from test performance. On the corrected no-leak benchmark, static reduction compresses the static space from 771 to 258 features, while sparse-aggressive reduction compresses the dynamic space from 21,918 to 374 features. An early-fusion XGBoost baseline achieves the best multiclass aggregate scores, whereas the validation-weighted calibrated hybrid provides the strongest false-negative-first Benign vs. Malware profile, reaching malware recall 0.9998, benign recall 0.8053, and one false negative on the test set. The study shows that, once leakage is removed and fusion is validation-driven, the preferred hybrid architecture depends on the operational objective rather than on a single aggregate metric.</description>
	<pubDate>2026-06-22</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 105: An Explainable Hybrid Pipeline for Malware Classification: Benchmark Construction, Feature Reduction, and Security-Oriented Evaluation</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/105">doi: 10.3390/jcp6030105</a></p>
	<p>Authors:
		Carmelo Ardito
		Giuseppe Loseto
		Riccardo Di Pietro
		Nicola Epicoco
		Alessandro Massaro
		</p>
	<p>Malware classification increasingly relies on machine learning models that combine static and dynamic evidence, yet their practical use is often limited by dataset inconsistency, high-dimensional feature spaces, and insufficient transparency. This paper presents an explainable hybrid malware-classification pipeline built on an aligned public dataset in which static and dynamic features are matched at sample level and share the same class space. The framework combines a Random Forest static branch, a calibrated XGBoost dynamic branch, and a weighted late-fusion stage whose branch weights are derived from inner-validation weighted-F1 rather than from test performance. On the corrected no-leak benchmark, static reduction compresses the static space from 771 to 258 features, while sparse-aggressive reduction compresses the dynamic space from 21,918 to 374 features. An early-fusion XGBoost baseline achieves the best multiclass aggregate scores, whereas the validation-weighted calibrated hybrid provides the strongest false-negative-first Benign vs. Malware profile, reaching malware recall 0.9998, benign recall 0.8053, and one false negative on the test set. The study shows that, once leakage is removed and fusion is validation-driven, the preferred hybrid architecture depends on the operational objective rather than on a single aggregate metric.</p>
	]]></content:encoded>

	<dc:title>An Explainable Hybrid Pipeline for Malware Classification: Benchmark Construction, Feature Reduction, and Security-Oriented Evaluation</dc:title>
			<dc:creator>Carmelo Ardito</dc:creator>
			<dc:creator>Giuseppe Loseto</dc:creator>
			<dc:creator>Riccardo Di Pietro</dc:creator>
			<dc:creator>Nicola Epicoco</dc:creator>
			<dc:creator>Alessandro Massaro</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030105</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-22</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-22</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>105</prism:startingPage>
		<prism:doi>10.3390/jcp6030105</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/105</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/104">

	<title>JCP, Vol. 6, Pages 104: Multidimensional Hill Cipher Substitution&amp;ndash;Permutation Network</title>
	<link>https://www.mdpi.com/2624-800X/6/3/104</link>
	<description>MD-Hill-SPN is the first Hill-based construction to combine a multi-tier diffusion mix layer, a memory-hard KDF, and a simultaneous multi-metric empirical evaluation. Two independent runs of the full metric suite yield: (a) full plaintext avalanche from round 1 (mean 63.97&amp;amp;ndash;64.67 of 128 bits, ideal 64); (b) the differential-probability sampling floor of 2 &amp;amp;times; 10&amp;amp;minus;5 reached at round 4 (50,000 of 50,000 output differences distinct, both sessions); (c) algebraic-degree lower-bound saturation at the maximum observable value from round 1; (d) linear-bias indistinguishable from random (combined exceedance 4.40%, below the 4.55% noise floor); and (e) branch numbers at the Singleton (MDS) bound for every tier (B = 5 for 4 &amp;amp;times; 4, B = 9 for 8 &amp;amp;times; 8, B = 17 for 16 &amp;amp;times; 16), computed exhaustively over weight-1 inputs. MD-Hill-SPN therefore moves beyond theoretical construction to a construction that passes a defined empirical evaluation suite: avalanche, differential sampling, linear-bias probing, algebraic-degree lower bounds, and MDS branch numbers under single-key, known-plaintext conditions with fixed parameters, an evaluation no prior Hill cipher variant has reported in full.</description>
	<pubDate>2026-06-17</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 104: Multidimensional Hill Cipher Substitution&amp;ndash;Permutation Network</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/104">doi: 10.3390/jcp6030104</a></p>
	<p>Authors:
		Porter E. Coggins
		</p>
	<p>MD-Hill-SPN is the first Hill-based construction to combine a multi-tier diffusion mix layer, a memory-hard KDF, and a simultaneous multi-metric empirical evaluation. Two independent runs of the full metric suite yield: (a) full plaintext avalanche from round 1 (mean 63.97&amp;amp;ndash;64.67 of 128 bits, ideal 64); (b) the differential-probability sampling floor of 2 &amp;amp;times; 10&amp;amp;minus;5 reached at round 4 (50,000 of 50,000 output differences distinct, both sessions); (c) algebraic-degree lower-bound saturation at the maximum observable value from round 1; (d) linear-bias indistinguishable from random (combined exceedance 4.40%, below the 4.55% noise floor); and (e) branch numbers at the Singleton (MDS) bound for every tier (B = 5 for 4 &amp;amp;times; 4, B = 9 for 8 &amp;amp;times; 8, B = 17 for 16 &amp;amp;times; 16), computed exhaustively over weight-1 inputs. MD-Hill-SPN therefore moves beyond theoretical construction to a construction that passes a defined empirical evaluation suite: avalanche, differential sampling, linear-bias probing, algebraic-degree lower bounds, and MDS branch numbers under single-key, known-plaintext conditions with fixed parameters, an evaluation no prior Hill cipher variant has reported in full.</p>
	]]></content:encoded>

	<dc:title>Multidimensional Hill Cipher Substitution&amp;amp;ndash;Permutation Network</dc:title>
			<dc:creator>Porter E. Coggins</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030104</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-17</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-17</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>104</prism:startingPage>
		<prism:doi>10.3390/jcp6030104</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/104</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/103">

	<title>JCP, Vol. 6, Pages 103: Privacy-Preserving Biometric Authentication in Resource-Constrained Environments: A PRISMA Systematic Review of Multimodal and Fuzzy-Vault Methods</title>
	<link>https://www.mdpi.com/2624-800X/6/3/103</link>
	<description>As micro, small and medium-sized enterprises (MSMEs) compete with limited resources, lightweight systems are needed to secure their digital assets. Fuzzy vaults (FVs) are useful for protecting secrets and, when applied to biometric systems, provide error-tolerance and privacy to enrolled biometric features. Combining multiple biometric traits also improves performance against attacks like spoofing in multimodal (MM) authentication systems. However, the design of the FV and the biometric-fusion method applied can limit the system&amp;amp;rsquo;s effectiveness. This study systematically evaluates recent studies on FVs and MM systems and presents an up-to-date review to identify gaps, give directions for future studies, and, ultimately, improve the design of these systems. The research targeting MSMEs was carried out in two parts, with the first search focused on MM systems and the second on FVs, following the PRISMA guidelines. The main findings include the need to optimise the resource intensity of FV systems for the authentication of large numbers of individuals. It also found the need to make the model compatible with other biometric modalities as greater focus is on minutiae features. By reviewing these systems, we aim to foster the development of lightweight MM FV models to provide privacy and security in MSMEs.</description>
	<pubDate>2026-06-12</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 103: Privacy-Preserving Biometric Authentication in Resource-Constrained Environments: A PRISMA Systematic Review of Multimodal and Fuzzy-Vault Methods</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/103">doi: 10.3390/jcp6030103</a></p>
	<p>Authors:
		Shadrach Olarewaju
		Ali Safaa Sadiq
		Omprakash Kaiwartya
		Alexandros Konios
		</p>
	<p>As micro, small and medium-sized enterprises (MSMEs) compete with limited resources, lightweight systems are needed to secure their digital assets. Fuzzy vaults (FVs) are useful for protecting secrets and, when applied to biometric systems, provide error-tolerance and privacy to enrolled biometric features. Combining multiple biometric traits also improves performance against attacks like spoofing in multimodal (MM) authentication systems. However, the design of the FV and the biometric-fusion method applied can limit the system&amp;amp;rsquo;s effectiveness. This study systematically evaluates recent studies on FVs and MM systems and presents an up-to-date review to identify gaps, give directions for future studies, and, ultimately, improve the design of these systems. The research targeting MSMEs was carried out in two parts, with the first search focused on MM systems and the second on FVs, following the PRISMA guidelines. The main findings include the need to optimise the resource intensity of FV systems for the authentication of large numbers of individuals. It also found the need to make the model compatible with other biometric modalities as greater focus is on minutiae features. By reviewing these systems, we aim to foster the development of lightweight MM FV models to provide privacy and security in MSMEs.</p>
	]]></content:encoded>

	<dc:title>Privacy-Preserving Biometric Authentication in Resource-Constrained Environments: A PRISMA Systematic Review of Multimodal and Fuzzy-Vault Methods</dc:title>
			<dc:creator>Shadrach Olarewaju</dc:creator>
			<dc:creator>Ali Safaa Sadiq</dc:creator>
			<dc:creator>Omprakash Kaiwartya</dc:creator>
			<dc:creator>Alexandros Konios</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030103</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-12</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-12</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Systematic Review</prism:section>
	<prism:startingPage>103</prism:startingPage>
		<prism:doi>10.3390/jcp6030103</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/103</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/102">

	<title>JCP, Vol. 6, Pages 102: NetGuard: A Hybrid Framework for Intelligent and Scalable Malicious URL Detection</title>
	<link>https://www.mdpi.com/2624-800X/6/3/102</link>
	<description>Due to the indispensable use of the internet, malicious actors have exploited URLs as a threat source of network information security and integrity. URL detection based on traditional methods has become inefficient against the uncontrolled increase of URLs, especially when facing dynamic and large-scale threats. To address the limitations of traditional methods and to provide intelligent and scalable detection of malicious URLs, this study proposes the hybrid framework (NetGuard) by integrating probabilistic data structures (PDSs) with machine learning (ML) capabilities. The proposed NetGuard utilizes PDSs to develop a Hybrid Scalable Detection Filter (HSDF), which combines the strengths of counting Bloom filters (CBFs) (deletion capability) and Scalable Bloom filters (SBFs). The proposed HSDF provides efficient membership queries under bounded false-positive rates (approximately 0.01) and ensures efficient data management and low-latency lookups on a scale of 10&amp;amp;minus;5 s. On the other hand, NetGuard leverages the ML classifier capabilities to train and package a learned classifier for detecting malicious URLs. The proposed framework utilizes Decision Trees (DTs) and Random Forest (RF) classifiers. The proposed classifiers are trained by a novel SupURLsIdDs dataset which includes fifteen distinctive lexical and structural URL features extracted from four URL classes: benign, defacement, malware, and phishing URLs. The experimental results indicated the effectiveness of the HSDF in insertion and deletion operations, with minimal memory consumption (approximately 2.7 MB for 222,000 URLs) while maintaining a controlled false-positive rate (approximately 0.01 on Real-only subset up to 0.12 with synthetic data). The HSDF memory footprint represents a 99.88% enhancement compared to the RF model (which demands 2253.17 MB); thus, the HSDF complements RF as an ultra-lightweight first line of defense. The ML classifiers showed the superiority of RF, which achieved an overall classification accuracy of approximately 96% on large-scale URL data. These experiments are conducted using benchmark datasets constructed from aggregated real and synthetic data to demonstrate the scalability, adaptability, and resource efficiency of the first phase of NetGuard as a practical foundation for real-time web threat detection. The real-time integration and dynamic updates are presented as a deployment architecture and constitute future work.</description>
	<pubDate>2026-06-10</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 102: NetGuard: A Hybrid Framework for Intelligent and Scalable Malicious URL Detection</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/102">doi: 10.3390/jcp6030102</a></p>
	<p>Authors:
		Saja D. Khudhur
		Sama S. Samaan
		Omar N. M. Taher
		Aymen D. D. Salman
		Amjad J. Humaidi
		</p>
	<p>Due to the indispensable use of the internet, malicious actors have exploited URLs as a threat source of network information security and integrity. URL detection based on traditional methods has become inefficient against the uncontrolled increase of URLs, especially when facing dynamic and large-scale threats. To address the limitations of traditional methods and to provide intelligent and scalable detection of malicious URLs, this study proposes the hybrid framework (NetGuard) by integrating probabilistic data structures (PDSs) with machine learning (ML) capabilities. The proposed NetGuard utilizes PDSs to develop a Hybrid Scalable Detection Filter (HSDF), which combines the strengths of counting Bloom filters (CBFs) (deletion capability) and Scalable Bloom filters (SBFs). The proposed HSDF provides efficient membership queries under bounded false-positive rates (approximately 0.01) and ensures efficient data management and low-latency lookups on a scale of 10&amp;amp;minus;5 s. On the other hand, NetGuard leverages the ML classifier capabilities to train and package a learned classifier for detecting malicious URLs. The proposed framework utilizes Decision Trees (DTs) and Random Forest (RF) classifiers. The proposed classifiers are trained by a novel SupURLsIdDs dataset which includes fifteen distinctive lexical and structural URL features extracted from four URL classes: benign, defacement, malware, and phishing URLs. The experimental results indicated the effectiveness of the HSDF in insertion and deletion operations, with minimal memory consumption (approximately 2.7 MB for 222,000 URLs) while maintaining a controlled false-positive rate (approximately 0.01 on Real-only subset up to 0.12 with synthetic data). The HSDF memory footprint represents a 99.88% enhancement compared to the RF model (which demands 2253.17 MB); thus, the HSDF complements RF as an ultra-lightweight first line of defense. The ML classifiers showed the superiority of RF, which achieved an overall classification accuracy of approximately 96% on large-scale URL data. These experiments are conducted using benchmark datasets constructed from aggregated real and synthetic data to demonstrate the scalability, adaptability, and resource efficiency of the first phase of NetGuard as a practical foundation for real-time web threat detection. The real-time integration and dynamic updates are presented as a deployment architecture and constitute future work.</p>
	]]></content:encoded>

	<dc:title>NetGuard: A Hybrid Framework for Intelligent and Scalable Malicious URL Detection</dc:title>
			<dc:creator>Saja D. Khudhur</dc:creator>
			<dc:creator>Sama S. Samaan</dc:creator>
			<dc:creator>Omar N. M. Taher</dc:creator>
			<dc:creator>Aymen D. D. Salman</dc:creator>
			<dc:creator>Amjad J. Humaidi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030102</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-10</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-10</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>102</prism:startingPage>
		<prism:doi>10.3390/jcp6030102</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/102</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/101">

	<title>JCP, Vol. 6, Pages 101: Chaotic Image Encryption by Intra-Channel Diffusion and Inter-Channel Confusion</title>
	<link>https://www.mdpi.com/2624-800X/6/3/101</link>
	<description>Most image encryption schemes exhibit one or more of the following limitations: keystream bias, high residual pixel correlation, pattern leakage, low sensitivity to key changes, or a security-efficiency trade-off. We present a robust image encryption framework based on a chaotic system that operates across the red, green, and blue color channels and mitigates all of the above vulnerabilities. The scheme consists of a novel integration of strong bidirectional modular diffusion, inter-channel confusion using a six-state permutation table, and Secure Hash Algorithm 256-based key derivation. Thus, we achieve the following: lossless reconstruction, near-ideal entropy, negligible adjacency correlation, high sensitivity to infinitesimal changes in both the plaintext and the secret key, a complete diffusion effect confirmed by standard differential metrics, and resilience against known- and chosen-plaintext attacks. Furthermore, the results comply with the National Institute of Standards and Technology randomness tests. These results are obtained with competitive encryption times (&amp;amp;sim;0.37 s for 512 &amp;amp;times; 512 images) without any code optimization. All of these features make the scheme promising for secure real-time visual data transmission, particularly in telemedicine and Internet of Things surveillance.</description>
	<pubDate>2026-06-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 101: Chaotic Image Encryption by Intra-Channel Diffusion and Inter-Channel Confusion</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/101">doi: 10.3390/jcp6030101</a></p>
	<p>Authors:
		Javier Alberto Vargas Valencia
		Carlos Alberto Marín Arango
		Jairo David García
		Rafael Uribe Guerra
		Luis Fernando Duque Gómez
		</p>
	<p>Most image encryption schemes exhibit one or more of the following limitations: keystream bias, high residual pixel correlation, pattern leakage, low sensitivity to key changes, or a security-efficiency trade-off. We present a robust image encryption framework based on a chaotic system that operates across the red, green, and blue color channels and mitigates all of the above vulnerabilities. The scheme consists of a novel integration of strong bidirectional modular diffusion, inter-channel confusion using a six-state permutation table, and Secure Hash Algorithm 256-based key derivation. Thus, we achieve the following: lossless reconstruction, near-ideal entropy, negligible adjacency correlation, high sensitivity to infinitesimal changes in both the plaintext and the secret key, a complete diffusion effect confirmed by standard differential metrics, and resilience against known- and chosen-plaintext attacks. Furthermore, the results comply with the National Institute of Standards and Technology randomness tests. These results are obtained with competitive encryption times (&amp;amp;sim;0.37 s for 512 &amp;amp;times; 512 images) without any code optimization. All of these features make the scheme promising for secure real-time visual data transmission, particularly in telemedicine and Internet of Things surveillance.</p>
	]]></content:encoded>

	<dc:title>Chaotic Image Encryption by Intra-Channel Diffusion and Inter-Channel Confusion</dc:title>
			<dc:creator>Javier Alberto Vargas Valencia</dc:creator>
			<dc:creator>Carlos Alberto Marín Arango</dc:creator>
			<dc:creator>Jairo David García</dc:creator>
			<dc:creator>Rafael Uribe Guerra</dc:creator>
			<dc:creator>Luis Fernando Duque Gómez</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030101</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>101</prism:startingPage>
		<prism:doi>10.3390/jcp6030101</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/101</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/100">

	<title>JCP, Vol. 6, Pages 100: Containment Invariants: Securing Intentionally Vulnerable Systems for Education, Training, and Research</title>
	<link>https://www.mdpi.com/2624-800X/6/3/100</link>
	<description>The rise of capture-the-flag (CTF) competitions and offensive security training requires the deployment of systems that are, by design, flawed. This creates a unique architectural paradox: how does one host a system intended to be compromised without compromising the host itself? This paper classifies the security principles of &amp;amp;ldquo;range engineering&amp;amp;rdquo;&amp;amp;mdash;the discipline of engineering the environment. This research study synthesizes evidence across the cyber-range, honeypot, ICS/OT testbed, and cloud-isolation literature to derive a containment-focused classification of threat planes, security invariants, boundary mechanisms and properties, and operational controls for intentionally vulnerable environments used in education, training, and research. Five security invariants are derived under the assumption of expected compromise and mapped to boundary families and measurable operational objectives. The analysis further identifies under-evidenced areas, particularly control-plane isolation, corrective controls for cross-tenant failures, and systematic validation of externalization defenses.</description>
	<pubDate>2026-06-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 100: Containment Invariants: Securing Intentionally Vulnerable Systems for Education, Training, and Research</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/100">doi: 10.3390/jcp6030100</a></p>
	<p>Authors:
		Stanislav Abaimov
		</p>
	<p>The rise of capture-the-flag (CTF) competitions and offensive security training requires the deployment of systems that are, by design, flawed. This creates a unique architectural paradox: how does one host a system intended to be compromised without compromising the host itself? This paper classifies the security principles of &amp;amp;ldquo;range engineering&amp;amp;rdquo;&amp;amp;mdash;the discipline of engineering the environment. This research study synthesizes evidence across the cyber-range, honeypot, ICS/OT testbed, and cloud-isolation literature to derive a containment-focused classification of threat planes, security invariants, boundary mechanisms and properties, and operational controls for intentionally vulnerable environments used in education, training, and research. Five security invariants are derived under the assumption of expected compromise and mapped to boundary families and measurable operational objectives. The analysis further identifies under-evidenced areas, particularly control-plane isolation, corrective controls for cross-tenant failures, and systematic validation of externalization defenses.</p>
	]]></content:encoded>

	<dc:title>Containment Invariants: Securing Intentionally Vulnerable Systems for Education, Training, and Research</dc:title>
			<dc:creator>Stanislav Abaimov</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030100</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>100</prism:startingPage>
		<prism:doi>10.3390/jcp6030100</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/100</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/99">

	<title>JCP, Vol. 6, Pages 99: SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls</title>
	<link>https://www.mdpi.com/2624-800X/6/3/99</link>
	<description>The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings.</description>
	<pubDate>2026-06-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 99: SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/99">doi: 10.3390/jcp6030099</a></p>
	<p>Authors:
		Lalie Arnoud
		Victor Breux
		Pierre-Henri Thevenon
		Éric Gaussier
		</p>
	<p>The increase and professionalization of cyberattacks calls for the development of relevant defense-in-depth mechanisms of which intrusion detection systems (IDSs) are essential components. This paper provides an in-depth analysis of system call-based IDSs as intelligence for detecting malicious activities. A systematic analysis of 209 publications from the scientific literature between 1996 and early 2026 highlights trends in this field of research and defines a taxonomy presenting the different approaches proposed by researchers. Eighteen state-of-the-art methods, representative of the diversity of approaches proposed in the literature, were reproduced and evaluated on two public datasets, ADFA-LD and NGIDS-DS. The detection performance and overhead of each method are examined in great detail, opening discussions on the shortcomings of the state of the art, limitations of system call-based IDSs, and lines of research that would enable this type of detection system to meet the challenges of deployment in a real-world environment. Finally, recommendations for future work are derived from these findings.</p>
	]]></content:encoded>

	<dc:title>SoK: An In-Depth Analysis of Intrusion Detection Systems Based on System Calls</dc:title>
			<dc:creator>Lalie Arnoud</dc:creator>
			<dc:creator>Victor Breux</dc:creator>
			<dc:creator>Pierre-Henri Thevenon</dc:creator>
			<dc:creator>Éric Gaussier</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030099</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>99</prism:startingPage>
		<prism:doi>10.3390/jcp6030099</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/99</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/98">

	<title>JCP, Vol. 6, Pages 98: Towards Responsible AI for IoT Network Security Auditing Using Knowledge Graph and RAGAS</title>
	<link>https://www.mdpi.com/2624-800X/6/3/98</link>
	<description>The trustworthiness of AI-powered network security auditing depends not only on detection accuracy but on the faithfulness of the explanations that support compliance verdicts. In IoT network security, Large Language Models (LLMs) are increasingly utilized to produce natural-language security assessments from raw network traffic, yet the extent to which these explanations are grounded in retrieved evidence is rarely measured. This paper presents the Retrieval-Augmented Generation Assessment Suite (RAGAS) as an evaluation framework that compares three retrieval paradigms&amp;amp;mdash;rule-based heuristic scoring, dense vector retrieval, and knowledge graph traversal&amp;amp;mdash;on the task of explaining network compliance against ETSI EN 303 645 IoT cybersecurity provisions. Using 30 human expert-validated compliance scenarios derived from the CIC-IoT2023 dataset and three LLMs (DeepSeek-R1, Qwen-2.5, Llama-3.2), we find that graph-based retrieval achieves the highest faithfulness (0.570), outperforming rule-based (0.524) and vector retrieval (0.509). All methods, however, exhibit low context recall (&amp;amp;le;22.4%), and we highlight that high detection F1 scores do not guarantee faithful explanations; over 40% of statements in compliance answers are unsupported by retrieved evidence. A proof-of-concept prototype, Security Audit Compliance Agent (SACA), demonstrates how knowledge graph traversal can be integrated with interactive visualization to support human auditor oversight. We argue that, in adherence to responsible AI principles, faithfulness measurement should become a standard complement to accuracy reporting for an AI-driven network audit or forensic analysis.</description>
	<pubDate>2026-06-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 98: Towards Responsible AI for IoT Network Security Auditing Using Knowledge Graph and RAGAS</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/98">doi: 10.3390/jcp6030098</a></p>
	<p>Authors:
		Obrina Briliyant
		Amir Javed
		Yulia Cherdantseva
		</p>
	<p>The trustworthiness of AI-powered network security auditing depends not only on detection accuracy but on the faithfulness of the explanations that support compliance verdicts. In IoT network security, Large Language Models (LLMs) are increasingly utilized to produce natural-language security assessments from raw network traffic, yet the extent to which these explanations are grounded in retrieved evidence is rarely measured. This paper presents the Retrieval-Augmented Generation Assessment Suite (RAGAS) as an evaluation framework that compares three retrieval paradigms&amp;amp;mdash;rule-based heuristic scoring, dense vector retrieval, and knowledge graph traversal&amp;amp;mdash;on the task of explaining network compliance against ETSI EN 303 645 IoT cybersecurity provisions. Using 30 human expert-validated compliance scenarios derived from the CIC-IoT2023 dataset and three LLMs (DeepSeek-R1, Qwen-2.5, Llama-3.2), we find that graph-based retrieval achieves the highest faithfulness (0.570), outperforming rule-based (0.524) and vector retrieval (0.509). All methods, however, exhibit low context recall (&amp;amp;le;22.4%), and we highlight that high detection F1 scores do not guarantee faithful explanations; over 40% of statements in compliance answers are unsupported by retrieved evidence. A proof-of-concept prototype, Security Audit Compliance Agent (SACA), demonstrates how knowledge graph traversal can be integrated with interactive visualization to support human auditor oversight. We argue that, in adherence to responsible AI principles, faithfulness measurement should become a standard complement to accuracy reporting for an AI-driven network audit or forensic analysis.</p>
	]]></content:encoded>

	<dc:title>Towards Responsible AI for IoT Network Security Auditing Using Knowledge Graph and RAGAS</dc:title>
			<dc:creator>Obrina Briliyant</dc:creator>
			<dc:creator>Amir Javed</dc:creator>
			<dc:creator>Yulia Cherdantseva</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030098</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>98</prism:startingPage>
		<prism:doi>10.3390/jcp6030098</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/98</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/97">

	<title>JCP, Vol. 6, Pages 97: Deep Neural Network Architectures for Fake News and Misinformation Detection</title>
	<link>https://www.mdpi.com/2624-800X/6/3/97</link>
	<description>The prompt spread of misleading information through recent information and communication technologies (ICT) admonishes social convention and credence. Developing trustworthy algorithms that can automatically identify fake content becomes increasingly difficult. We investigate a hybrid artificial intelligence (AI) strategy that integrates machine learning (ML) and deep learning (DL) to enhance fake news detection. The model&amp;amp;rsquo;s deep learning entity evaluates confined text arrangements and inclusive text values using a Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) with an attention layer. Conventional machine learning classifiers, mostly Support Vector Machine (SVM), Random Forest (RF), and Logistic Regression (LR), are trained synchronously employing Term Frequency&amp;amp;ndash;Inverse Document Frequency (TF-IDF). A simple ensemble averaging strategy is used on both machine learning and deep learning predictions. The model demonstrates strong generalization across various text types when evaluated on the LIAR dataset and a Kaggle-style fake news dataset. The combined system performs noticeably better than each of the separate models in terms of accuracy, precision, recall, F1, and AUC.</description>
	<pubDate>2026-06-05</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 97: Deep Neural Network Architectures for Fake News and Misinformation Detection</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/97">doi: 10.3390/jcp6030097</a></p>
	<p>Authors:
		Mariam Ibrahim
		Ruba Elhafiz
		</p>
	<p>The prompt spread of misleading information through recent information and communication technologies (ICT) admonishes social convention and credence. Developing trustworthy algorithms that can automatically identify fake content becomes increasingly difficult. We investigate a hybrid artificial intelligence (AI) strategy that integrates machine learning (ML) and deep learning (DL) to enhance fake news detection. The model&amp;amp;rsquo;s deep learning entity evaluates confined text arrangements and inclusive text values using a Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) with an attention layer. Conventional machine learning classifiers, mostly Support Vector Machine (SVM), Random Forest (RF), and Logistic Regression (LR), are trained synchronously employing Term Frequency&amp;amp;ndash;Inverse Document Frequency (TF-IDF). A simple ensemble averaging strategy is used on both machine learning and deep learning predictions. The model demonstrates strong generalization across various text types when evaluated on the LIAR dataset and a Kaggle-style fake news dataset. The combined system performs noticeably better than each of the separate models in terms of accuracy, precision, recall, F1, and AUC.</p>
	]]></content:encoded>

	<dc:title>Deep Neural Network Architectures for Fake News and Misinformation Detection</dc:title>
			<dc:creator>Mariam Ibrahim</dc:creator>
			<dc:creator>Ruba Elhafiz</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030097</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-05</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-05</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>97</prism:startingPage>
		<prism:doi>10.3390/jcp6030097</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/97</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/96">

	<title>JCP, Vol. 6, Pages 96: Enhancing Data Privacy in Large Language Models Through Private Association Editing</title>
	<link>https://www.mdpi.com/2624-800X/6/3/96</link>
	<description>Large language models (LLMs) require a significant redesign in solutions to preserve privacy in data-intensive applications due to their text-generation capabilities. Indeed, LLMs tend to memorize and emit private information when maliciously prompted. In this paper, we introduce Private Association Editing (PAE) as a novel defense approach for private data leakage. PAE is designed to effectively remove Personally Identifiable Information (PII) without retraining the model. We experimented on three open-weight, open-data models&amp;amp;mdash;GPT-Neo 1.3B, GPT-Neo 2.7B, and GPT-J&amp;amp;mdash;by applying Training Data Extraction (TDE) attacks to retrieve hundreds of PII, including email addresses, phone numbers, and Twitter handles. Since these models were trained on Pile, an openly available pre-training dataset, it is possible to verify the true extent of the data leakage. While all three models tend to leak PII under TDE attacks, experimental results demonstrate the effectiveness of PAE with respect to alternative baseline methods in defending against those attacks. In fact, unlike other techniques that tend to degrade model performance, our experiments show that PAE consistently reduces the number of leakages without affecting the model&amp;amp;rsquo;s utility. We believe PAE will serve as a practical tool for removing memorized PII from deployed LLMs without retraining.</description>
	<pubDate>2026-06-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 96: Enhancing Data Privacy in Large Language Models Through Private Association Editing</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/96">doi: 10.3390/jcp6030096</a></p>
	<p>Authors:
		Davide Venditti
		Elena Sofia Ruzzetti
		Giancarlo A. Xompero
		Cristina Giannone
		Andrea Favalli
		Raniero Romagnoli
		Fabio Massimo Zanzotto
		</p>
	<p>Large language models (LLMs) require a significant redesign in solutions to preserve privacy in data-intensive applications due to their text-generation capabilities. Indeed, LLMs tend to memorize and emit private information when maliciously prompted. In this paper, we introduce Private Association Editing (PAE) as a novel defense approach for private data leakage. PAE is designed to effectively remove Personally Identifiable Information (PII) without retraining the model. We experimented on three open-weight, open-data models&amp;amp;mdash;GPT-Neo 1.3B, GPT-Neo 2.7B, and GPT-J&amp;amp;mdash;by applying Training Data Extraction (TDE) attacks to retrieve hundreds of PII, including email addresses, phone numbers, and Twitter handles. Since these models were trained on Pile, an openly available pre-training dataset, it is possible to verify the true extent of the data leakage. While all three models tend to leak PII under TDE attacks, experimental results demonstrate the effectiveness of PAE with respect to alternative baseline methods in defending against those attacks. In fact, unlike other techniques that tend to degrade model performance, our experiments show that PAE consistently reduces the number of leakages without affecting the model&amp;amp;rsquo;s utility. We believe PAE will serve as a practical tool for removing memorized PII from deployed LLMs without retraining.</p>
	]]></content:encoded>

	<dc:title>Enhancing Data Privacy in Large Language Models Through Private Association Editing</dc:title>
			<dc:creator>Davide Venditti</dc:creator>
			<dc:creator>Elena Sofia Ruzzetti</dc:creator>
			<dc:creator>Giancarlo A. Xompero</dc:creator>
			<dc:creator>Cristina Giannone</dc:creator>
			<dc:creator>Andrea Favalli</dc:creator>
			<dc:creator>Raniero Romagnoli</dc:creator>
			<dc:creator>Fabio Massimo Zanzotto</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030096</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-06-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-06-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>96</prism:startingPage>
		<prism:doi>10.3390/jcp6030096</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/96</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/95">

	<title>JCP, Vol. 6, Pages 95: Spectral &amp;amp; Memory Trade-Offs in Multiplexed Fourier Domain Chaotic Image Encryption</title>
	<link>https://www.mdpi.com/2624-800X/6/3/95</link>
	<description>This work presents a Fourier-domain encryption scheme for multiplexed image databases that integrates virtual-optical multiplexing with chaotic diffusion. By combining chaotic encryption with spectral-domain symmetry reduction, the proposed approach secures large multiplexed image datasets while reducing memory requirements and preserving reconstruction fidelity. A dataset of 2025 grayscale images (512&amp;amp;times;512 pixels) is multiplexed and encrypted using linear chaotic transformations applied separately to the amplitude (A) and phase (&amp;amp;#981;) components. To improve storage efficiency, the symmetry conditions of both spectral components are exploited, allowing a reduced portion of the Fourier plane to be stored while preserving accurate reconstruction. A performance landscape relating the correlation coefficient (CC), memory consumption, and the retained Fourier-plane percentage (FPP) is constructed to identify stable operating regions that balance reconstruction fidelity and compression under increasing multiplexing load. The encryption key consists of a 22-symbol ASCII string from which 84 seed parameters for a deterministic pseudorandom chaotic map are derived. Security and sensitivity analyses demonstrate strong key dependence and resistance to statistical attacks, while maintaining high reconstruction fidelity. The proposed scheme provides an efficient and scalable solution for secure large-scale image repositories.</description>
	<pubDate>2026-05-29</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 95: Spectral &amp;amp; Memory Trade-Offs in Multiplexed Fourier Domain Chaotic Image Encryption</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/95">doi: 10.3390/jcp6030095</a></p>
	<p>Authors:
		Javier Alberto Vargas Valencia
		Luis Fernando Duque Gómez
		Carlos Alberto Marín Arango
		Mauricio A. Londoño-Arboleda
		Hernán David Salinas Jiménez
		</p>
	<p>This work presents a Fourier-domain encryption scheme for multiplexed image databases that integrates virtual-optical multiplexing with chaotic diffusion. By combining chaotic encryption with spectral-domain symmetry reduction, the proposed approach secures large multiplexed image datasets while reducing memory requirements and preserving reconstruction fidelity. A dataset of 2025 grayscale images (512&amp;amp;times;512 pixels) is multiplexed and encrypted using linear chaotic transformations applied separately to the amplitude (A) and phase (&amp;amp;#981;) components. To improve storage efficiency, the symmetry conditions of both spectral components are exploited, allowing a reduced portion of the Fourier plane to be stored while preserving accurate reconstruction. A performance landscape relating the correlation coefficient (CC), memory consumption, and the retained Fourier-plane percentage (FPP) is constructed to identify stable operating regions that balance reconstruction fidelity and compression under increasing multiplexing load. The encryption key consists of a 22-symbol ASCII string from which 84 seed parameters for a deterministic pseudorandom chaotic map are derived. Security and sensitivity analyses demonstrate strong key dependence and resistance to statistical attacks, while maintaining high reconstruction fidelity. The proposed scheme provides an efficient and scalable solution for secure large-scale image repositories.</p>
	]]></content:encoded>

	<dc:title>Spectral &amp;amp;amp; Memory Trade-Offs in Multiplexed Fourier Domain Chaotic Image Encryption</dc:title>
			<dc:creator>Javier Alberto Vargas Valencia</dc:creator>
			<dc:creator>Luis Fernando Duque Gómez</dc:creator>
			<dc:creator>Carlos Alberto Marín Arango</dc:creator>
			<dc:creator>Mauricio A. Londoño-Arboleda</dc:creator>
			<dc:creator>Hernán David Salinas Jiménez</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030095</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-29</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-29</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>95</prism:startingPage>
		<prism:doi>10.3390/jcp6030095</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/95</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/94">

	<title>JCP, Vol. 6, Pages 94: A Multi-Group Usability Evaluation of a Human-Centred Privacy and Permission Management Framework (MIDA)</title>
	<link>https://www.mdpi.com/2624-800X/6/3/94</link>
	<description>Users encounter privacy and permission settings across digital platforms, yet often struggle to understand, locate, and manage them effectively. Despite regulatory efforts such as the General Data Protection Regulation (GDPR) and platform mechanisms like App Tracking Transparency, these challenges persist due to interface design limitations rather than solely user capability. This study evaluates the My Information and Data Access (MIDA) framework, a user-centred privacy interface designed to support users with different levels of expertise. A between-subjects usability study was conducted with 44 participants (novice n = 15, intermediate n = 14, advanced n = 15), combining System Usability Scale (SUS) scores, task completion rates, error rates, and think-aloud protocols. The results show high usability across all groups, with SUS scores of 80 (novice), 84 (intermediate), and 92 (advanced), all exceeding the acceptability threshold of 68. Task completion rates exceeded 80%, whilst error rates remained below 25% across most tasks. These findings indicate that MIDA can support users in understanding, configuring, and managing privacy settings across different levels of expertise. This study builds on prior HCI research linking privacy management challenges to interface design limitations and provides empirical evidence that an expertise-adaptive interface can improve users&amp;amp;rsquo; ability to understand and manage privacy settings.</description>
	<pubDate>2026-05-22</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 94: A Multi-Group Usability Evaluation of a Human-Centred Privacy and Permission Management Framework (MIDA)</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/94">doi: 10.3390/jcp6030094</a></p>
	<p>Authors:
		Nourah Alshomrani
		Steven Furnell
		Helena Webb
		Alejandro Guerra-Manzanares
		</p>
	<p>Users encounter privacy and permission settings across digital platforms, yet often struggle to understand, locate, and manage them effectively. Despite regulatory efforts such as the General Data Protection Regulation (GDPR) and platform mechanisms like App Tracking Transparency, these challenges persist due to interface design limitations rather than solely user capability. This study evaluates the My Information and Data Access (MIDA) framework, a user-centred privacy interface designed to support users with different levels of expertise. A between-subjects usability study was conducted with 44 participants (novice n = 15, intermediate n = 14, advanced n = 15), combining System Usability Scale (SUS) scores, task completion rates, error rates, and think-aloud protocols. The results show high usability across all groups, with SUS scores of 80 (novice), 84 (intermediate), and 92 (advanced), all exceeding the acceptability threshold of 68. Task completion rates exceeded 80%, whilst error rates remained below 25% across most tasks. These findings indicate that MIDA can support users in understanding, configuring, and managing privacy settings across different levels of expertise. This study builds on prior HCI research linking privacy management challenges to interface design limitations and provides empirical evidence that an expertise-adaptive interface can improve users&amp;amp;rsquo; ability to understand and manage privacy settings.</p>
	]]></content:encoded>

	<dc:title>A Multi-Group Usability Evaluation of a Human-Centred Privacy and Permission Management Framework (MIDA)</dc:title>
			<dc:creator>Nourah Alshomrani</dc:creator>
			<dc:creator>Steven Furnell</dc:creator>
			<dc:creator>Helena Webb</dc:creator>
			<dc:creator>Alejandro Guerra-Manzanares</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030094</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-22</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-22</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>94</prism:startingPage>
		<prism:doi>10.3390/jcp6030094</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/94</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/93">

	<title>JCP, Vol. 6, Pages 93: Systematic Artefact-Based Review of Government Digital Identity Programmes: Alignment, Maturity and Transparency</title>
	<link>https://www.mdpi.com/2624-800X/6/3/93</link>
	<description>Digital identity is increasingly treated as foundational infrastructure for digital economies and public services, yet national approaches remain fragmented and difficult to compare. This study presents a PRISMA-guided systematic artefact-based review of government digital identity programmes, using programme-relevant government artefacts as the review corpus, including strategies, trust frameworks, guidance, service documentation, and identity-enabled public-service materials. Adapting an NLP pipeline for large-scale digital identity text analysis, the study identifies recurring themes, constructs comparative programme profiles, and operationalises three artefact-based measures: alignment, transparency, and maturity. Rather than assessing innovation performance or operational system quality directly, it examines the documentary layer through which programmes are described, justified, and made comparable. The analysis reveals substantial variation in how highly digitalised societies articulate governance, trust, interoperability, security, privacy, and service delivery. The review contributes a repeatable artefact-based framework for cross-jurisdictional comparison and provides a baseline for ontology development and future triangulation against citizen perception, expert assessment, and technical evaluation.</description>
	<pubDate>2026-05-21</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 93: Systematic Artefact-Based Review of Government Digital Identity Programmes: Alignment, Maturity and Transparency</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/93">doi: 10.3390/jcp6030093</a></p>
	<p>Authors:
		Matthew Comb
		Andrew Martin
		</p>
	<p>Digital identity is increasingly treated as foundational infrastructure for digital economies and public services, yet national approaches remain fragmented and difficult to compare. This study presents a PRISMA-guided systematic artefact-based review of government digital identity programmes, using programme-relevant government artefacts as the review corpus, including strategies, trust frameworks, guidance, service documentation, and identity-enabled public-service materials. Adapting an NLP pipeline for large-scale digital identity text analysis, the study identifies recurring themes, constructs comparative programme profiles, and operationalises three artefact-based measures: alignment, transparency, and maturity. Rather than assessing innovation performance or operational system quality directly, it examines the documentary layer through which programmes are described, justified, and made comparable. The analysis reveals substantial variation in how highly digitalised societies articulate governance, trust, interoperability, security, privacy, and service delivery. The review contributes a repeatable artefact-based framework for cross-jurisdictional comparison and provides a baseline for ontology development and future triangulation against citizen perception, expert assessment, and technical evaluation.</p>
	]]></content:encoded>

	<dc:title>Systematic Artefact-Based Review of Government Digital Identity Programmes: Alignment, Maturity and Transparency</dc:title>
			<dc:creator>Matthew Comb</dc:creator>
			<dc:creator>Andrew Martin</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030093</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-21</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-21</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Systematic Review</prism:section>
	<prism:startingPage>93</prism:startingPage>
		<prism:doi>10.3390/jcp6030093</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/93</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/92">

	<title>JCP, Vol. 6, Pages 92: Design and Implementation of a Microgrid Testbed for Cybersecurity Analysis and Resilience Testing</title>
	<link>https://www.mdpi.com/2624-800X/6/3/92</link>
	<description>A microgrid is a localized distribution network composed of electricity users who have access to local renewable and other energy sources. While the utility grid plays a critical role in the nation&amp;amp;rsquo;s economy, security, and the well-being of its residents, connecting microgrids to the wider network via utility substations can introduce significant cybersecurity risks. Unlike most existing studies that rely on simulation, this research designs and implements a physical microgrid testbed to examine cybersecurity vulnerabilities in microgrid systems. We examine the impact of various cyberattacks&amp;amp;mdash;including denial of service (DoS) and communication hijacking&amp;amp;mdash;on microgrid operations, with a particular focus on system stability and communication networks. The findings reveal critical weaknesses within the existing communication infrastructure, providing valuable insights for designing more resilient and secure microgrids. This work offers a practical framework for addressing cybersecurity challenges in real-world industrial utility networks.</description>
	<pubDate>2026-05-20</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 92: Design and Implementation of a Microgrid Testbed for Cybersecurity Analysis and Resilience Testing</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/92">doi: 10.3390/jcp6030092</a></p>
	<p>Authors:
		Joseph Mikkelson
		Dominic G. De La Cerda
		Yanwei Wu
		Xiaoguang Ma
		</p>
	<p>A microgrid is a localized distribution network composed of electricity users who have access to local renewable and other energy sources. While the utility grid plays a critical role in the nation&amp;amp;rsquo;s economy, security, and the well-being of its residents, connecting microgrids to the wider network via utility substations can introduce significant cybersecurity risks. Unlike most existing studies that rely on simulation, this research designs and implements a physical microgrid testbed to examine cybersecurity vulnerabilities in microgrid systems. We examine the impact of various cyberattacks&amp;amp;mdash;including denial of service (DoS) and communication hijacking&amp;amp;mdash;on microgrid operations, with a particular focus on system stability and communication networks. The findings reveal critical weaknesses within the existing communication infrastructure, providing valuable insights for designing more resilient and secure microgrids. This work offers a practical framework for addressing cybersecurity challenges in real-world industrial utility networks.</p>
	]]></content:encoded>

	<dc:title>Design and Implementation of a Microgrid Testbed for Cybersecurity Analysis and Resilience Testing</dc:title>
			<dc:creator>Joseph Mikkelson</dc:creator>
			<dc:creator>Dominic G. De La Cerda</dc:creator>
			<dc:creator>Yanwei Wu</dc:creator>
			<dc:creator>Xiaoguang Ma</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030092</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-20</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-20</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>92</prism:startingPage>
		<prism:doi>10.3390/jcp6030092</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/92</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/90">

	<title>JCP, Vol. 6, Pages 90: Feature-Engineered Trojan Malware Detection on Windows-Based IoT Gateways Using a Custom Deep Neural Network and Automated Monitoring Pipeline</title>
	<link>https://www.mdpi.com/2624-800X/6/3/90</link>
	<description>The growth of Internet of Things (IoT) environments has expanded the attack surface of modern systems. Trojan attacks are a major challenge as they evade conventional detection mechanisms and operate silently within legitimate processes. This paper presents an automated Trojan detection framework for Windows-based IoT gateways. The framework combines custom dataset generation informative feature engineering and deep learning-driven analysis. A dataset of 3000 real world executable samples was created through controlled sandbox execution and forensic monitoring. The process captured behavioral static and network-level characteristics. An initial set contained 146 extracted features. A multi-stage feature selection process identified 33 informative attributes. This step allowed efficient learning and preserved discriminative power. A custom deep neural network model named TrDNN was developed using these features. The model captures complex nonlinear patterns linked to Trojan activity. The framework was evaluated against five classical machine learning models. It was also compared with five deep learning baselines. Results show that TrDNN achieves strong detection performance. The accuracy is 0.975. The precision is 0.972. The recall is 0.969. The F1 score is 0.970. The study also examines inference time and energy consumption. The model shows a balance between detection effectiveness, computational cost and energy efficiency. This makes it suitable for resource-constrained IoT gateway deployment. The detection model was integrated into an automated real-time monitoring pipeline. The system enables continuous process surveillance through Windows command line automation with minimal operational overhead. Statistical validation used paired t tests, Wilcoxon signed rank tests and McNemar chi-square test. The performance gains are statistically significant and do not indicate overfitting. The framework provides a reliable, efficient and deployable solution for Trojan detection in modern IoT systems.</description>
	<pubDate>2026-05-19</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 90: Feature-Engineered Trojan Malware Detection on Windows-Based IoT Gateways Using a Custom Deep Neural Network and Automated Monitoring Pipeline</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/90">doi: 10.3390/jcp6030090</a></p>
	<p>Authors:
		Mazdak Maghanaki
		Mohammad Shahin
		Soraya Keramati
		F. Frank Chen
		Enrique Contreras
		</p>
	<p>The growth of Internet of Things (IoT) environments has expanded the attack surface of modern systems. Trojan attacks are a major challenge as they evade conventional detection mechanisms and operate silently within legitimate processes. This paper presents an automated Trojan detection framework for Windows-based IoT gateways. The framework combines custom dataset generation informative feature engineering and deep learning-driven analysis. A dataset of 3000 real world executable samples was created through controlled sandbox execution and forensic monitoring. The process captured behavioral static and network-level characteristics. An initial set contained 146 extracted features. A multi-stage feature selection process identified 33 informative attributes. This step allowed efficient learning and preserved discriminative power. A custom deep neural network model named TrDNN was developed using these features. The model captures complex nonlinear patterns linked to Trojan activity. The framework was evaluated against five classical machine learning models. It was also compared with five deep learning baselines. Results show that TrDNN achieves strong detection performance. The accuracy is 0.975. The precision is 0.972. The recall is 0.969. The F1 score is 0.970. The study also examines inference time and energy consumption. The model shows a balance between detection effectiveness, computational cost and energy efficiency. This makes it suitable for resource-constrained IoT gateway deployment. The detection model was integrated into an automated real-time monitoring pipeline. The system enables continuous process surveillance through Windows command line automation with minimal operational overhead. Statistical validation used paired t tests, Wilcoxon signed rank tests and McNemar chi-square test. The performance gains are statistically significant and do not indicate overfitting. The framework provides a reliable, efficient and deployable solution for Trojan detection in modern IoT systems.</p>
	]]></content:encoded>

	<dc:title>Feature-Engineered Trojan Malware Detection on Windows-Based IoT Gateways Using a Custom Deep Neural Network and Automated Monitoring Pipeline</dc:title>
			<dc:creator>Mazdak Maghanaki</dc:creator>
			<dc:creator>Mohammad Shahin</dc:creator>
			<dc:creator>Soraya Keramati</dc:creator>
			<dc:creator>F. Frank Chen</dc:creator>
			<dc:creator>Enrique Contreras</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030090</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-19</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-19</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>90</prism:startingPage>
		<prism:doi>10.3390/jcp6030090</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/90</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/91">

	<title>JCP, Vol. 6, Pages 91: Connecting the Dots: A Systematic Literature Review of Explainable AI, Cybersecurity, Human-Centered Design and Edge Computing</title>
	<link>https://www.mdpi.com/2624-800X/6/3/91</link>
	<description>The incorporation of Artificial Intelligence (AI) into cybersecurity has become widespread, largely propelled by the emergence of Generative AI (GenAI) and Large Language Models (LLMs). While these technologies promise to revolutionize threat detection, they introduce profound challenges regarding explainability, trust, and deployment feasibility in resource-constrained environments. Current research often exhibits a form of technological determinism, prioritizing algorithmic performance over the operational realities of Security Operations Centers (SOCs). This paper presents a hybrid qualitative Systematic Literature Review (SLR) and Mapping Study, adhering to the Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) 2020 guidelines. Our research questions are narrowly focused, seeking to explore how four key domains intersect: (1) Explainable AI (XAI) methods; (2) cybersecurity operations; (3) human-centered design; and (4) the constraints inherent to edge computing. From an initial corpus of 385 records drawn from Scopus and OpenAlex (spanning a search window from 2014 to 2025, with relevant findings heavily clustered in the 2020&amp;amp;ndash;2025 period), included studies were evaluated using a quality assessment protocol adapted from Kitchenham&amp;amp;rsquo;s guidelines, scoring each study on a 0&amp;amp;ndash;24 scale across four dimensions (Venue Quality, Methodological Rigor, Dataset Realism, and Depth of XAI/Human Validation). The results reveal a significant &amp;amp;ldquo;validation gap&amp;amp;rdquo;: while 63% of studies claim human-centric relevance, only ~22% incorporate empirical validation with human operators. Furthermore, we identify a critical trade-off between the reasoning power of cloud-based LLMs and the privacy requirements of Edge security. We conclude by proposing a research agenda for &amp;amp;ldquo;Cognitive SOCs&amp;amp;rdquo;, emphasizing the need for Small Language Models (SLMs), standardized human-centric metrics, and robust hallucination detection mechanisms.</description>
	<pubDate>2026-05-19</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 91: Connecting the Dots: A Systematic Literature Review of Explainable AI, Cybersecurity, Human-Centered Design and Edge Computing</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/91">doi: 10.3390/jcp6030091</a></p>
	<p>Authors:
		Gaia Cecchi
		Fabrizio Benelli
		Mario Caronna
		Giulia Palma
		Antonio Rizzo
		</p>
	<p>The incorporation of Artificial Intelligence (AI) into cybersecurity has become widespread, largely propelled by the emergence of Generative AI (GenAI) and Large Language Models (LLMs). While these technologies promise to revolutionize threat detection, they introduce profound challenges regarding explainability, trust, and deployment feasibility in resource-constrained environments. Current research often exhibits a form of technological determinism, prioritizing algorithmic performance over the operational realities of Security Operations Centers (SOCs). This paper presents a hybrid qualitative Systematic Literature Review (SLR) and Mapping Study, adhering to the Preferred Reporting Items for Systematic reviews and Meta-Analyses (PRISMA) 2020 guidelines. Our research questions are narrowly focused, seeking to explore how four key domains intersect: (1) Explainable AI (XAI) methods; (2) cybersecurity operations; (3) human-centered design; and (4) the constraints inherent to edge computing. From an initial corpus of 385 records drawn from Scopus and OpenAlex (spanning a search window from 2014 to 2025, with relevant findings heavily clustered in the 2020&amp;amp;ndash;2025 period), included studies were evaluated using a quality assessment protocol adapted from Kitchenham&amp;amp;rsquo;s guidelines, scoring each study on a 0&amp;amp;ndash;24 scale across four dimensions (Venue Quality, Methodological Rigor, Dataset Realism, and Depth of XAI/Human Validation). The results reveal a significant &amp;amp;ldquo;validation gap&amp;amp;rdquo;: while 63% of studies claim human-centric relevance, only ~22% incorporate empirical validation with human operators. Furthermore, we identify a critical trade-off between the reasoning power of cloud-based LLMs and the privacy requirements of Edge security. We conclude by proposing a research agenda for &amp;amp;ldquo;Cognitive SOCs&amp;amp;rdquo;, emphasizing the need for Small Language Models (SLMs), standardized human-centric metrics, and robust hallucination detection mechanisms.</p>
	]]></content:encoded>

	<dc:title>Connecting the Dots: A Systematic Literature Review of Explainable AI, Cybersecurity, Human-Centered Design and Edge Computing</dc:title>
			<dc:creator>Gaia Cecchi</dc:creator>
			<dc:creator>Fabrizio Benelli</dc:creator>
			<dc:creator>Mario Caronna</dc:creator>
			<dc:creator>Giulia Palma</dc:creator>
			<dc:creator>Antonio Rizzo</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030091</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-19</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-19</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Systematic Review</prism:section>
	<prism:startingPage>91</prism:startingPage>
		<prism:doi>10.3390/jcp6030091</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/91</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/89">

	<title>JCP, Vol. 6, Pages 89: Recovering Error-Free Cryptographic Keys from Noisy Quantum Key Distribution and Independent Eavesdropper Detection on the Receiving End</title>
	<link>https://www.mdpi.com/2624-800X/6/3/89</link>
	<description>This work considers the performance and feasibility of a challenge-response pair (CRP)-based key generation method integrated with multi-wavelength Quantum Key Distribution (QKD). In this design, Alice and Bob use independently derived information from the CRP mechanism to encode and recover the key without disclosing helper data. Simulations show that even when up to 40% of the data is corrupted, error-free key recovery is possible with longer response lengths. Another new advantage of this method is that eavesdropper detection is performed using only the statistics of the received quantum stream, as opposed to sacrificing a portion of the key for public comparison, as is required in other QKD schemes. The CRP mechanism and encoding scheme are explained, and the results of key recovery and error detection across various levels of data corruption are presented. The results show that according to the studied conditions, reliable key recovery and eavesdropper detection are possible without publicly comparing the key or using helper data, and it suggests that this approach can reduce classical reconciliation reliance and allow for reliable key recovery in noisy settings without extending security thresholds.</description>
	<pubDate>2026-05-14</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 89: Recovering Error-Free Cryptographic Keys from Noisy Quantum Key Distribution and Independent Eavesdropper Detection on the Receiving End</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/89">doi: 10.3390/jcp6030089</a></p>
	<p>Authors:
		Dina Ghanai Miandoab
		Brit Riggs
		Nicholas Paul Navas
		Bertrand Cambou
		</p>
	<p>This work considers the performance and feasibility of a challenge-response pair (CRP)-based key generation method integrated with multi-wavelength Quantum Key Distribution (QKD). In this design, Alice and Bob use independently derived information from the CRP mechanism to encode and recover the key without disclosing helper data. Simulations show that even when up to 40% of the data is corrupted, error-free key recovery is possible with longer response lengths. Another new advantage of this method is that eavesdropper detection is performed using only the statistics of the received quantum stream, as opposed to sacrificing a portion of the key for public comparison, as is required in other QKD schemes. The CRP mechanism and encoding scheme are explained, and the results of key recovery and error detection across various levels of data corruption are presented. The results show that according to the studied conditions, reliable key recovery and eavesdropper detection are possible without publicly comparing the key or using helper data, and it suggests that this approach can reduce classical reconciliation reliance and allow for reliable key recovery in noisy settings without extending security thresholds.</p>
	]]></content:encoded>

	<dc:title>Recovering Error-Free Cryptographic Keys from Noisy Quantum Key Distribution and Independent Eavesdropper Detection on the Receiving End</dc:title>
			<dc:creator>Dina Ghanai Miandoab</dc:creator>
			<dc:creator>Brit Riggs</dc:creator>
			<dc:creator>Nicholas Paul Navas</dc:creator>
			<dc:creator>Bertrand Cambou</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030089</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-14</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-14</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>89</prism:startingPage>
		<prism:doi>10.3390/jcp6030089</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/89</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/88">

	<title>JCP, Vol. 6, Pages 88: Recursive Augmented Fernet (RAF) Token: Alleviating the Pain of Stolen Tokens</title>
	<link>https://www.mdpi.com/2624-800X/6/3/88</link>
	<description>A robust authentication and authorization mechanism is imperative in modular system development, where modularity and modular thinking are pivotal. Traditional systems often employ identity modules responsible for authentication and token issuance. Tokens, representing user credentials, offer advantages such as reduced reliance on passwords, limited lifespan, and scoped access. Despite these benefits, the &amp;amp;ldquo;bearer token&amp;amp;rdquo; problem persists, leaving systems vulnerable to abuse if tokens are compromised. We propose a token-based authentication mechanism addressing the critical bearer token problem in modular systems. The proposed mechanism includes a novel RAF (Recursive Augmented Fernet) token, a blacklist component, and a policy enforcer component. RAF tokens are one-time-use tokens, like tickets. They carry commands, and the receiver of an RAF token can issue new tokens using the received RAF token. The blacklist component guarantees an RAF token cannot be validated more than once, and the policy enforcer checks the compatibility of commands carried by an RAF token. We introduce two variations of RAF tokens: user-tied RAF, offering simplicity and compatibility, and fully-tied RAF, providing enhanced security through service-specific secret keys. We thoroughly discuss the security guarantees, technical definitions, and construction of RAF tokens backed by game-based proofs. We demonstrate a proof of concept in the context of OpenStack, involving modifications to Keystone and the creation of an RAFT library. The experimental results reveal minimal overhead in typical scenarios, establishing the practicality and effectiveness of RAF. Our experiments show that the RAF mechanism outperforms the use of short-life Fernet tokens while providing much better security.</description>
	<pubDate>2026-05-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 88: Recursive Augmented Fernet (RAF) Token: Alleviating the Pain of Stolen Tokens</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/88">doi: 10.3390/jcp6030088</a></p>
	<p>Authors:
		Reza Rahaeimehr
		Marten van Dijk
		</p>
	<p>A robust authentication and authorization mechanism is imperative in modular system development, where modularity and modular thinking are pivotal. Traditional systems often employ identity modules responsible for authentication and token issuance. Tokens, representing user credentials, offer advantages such as reduced reliance on passwords, limited lifespan, and scoped access. Despite these benefits, the &amp;amp;ldquo;bearer token&amp;amp;rdquo; problem persists, leaving systems vulnerable to abuse if tokens are compromised. We propose a token-based authentication mechanism addressing the critical bearer token problem in modular systems. The proposed mechanism includes a novel RAF (Recursive Augmented Fernet) token, a blacklist component, and a policy enforcer component. RAF tokens are one-time-use tokens, like tickets. They carry commands, and the receiver of an RAF token can issue new tokens using the received RAF token. The blacklist component guarantees an RAF token cannot be validated more than once, and the policy enforcer checks the compatibility of commands carried by an RAF token. We introduce two variations of RAF tokens: user-tied RAF, offering simplicity and compatibility, and fully-tied RAF, providing enhanced security through service-specific secret keys. We thoroughly discuss the security guarantees, technical definitions, and construction of RAF tokens backed by game-based proofs. We demonstrate a proof of concept in the context of OpenStack, involving modifications to Keystone and the creation of an RAFT library. The experimental results reveal minimal overhead in typical scenarios, establishing the practicality and effectiveness of RAF. Our experiments show that the RAF mechanism outperforms the use of short-life Fernet tokens while providing much better security.</p>
	]]></content:encoded>

	<dc:title>Recursive Augmented Fernet (RAF) Token: Alleviating the Pain of Stolen Tokens</dc:title>
			<dc:creator>Reza Rahaeimehr</dc:creator>
			<dc:creator>Marten van Dijk</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030088</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>88</prism:startingPage>
		<prism:doi>10.3390/jcp6030088</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/88</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/87">

	<title>JCP, Vol. 6, Pages 87: Phase-First Gaussian Modulation for Resilient Continuous-Variable Quantum Communication Under Adversarial Disturbances</title>
	<link>https://www.mdpi.com/2624-800X/6/3/87</link>
	<description>Continuous-variable quantum communication (CVQC) operates under finite-resolution inference (finite data windows, calibration uncertainty, and estimator tolerances) and hardware control/readout limits that can be exploited by structured and adversarial disturbances. We study a feedback-inspired phase-space modulation strategy for implementation-layer resilience under DoS-like receiver-observable stress (e.g., fluctuation inflation, phase reference destabilization, or interface non-idealities), rather than proposing a protocol-level security proof. We propose a phase-first framework in which the defender selects a phase-space rotation angle &amp;amp;theta; (and, in principle, a squeezing parameter r) to minimize a receiver-observable centered second-moment degradation proxy, emphasizing containment rather than disturbance inversion. Because platforms expose different native observables, we evaluate phase-first modulation using two complementary tracks: (i) in theory/simulation, we monitor basis-dependent quadrature variance and covariance-derived summaries formed from mean-subtracted second moments so that &amp;amp;Delta;Ecov reflects covariance inflation rather than coherent displacement; (ii) in the X8_01 hardware workflow, the readout is Fock sampling; thus, we use the shot-to-shot standard deviation &amp;amp;sigma;N(&amp;amp;theta;):=Var^(N(&amp;amp;theta;)), where N(&amp;amp;theta;) denotes the shot-level detected count random variable at fixed &amp;amp;theta;. In the reported hardware workflow, this shot-level count is formed by aggregating the returned Fock counts prior to postprocessing. We emphasize that &amp;amp;sigma;N(&amp;amp;theta;) is not claimed to estimate Tr(V); it is an implementation-layer variability proxy aligned with the available readout. Our experimental validation is restricted to phase-only control instantiated as offline phase selection via one-dimensional grid search over &amp;amp;theta;. Across numerical simulations and hardware phase-angle scans on Xanadu&amp;amp;rsquo;s X8_01 photonic quantum processor, we find that static operating points can be brittle under strong DoS-like stress, whereas optimized phase selection can materially reduce a receiver-observed degradation proxy even without real-time feedback. Since Tr(V) is invariant under pure rotations for phase-independent additive noise and ideal photon-number probabilities are invariant under a terminal Fock-basis phase gate, any observed &amp;amp;theta;-dependence is interpreted operationally as evidence of a phase-dependent effective disturbance/measurement channel at the receiver interface. Simulation-only analyses indicate additional upside when squeezing is available, motivating future extensions incorporating higher-rate re-optimization, feedback-assisted architectures, and extended Gaussian control when available.</description>
	<pubDate>2026-05-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 87: Phase-First Gaussian Modulation for Resilient Continuous-Variable Quantum Communication Under Adversarial Disturbances</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/87">doi: 10.3390/jcp6030087</a></p>
	<p>Authors:
		José R. Rosas-Bustos
		Jesse Van Griensven Thé
		Roydon Andrew Fraser
		Nadeem Said
		Sebastian Ratto Valderrama
		Mark Pecen
		Alexander Truskovsky
		Andy Thanos
		</p>
	<p>Continuous-variable quantum communication (CVQC) operates under finite-resolution inference (finite data windows, calibration uncertainty, and estimator tolerances) and hardware control/readout limits that can be exploited by structured and adversarial disturbances. We study a feedback-inspired phase-space modulation strategy for implementation-layer resilience under DoS-like receiver-observable stress (e.g., fluctuation inflation, phase reference destabilization, or interface non-idealities), rather than proposing a protocol-level security proof. We propose a phase-first framework in which the defender selects a phase-space rotation angle &amp;amp;theta; (and, in principle, a squeezing parameter r) to minimize a receiver-observable centered second-moment degradation proxy, emphasizing containment rather than disturbance inversion. Because platforms expose different native observables, we evaluate phase-first modulation using two complementary tracks: (i) in theory/simulation, we monitor basis-dependent quadrature variance and covariance-derived summaries formed from mean-subtracted second moments so that &amp;amp;Delta;Ecov reflects covariance inflation rather than coherent displacement; (ii) in the X8_01 hardware workflow, the readout is Fock sampling; thus, we use the shot-to-shot standard deviation &amp;amp;sigma;N(&amp;amp;theta;):=Var^(N(&amp;amp;theta;)), where N(&amp;amp;theta;) denotes the shot-level detected count random variable at fixed &amp;amp;theta;. In the reported hardware workflow, this shot-level count is formed by aggregating the returned Fock counts prior to postprocessing. We emphasize that &amp;amp;sigma;N(&amp;amp;theta;) is not claimed to estimate Tr(V); it is an implementation-layer variability proxy aligned with the available readout. Our experimental validation is restricted to phase-only control instantiated as offline phase selection via one-dimensional grid search over &amp;amp;theta;. Across numerical simulations and hardware phase-angle scans on Xanadu&amp;amp;rsquo;s X8_01 photonic quantum processor, we find that static operating points can be brittle under strong DoS-like stress, whereas optimized phase selection can materially reduce a receiver-observed degradation proxy even without real-time feedback. Since Tr(V) is invariant under pure rotations for phase-independent additive noise and ideal photon-number probabilities are invariant under a terminal Fock-basis phase gate, any observed &amp;amp;theta;-dependence is interpreted operationally as evidence of a phase-dependent effective disturbance/measurement channel at the receiver interface. Simulation-only analyses indicate additional upside when squeezing is available, motivating future extensions incorporating higher-rate re-optimization, feedback-assisted architectures, and extended Gaussian control when available.</p>
	]]></content:encoded>

	<dc:title>Phase-First Gaussian Modulation for Resilient Continuous-Variable Quantum Communication Under Adversarial Disturbances</dc:title>
			<dc:creator>José R. Rosas-Bustos</dc:creator>
			<dc:creator>Jesse Van Griensven Thé</dc:creator>
			<dc:creator>Roydon Andrew Fraser</dc:creator>
			<dc:creator>Nadeem Said</dc:creator>
			<dc:creator>Sebastian Ratto Valderrama</dc:creator>
			<dc:creator>Mark Pecen</dc:creator>
			<dc:creator>Alexander Truskovsky</dc:creator>
			<dc:creator>Andy Thanos</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030087</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>87</prism:startingPage>
		<prism:doi>10.3390/jcp6030087</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/87</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/86">

	<title>JCP, Vol. 6, Pages 86: CryptoKANs+: KAN-Inspired Self-Learning Polynomial Networks for Efficient Privacy-Preserving Machine Learning</title>
	<link>https://www.mdpi.com/2624-800X/6/3/86</link>
	<description>Processing sensitive data in cloud-based neural networks raises privacy concerns, which Homomorphic Encryption addresses by enabling privacy-preserving machine learning. In our previous work, we introduced CryptoKANs, enabling efficient Kolmogorov&amp;amp;ndash;Arnold Network (KAN) inference over encrypted data via polynomial approximation of spline-based activation functions using KAN symbolization. To avoid performance degradation, CryptoKAN required min&amp;amp;ndash;max scaling of pre-activation inputs to a small interval&amp;amp;mdash;a requirement that could negatively affect training. In addition, a direct theoretical structural comparison with Multi-Layer Perceptron (MLP)-based solutions, such as CryptoNets, was missing. In this work, we address these limitations by presenting CryptoKAN+, a KAN-inspired network integrating self-learned polynomial activations through a Fully Connected Quadratic Transformation (FCQT) layer. By enforcing polynomial activations during training, this design replaces spline functions without post-training symbolization, eliminates the need for interval scaling, absorbs subsequent linear transformations, and reduces multiplicative depth for efficient encrypted inference. Experiments show that CryptoKAN+ achieves competitive accuracy while slightly improving encrypted inference efficiency&amp;amp;mdash;a natural consequence of compacting weights with self-learned activations. Overall, this work provides a formal analysis of the structural relationship between KANs and MLPs and demonstrates how enforcing polynomial activations during training enables efficient encrypted inference while preserving accuracy.</description>
	<pubDate>2026-05-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 86: CryptoKANs+: KAN-Inspired Self-Learning Polynomial Networks for Efficient Privacy-Preserving Machine Learning</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/86">doi: 10.3390/jcp6030086</a></p>
	<p>Authors:
		Omar Tahmi
		Chamseddine Talhi
		Hakima Ould-Slimane
		</p>
	<p>Processing sensitive data in cloud-based neural networks raises privacy concerns, which Homomorphic Encryption addresses by enabling privacy-preserving machine learning. In our previous work, we introduced CryptoKANs, enabling efficient Kolmogorov&amp;amp;ndash;Arnold Network (KAN) inference over encrypted data via polynomial approximation of spline-based activation functions using KAN symbolization. To avoid performance degradation, CryptoKAN required min&amp;amp;ndash;max scaling of pre-activation inputs to a small interval&amp;amp;mdash;a requirement that could negatively affect training. In addition, a direct theoretical structural comparison with Multi-Layer Perceptron (MLP)-based solutions, such as CryptoNets, was missing. In this work, we address these limitations by presenting CryptoKAN+, a KAN-inspired network integrating self-learned polynomial activations through a Fully Connected Quadratic Transformation (FCQT) layer. By enforcing polynomial activations during training, this design replaces spline functions without post-training symbolization, eliminates the need for interval scaling, absorbs subsequent linear transformations, and reduces multiplicative depth for efficient encrypted inference. Experiments show that CryptoKAN+ achieves competitive accuracy while slightly improving encrypted inference efficiency&amp;amp;mdash;a natural consequence of compacting weights with self-learned activations. Overall, this work provides a formal analysis of the structural relationship between KANs and MLPs and demonstrates how enforcing polynomial activations during training enables efficient encrypted inference while preserving accuracy.</p>
	]]></content:encoded>

	<dc:title>CryptoKANs+: KAN-Inspired Self-Learning Polynomial Networks for Efficient Privacy-Preserving Machine Learning</dc:title>
			<dc:creator>Omar Tahmi</dc:creator>
			<dc:creator>Chamseddine Talhi</dc:creator>
			<dc:creator>Hakima Ould-Slimane</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030086</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>86</prism:startingPage>
		<prism:doi>10.3390/jcp6030086</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/86</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/85">

	<title>JCP, Vol. 6, Pages 85: A Hybrid Blockchain-Based Framework for Adaptive Cyber-Risk Prediction and Multi-Layer Threat Mitigation in Enterprise Networks</title>
	<link>https://www.mdpi.com/2624-800X/6/3/85</link>
	<description>The environment of cybersecurity is changing at a higher rate than most automated defensive systems can keep pace with, and most enterprise-level solutions are based on a fixed set of rules or a black box with machine learning results. This leads to a loophole between identifying and controlling responses, particularly where the mitigation should demand accountability, proportionality, and justifiable reliability. Current AI&amp;amp;ndash;blockchain models enhance logging and detection and are seldom used to enforce adaptive, understandable, or risk-weighted response automation. It presents AGML, a hybrid governance-based defense framework that integrates blockchain mitigation execution with reinforcement-tuned prediction of cyber-risks. The system scores the risk continuously, mitigates severity depending on the situation, and recalculates behavior via a closed feedback mechanism. The blockchain layer is an enforcement boundary and not a passive ledger as all activities are auditable and not tamperable. The results of the evaluation show that there is a quantifiable increase in comparison with recent baselines: 96.48% detection accuracy, 95.22% precision, 94.65% recall, and a false-positive rate of 2.81. The average response latency was 312 ms and around 26 ms was due to governance validation. The system was also found to be stable in repeated adversarial cycles and exhibited stable convergence as opposed to drifting. These findings indicate that responsible and responsive automation, not rapid but uninhibited automation, could provide a more feasible solution to the resilient enterprise cybersecurity.</description>
	<pubDate>2026-05-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 85: A Hybrid Blockchain-Based Framework for Adaptive Cyber-Risk Prediction and Multi-Layer Threat Mitigation in Enterprise Networks</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/85">doi: 10.3390/jcp6030085</a></p>
	<p>Authors:
		Udit Mamodiya
		Indra Kishor
		Rahat Naz
		Mohammed Almaiah
		Amer Alqutaish
		</p>
	<p>The environment of cybersecurity is changing at a higher rate than most automated defensive systems can keep pace with, and most enterprise-level solutions are based on a fixed set of rules or a black box with machine learning results. This leads to a loophole between identifying and controlling responses, particularly where the mitigation should demand accountability, proportionality, and justifiable reliability. Current AI&amp;amp;ndash;blockchain models enhance logging and detection and are seldom used to enforce adaptive, understandable, or risk-weighted response automation. It presents AGML, a hybrid governance-based defense framework that integrates blockchain mitigation execution with reinforcement-tuned prediction of cyber-risks. The system scores the risk continuously, mitigates severity depending on the situation, and recalculates behavior via a closed feedback mechanism. The blockchain layer is an enforcement boundary and not a passive ledger as all activities are auditable and not tamperable. The results of the evaluation show that there is a quantifiable increase in comparison with recent baselines: 96.48% detection accuracy, 95.22% precision, 94.65% recall, and a false-positive rate of 2.81. The average response latency was 312 ms and around 26 ms was due to governance validation. The system was also found to be stable in repeated adversarial cycles and exhibited stable convergence as opposed to drifting. These findings indicate that responsible and responsive automation, not rapid but uninhibited automation, could provide a more feasible solution to the resilient enterprise cybersecurity.</p>
	]]></content:encoded>

	<dc:title>A Hybrid Blockchain-Based Framework for Adaptive Cyber-Risk Prediction and Multi-Layer Threat Mitigation in Enterprise Networks</dc:title>
			<dc:creator>Udit Mamodiya</dc:creator>
			<dc:creator>Indra Kishor</dc:creator>
			<dc:creator>Rahat Naz</dc:creator>
			<dc:creator>Mohammed Almaiah</dc:creator>
			<dc:creator>Amer Alqutaish</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030085</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>85</prism:startingPage>
		<prism:doi>10.3390/jcp6030085</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/85</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/84">

	<title>JCP, Vol. 6, Pages 84: Model Context Protocol Threat Modeling and Analysis of Vulnerabilities to Prompt Injection with Tool Poisoning</title>
	<link>https://www.mdpi.com/2624-800X/6/3/84</link>
	<description>The Model Context Protocol (MCP) has rapidly emerged as a universal standard for connecting AI assistants to external tools and data sources. While the MCP simplifies integration between AI applications and various services, it introduces significant security vulnerabilities, particularly on the client side. In this work, we conduct threat modelings of MCP implementations using STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and DREAD (Damage, Reproducibility, Exploitability, Affected Users, Discoverability) frameworks across six key components: MCP host, MCP client, LLM, MCP server, external data stores, and authorization server. This comprehensive analysis reveals tool poisoning&amp;amp;mdash;where malicious instructions are embedded in tool metadata&amp;amp;mdash;as the most prevalent and impactful client-side vulnerability. We therefore focus our empirical evaluation on this critical attack vector, providing a systematic comparison of how seven major MCP clients validate and defend against tool poisoning attacks. Our analysis reveals significant security issues with most tested clients due to insufficient static validation and parameter visibility. We propose a multi-layered defense strategy encompassing static metadata analysis, model decision path tracking, behavioral anomaly detection, and user transparency mechanisms. This research addresses a critical gap in MCP security, which has primarily focused on server-side vulnerabilities, and provides actionable recommendations and mitigation strategies for securing AI agent ecosystems.</description>
	<pubDate>2026-05-05</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 84: Model Context Protocol Threat Modeling and Analysis of Vulnerabilities to Prompt Injection with Tool Poisoning</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/84">doi: 10.3390/jcp6030084</a></p>
	<p>Authors:
		Charoes Huang
		Xin Huang
		Ngoc Phu Tran
		Amin Milani Fard
		</p>
	<p>The Model Context Protocol (MCP) has rapidly emerged as a universal standard for connecting AI assistants to external tools and data sources. While the MCP simplifies integration between AI applications and various services, it introduces significant security vulnerabilities, particularly on the client side. In this work, we conduct threat modelings of MCP implementations using STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and DREAD (Damage, Reproducibility, Exploitability, Affected Users, Discoverability) frameworks across six key components: MCP host, MCP client, LLM, MCP server, external data stores, and authorization server. This comprehensive analysis reveals tool poisoning&amp;amp;mdash;where malicious instructions are embedded in tool metadata&amp;amp;mdash;as the most prevalent and impactful client-side vulnerability. We therefore focus our empirical evaluation on this critical attack vector, providing a systematic comparison of how seven major MCP clients validate and defend against tool poisoning attacks. Our analysis reveals significant security issues with most tested clients due to insufficient static validation and parameter visibility. We propose a multi-layered defense strategy encompassing static metadata analysis, model decision path tracking, behavioral anomaly detection, and user transparency mechanisms. This research addresses a critical gap in MCP security, which has primarily focused on server-side vulnerabilities, and provides actionable recommendations and mitigation strategies for securing AI agent ecosystems.</p>
	]]></content:encoded>

	<dc:title>Model Context Protocol Threat Modeling and Analysis of Vulnerabilities to Prompt Injection with Tool Poisoning</dc:title>
			<dc:creator>Charoes Huang</dc:creator>
			<dc:creator>Xin Huang</dc:creator>
			<dc:creator>Ngoc Phu Tran</dc:creator>
			<dc:creator>Amin Milani Fard</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030084</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-05</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-05</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>84</prism:startingPage>
		<prism:doi>10.3390/jcp6030084</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/84</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/83">

	<title>JCP, Vol. 6, Pages 83: LDSEGoV: An Efficient Lightweight Digital-Signature Algorithm Based on CDLP and Provable Security for E-Governance Authentication</title>
	<link>https://www.mdpi.com/2624-800X/6/3/83</link>
	<description>Digital signatures serve as a crucial cryptographic primitive in an e-governance system for authenticating citizen-government interactions. Traditional methods (DSA, ECDSA) impose computational overhead on resource-limited endpoints and centralized verification servers. While complex-number cryptography provides theoretical efficiency through the Complex Discrete-Logarithm Problem (CDLP), prior works often fail to meet the requirements for real-world applications. This paper advances the knowledge in lightweight cryptography by introducing LDSEGoV, a lightweight digital signature scheme for e-governance infrastructure. The proposed method overcomes the shortcomings of previous methods by incorporating sound modular arithmetic for consistent verification, using NIST-approved hash functions. Furthermore, we provide a comprehensive security analysis, including formal proofs of existential unforgeability (EUF-CMA) for the proposed scheme in the Random Oracle Model. Additionally, the experimental results show a 6.5&amp;amp;times; improvement in signing performance and a 24.76&amp;amp;times; improvement in verification performance over ECDSA, with a 61% reduction in signature size. These results demonstrate computational efficiency suitable for e-governance authentication scenarios.</description>
	<pubDate>2026-05-05</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 83: LDSEGoV: An Efficient Lightweight Digital-Signature Algorithm Based on CDLP and Provable Security for E-Governance Authentication</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/83">doi: 10.3390/jcp6030083</a></p>
	<p>Authors:
		Seema Sirpal
		Pardeep Singh
		Om Pal
		</p>
	<p>Digital signatures serve as a crucial cryptographic primitive in an e-governance system for authenticating citizen-government interactions. Traditional methods (DSA, ECDSA) impose computational overhead on resource-limited endpoints and centralized verification servers. While complex-number cryptography provides theoretical efficiency through the Complex Discrete-Logarithm Problem (CDLP), prior works often fail to meet the requirements for real-world applications. This paper advances the knowledge in lightweight cryptography by introducing LDSEGoV, a lightweight digital signature scheme for e-governance infrastructure. The proposed method overcomes the shortcomings of previous methods by incorporating sound modular arithmetic for consistent verification, using NIST-approved hash functions. Furthermore, we provide a comprehensive security analysis, including formal proofs of existential unforgeability (EUF-CMA) for the proposed scheme in the Random Oracle Model. Additionally, the experimental results show a 6.5&amp;amp;times; improvement in signing performance and a 24.76&amp;amp;times; improvement in verification performance over ECDSA, with a 61% reduction in signature size. These results demonstrate computational efficiency suitable for e-governance authentication scenarios.</p>
	]]></content:encoded>

	<dc:title>LDSEGoV: An Efficient Lightweight Digital-Signature Algorithm Based on CDLP and Provable Security for E-Governance Authentication</dc:title>
			<dc:creator>Seema Sirpal</dc:creator>
			<dc:creator>Pardeep Singh</dc:creator>
			<dc:creator>Om Pal</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030083</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-05</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-05</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>83</prism:startingPage>
		<prism:doi>10.3390/jcp6030083</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/83</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/82">

	<title>JCP, Vol. 6, Pages 82: Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study</title>
	<link>https://www.mdpi.com/2624-800X/6/3/82</link>
	<description>The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated protocol analyses, or hard-to-replicate setups. This paper addresses that gap with two main contributions: a structured review of ten influential IoT security studies from the USENIX Security Symposium and a confirmatory empirical experiment deploying Cowrie and IoTPOT honeypots simultaneously on a Microsoft Azure cloud-based virtual machine. Unlike earlier studies that focus on single protocols or large-scale environments, this work acts as a validation study, confirming well-known IoT botnet behaviors, including credential brute-force attacks, Mirai-style commands, and Telnet dominance, using real-time attack data collected from a reproducible, affordable cloud environment that simulates known IoT vulnerabilities (such as CVE-2016-10401, CVE-2017-17215, and CVE-2014-9222). Rather than revealing new attack methods, this study explicitly verifies the persistence of behaviors first documented almost ten years ago. The data indicates that attackers continue to exploit basic authentication flaws and reuse long-standing command sequences, confirming that core IoT vulnerabilities remain prevalent despite a decade of security research. It also highlights the ongoing gap between research progress and industry implementation. The analysis situates these findings within the broader evolution of IoT botnets, from early centralized command-and-control structures like Mirai to more resilient peer-to-peer networks that use anonymized channels and target high-wattage devices for power-grid manipulation. This study shows that small, cloud-based honeypots are valuable for continuous threat monitoring, model validation, and security assessments, providing a practical, reproducible approach for ongoing IoT security research.</description>
	<pubDate>2026-05-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 82: Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/82">doi: 10.3390/jcp6030082</a></p>
	<p>Authors:
		Rajkumar Banoth
		Santosh Reddy Addula
		Aruna Kranthi Godishala
		Rithwik Sannapu
		Guna Sekhar Sajja
		Deepak Kumar
		Vinay Kumar Kasula
		Chaitanya Tumma
		</p>
	<p>The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated protocol analyses, or hard-to-replicate setups. This paper addresses that gap with two main contributions: a structured review of ten influential IoT security studies from the USENIX Security Symposium and a confirmatory empirical experiment deploying Cowrie and IoTPOT honeypots simultaneously on a Microsoft Azure cloud-based virtual machine. Unlike earlier studies that focus on single protocols or large-scale environments, this work acts as a validation study, confirming well-known IoT botnet behaviors, including credential brute-force attacks, Mirai-style commands, and Telnet dominance, using real-time attack data collected from a reproducible, affordable cloud environment that simulates known IoT vulnerabilities (such as CVE-2016-10401, CVE-2017-17215, and CVE-2014-9222). Rather than revealing new attack methods, this study explicitly verifies the persistence of behaviors first documented almost ten years ago. The data indicates that attackers continue to exploit basic authentication flaws and reuse long-standing command sequences, confirming that core IoT vulnerabilities remain prevalent despite a decade of security research. It also highlights the ongoing gap between research progress and industry implementation. The analysis situates these findings within the broader evolution of IoT botnets, from early centralized command-and-control structures like Mirai to more resilient peer-to-peer networks that use anonymized channels and target high-wattage devices for power-grid manipulation. This study shows that small, cloud-based honeypots are valuable for continuous threat monitoring, model validation, and security assessments, providing a practical, reproducible approach for ongoing IoT security research.</p>
	]]></content:encoded>

	<dc:title>Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study</dc:title>
			<dc:creator>Rajkumar Banoth</dc:creator>
			<dc:creator>Santosh Reddy Addula</dc:creator>
			<dc:creator>Aruna Kranthi Godishala</dc:creator>
			<dc:creator>Rithwik Sannapu</dc:creator>
			<dc:creator>Guna Sekhar Sajja</dc:creator>
			<dc:creator>Deepak Kumar</dc:creator>
			<dc:creator>Vinay Kumar Kasula</dc:creator>
			<dc:creator>Chaitanya Tumma</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030082</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>82</prism:startingPage>
		<prism:doi>10.3390/jcp6030082</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/82</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/81">

	<title>JCP, Vol. 6, Pages 81: A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems</title>
	<link>https://www.mdpi.com/2624-800X/6/3/81</link>
	<description>Industrial Control Systems (ICSs), which are essential components of critical infrastructures, are inherently complex and vulnerable to cyberattacks. Advanced Persistent Threats (APTs) that target these systems are multi-stage, coordinated attacks that can lead not only to information loss but also to physical damage and loss of life. Traditional threat modeling approaches fall short in adapting to the dynamic nature of ICSs, necessitating new methodologies to predict and prevent such complex attacks. This work presents a digital twin-assisted dynamic threat modeling framework for ICS environments. The framework leverages a knowledge graph that integrates system data and cyber threat intelligence to predict potential attacks. In addition, the digital twin environment enables the validation of mitigation strategies before deployment in the physical system, while also supporting adaptive response and real-time mitigation. To predict the attacker&amp;amp;rsquo;s next move, we propose a Relational Graph Convolutional Network (RGCN)-based model that utilizes enriched relational data such as tactics, campaigns, groups, techniques, and assets. The proposed RGCN model achieves a recall of 0.887, an F1-score of 0.893, and an AUC of 0.957 in predicting potential attack sequences. These results demonstrate that the model provides reliable and well-balanced predictive performance.</description>
	<pubDate>2026-05-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 81: A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/81">doi: 10.3390/jcp6030081</a></p>
	<p>Authors:
		Gizem Erceylan
		Doney Abraham
		Aida Akbarzadeh
		Vasileios Gkioulos
		Sandeep Pirbhulal
		</p>
	<p>Industrial Control Systems (ICSs), which are essential components of critical infrastructures, are inherently complex and vulnerable to cyberattacks. Advanced Persistent Threats (APTs) that target these systems are multi-stage, coordinated attacks that can lead not only to information loss but also to physical damage and loss of life. Traditional threat modeling approaches fall short in adapting to the dynamic nature of ICSs, necessitating new methodologies to predict and prevent such complex attacks. This work presents a digital twin-assisted dynamic threat modeling framework for ICS environments. The framework leverages a knowledge graph that integrates system data and cyber threat intelligence to predict potential attacks. In addition, the digital twin environment enables the validation of mitigation strategies before deployment in the physical system, while also supporting adaptive response and real-time mitigation. To predict the attacker&amp;amp;rsquo;s next move, we propose a Relational Graph Convolutional Network (RGCN)-based model that utilizes enriched relational data such as tactics, campaigns, groups, techniques, and assets. The proposed RGCN model achieves a recall of 0.887, an F1-score of 0.893, and an AUC of 0.957 in predicting potential attack sequences. These results demonstrate that the model provides reliable and well-balanced predictive performance.</p>
	]]></content:encoded>

	<dc:title>A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems</dc:title>
			<dc:creator>Gizem Erceylan</dc:creator>
			<dc:creator>Doney Abraham</dc:creator>
			<dc:creator>Aida Akbarzadeh</dc:creator>
			<dc:creator>Vasileios Gkioulos</dc:creator>
			<dc:creator>Sandeep Pirbhulal</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030081</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>81</prism:startingPage>
		<prism:doi>10.3390/jcp6030081</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/81</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/80">

	<title>JCP, Vol. 6, Pages 80: The Evaluation of a Double-Spend Attack Probability for Ouroboros-like Proof-of-Stake Consensus</title>
	<link>https://www.mdpi.com/2624-800X/6/3/80</link>
	<description>This paper studies the probability of a double-spend attack in an Ouroboros-like Proof-of-Stake (PoS) setting when confirmation decisions must be made for a finite number of blocks. Existing security analyses of Ouroboros-family protocols are mainly asymptotic and therefore do not directly provide the attack probability for a fixed confirmation depth. We consider an analytically tractable model that allows empty slots and multiple slot leaders, and assumes fixed stake distribution within an epoch, one-block growth of the public longest chain in any slot containing at least one honest leader, and next-slot block visibility. These assumptions hold when the time slot length is much greater than the network delay, and are applicable to practical deployment scenarios such as Cardano. Under these assumptions, for the first time, an exact closed-form solution for the success probability of a double-spend attack considering a realistic model with multiple leaders and empty time slots. Numerical examples illustrate how the required confirmation depth depends on the adversarial stake ratio and the active slot coefficient. The results apply to the stated analytical model and do not yet cover delayed fork resolution or the full protocol-level fork-choice and finality mechanisms of Ouroboros Praos.</description>
	<pubDate>2026-05-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 80: The Evaluation of a Double-Spend Attack Probability for Ouroboros-like Proof-of-Stake Consensus</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/80">doi: 10.3390/jcp6030080</a></p>
	<p>Authors:
		Lyudmila Kovalchuk
		Mariia Rodinko
		Roman Oliynykov
		Volodymyr Artemchuk
		</p>
	<p>This paper studies the probability of a double-spend attack in an Ouroboros-like Proof-of-Stake (PoS) setting when confirmation decisions must be made for a finite number of blocks. Existing security analyses of Ouroboros-family protocols are mainly asymptotic and therefore do not directly provide the attack probability for a fixed confirmation depth. We consider an analytically tractable model that allows empty slots and multiple slot leaders, and assumes fixed stake distribution within an epoch, one-block growth of the public longest chain in any slot containing at least one honest leader, and next-slot block visibility. These assumptions hold when the time slot length is much greater than the network delay, and are applicable to practical deployment scenarios such as Cardano. Under these assumptions, for the first time, an exact closed-form solution for the success probability of a double-spend attack considering a realistic model with multiple leaders and empty time slots. Numerical examples illustrate how the required confirmation depth depends on the adversarial stake ratio and the active slot coefficient. The results apply to the stated analytical model and do not yet cover delayed fork resolution or the full protocol-level fork-choice and finality mechanisms of Ouroboros Praos.</p>
	]]></content:encoded>

	<dc:title>The Evaluation of a Double-Spend Attack Probability for Ouroboros-like Proof-of-Stake Consensus</dc:title>
			<dc:creator>Lyudmila Kovalchuk</dc:creator>
			<dc:creator>Mariia Rodinko</dc:creator>
			<dc:creator>Roman Oliynykov</dc:creator>
			<dc:creator>Volodymyr Artemchuk</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030080</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>80</prism:startingPage>
		<prism:doi>10.3390/jcp6030080</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/80</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/79">

	<title>JCP, Vol. 6, Pages 79: Vertical Federated XGBoost with Privacy Preservation via Secure Multiparty Computation</title>
	<link>https://www.mdpi.com/2624-800X/6/3/79</link>
	<description>Gradient Boosted Decision Trees (GBDTs) are popular for their strong predictive performance. However, in domains like finance and healthcare, data are often distributed across organizations, making collaborative model training challenging due to privacy concerns. Vertical federated learning (VFL) enables such collaboration when data are split by features, but many existing methods focus on protecting raw data while exposing sensitive model information, such as gradients and Hessians&amp;amp;mdash;especially to the label-owning party. Techniques like Homomorphic Encryption and Secret Sharing help, but often rely on trusted or privileged parties and may still leak intermediate statistics. To address this, we propose MPC-XGB, a privacy-preserving framework for training XGBoost under VFL with an honest-but-curious threat model. It uses secure three-party computation with Replicated Secret Sharing, distributing data across non-colluding servers and performing all computations on shares. This ensures that raw data, labels, and model statistics remain hidden, while supporting both secure training and prediction. Experiments show that MPC-XGB achieves strong performance (0.93 accuracy, 0.82 AUC), comparable to that of existing methods, with improved privacy guarantees.</description>
	<pubDate>2026-05-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 79: Vertical Federated XGBoost with Privacy Preservation via Secure Multiparty Computation</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/79">doi: 10.3390/jcp6030079</a></p>
	<p>Authors:
		Asma Ramay
		Estrid He
		Mengmeng Yang
		Tabinda Sarwar
		Xinqian Wang
		Xun Yi
		</p>
	<p>Gradient Boosted Decision Trees (GBDTs) are popular for their strong predictive performance. However, in domains like finance and healthcare, data are often distributed across organizations, making collaborative model training challenging due to privacy concerns. Vertical federated learning (VFL) enables such collaboration when data are split by features, but many existing methods focus on protecting raw data while exposing sensitive model information, such as gradients and Hessians&amp;amp;mdash;especially to the label-owning party. Techniques like Homomorphic Encryption and Secret Sharing help, but often rely on trusted or privileged parties and may still leak intermediate statistics. To address this, we propose MPC-XGB, a privacy-preserving framework for training XGBoost under VFL with an honest-but-curious threat model. It uses secure three-party computation with Replicated Secret Sharing, distributing data across non-colluding servers and performing all computations on shares. This ensures that raw data, labels, and model statistics remain hidden, while supporting both secure training and prediction. Experiments show that MPC-XGB achieves strong performance (0.93 accuracy, 0.82 AUC), comparable to that of existing methods, with improved privacy guarantees.</p>
	]]></content:encoded>

	<dc:title>Vertical Federated XGBoost with Privacy Preservation via Secure Multiparty Computation</dc:title>
			<dc:creator>Asma Ramay</dc:creator>
			<dc:creator>Estrid He</dc:creator>
			<dc:creator>Mengmeng Yang</dc:creator>
			<dc:creator>Tabinda Sarwar</dc:creator>
			<dc:creator>Xinqian Wang</dc:creator>
			<dc:creator>Xun Yi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030079</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>79</prism:startingPage>
		<prism:doi>10.3390/jcp6030079</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/79</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/78">

	<title>JCP, Vol. 6, Pages 78: Empirical Evaluation of Android Browser Forensics and Artifact Persistence</title>
	<link>https://www.mdpi.com/2624-800X/6/3/78</link>
	<description>The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from popular mobile browsers (Chrome, Firefox, Tor, DuckDuckGo, and Brave) on authentic Android 13 devices. By utilizing a rooted environment to bypass application sandboxing, we introduce a standardized scoring framework to quantify and compare the residual digital footprints left across diverse usage scenarios, including standard browsing, manual data deletion, and private/incognito modes. The study details a hybrid acquisition methodology that integrates persistent storage analysis with custom volatile memory extraction routines to capture ephemeral process data. Through a suite of controlled, realistic scenarios&amp;amp;mdash;encompassing form filling, virtual transactions, and anti-forensic activities&amp;amp;mdash;the results demonstrate that significant portions of user activity remained recoverable within the tested and evaluated experimental environment and browser configurations despite aggressive privacy-enhancing measures. Our findings reveal that while private modes effectively minimize the persistent filesystem footprint, volatile memory remains a fertile source of cleartext credentials and session identifiers. This recovery is particularly pronounced in Chromium-based browsers, whereas privacy-centric alternatives like Tor exhibit higher forensic resilience. Ultimately, this research underscores the importance of volatile memory acquisition in mobile investigations and provides an experimental systematic approach for evaluating the trade-offs between browser usability and forensic traceability in contemporary Android environments, demonstrating potential applicability to subsequent Android iterations.</description>
	<pubDate>2026-05-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 78: Empirical Evaluation of Android Browser Forensics and Artifact Persistence</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/78">doi: 10.3390/jcp6030078</a></p>
	<p>Authors:
		Paraskevas Giannakopoulos
		Christos Smiliotopoulos
		Georgios Kambourakis
		</p>
	<p>The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from popular mobile browsers (Chrome, Firefox, Tor, DuckDuckGo, and Brave) on authentic Android 13 devices. By utilizing a rooted environment to bypass application sandboxing, we introduce a standardized scoring framework to quantify and compare the residual digital footprints left across diverse usage scenarios, including standard browsing, manual data deletion, and private/incognito modes. The study details a hybrid acquisition methodology that integrates persistent storage analysis with custom volatile memory extraction routines to capture ephemeral process data. Through a suite of controlled, realistic scenarios&amp;amp;mdash;encompassing form filling, virtual transactions, and anti-forensic activities&amp;amp;mdash;the results demonstrate that significant portions of user activity remained recoverable within the tested and evaluated experimental environment and browser configurations despite aggressive privacy-enhancing measures. Our findings reveal that while private modes effectively minimize the persistent filesystem footprint, volatile memory remains a fertile source of cleartext credentials and session identifiers. This recovery is particularly pronounced in Chromium-based browsers, whereas privacy-centric alternatives like Tor exhibit higher forensic resilience. Ultimately, this research underscores the importance of volatile memory acquisition in mobile investigations and provides an experimental systematic approach for evaluating the trade-offs between browser usability and forensic traceability in contemporary Android environments, demonstrating potential applicability to subsequent Android iterations.</p>
	]]></content:encoded>

	<dc:title>Empirical Evaluation of Android Browser Forensics and Artifact Persistence</dc:title>
			<dc:creator>Paraskevas Giannakopoulos</dc:creator>
			<dc:creator>Christos Smiliotopoulos</dc:creator>
			<dc:creator>Georgios Kambourakis</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030078</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-05-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-05-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>78</prism:startingPage>
		<prism:doi>10.3390/jcp6030078</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/78</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/3/77">

	<title>JCP, Vol. 6, Pages 77: IoT-Oriented Digital Signature Defense Against Single-Trace Belief Propagation Attacks in Post-Quantum Cryptography</title>
	<link>https://www.mdpi.com/2624-800X/6/3/77</link>
	<description>Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital signatures using only a single side-channel trace of the Number Theoretic Transform (NTT). This work introduces the Quantum-Randomized Number Theoretic Transform (QR-NTT), an implementation-level defense mechanism that integrates quantum-derived entropy directly into the execution flow of lattice-based signature algorithms. Rather than treating randomness as a static input, QR-NTT uses quantum entropy to introduce controlled variability in execution ordering, arithmetic factor usage, and memory access behavior while preserving mathematical correctness and constant-time execution. The proposed framework is designed for embedded platforms and remains compatible with existing post-quantum cryptographic standards and IoT communication protocols. A complete implementation on an ARM Cortex-M4 platform, coupled with commercial quantum random number generator (QRNG) hardware, demonstrates that QR-NTT significantly degrades the effectiveness of template matching and belief propagation attacks. Experimental evaluation shows a reduction in single-trace attack success rates from over 90% to below 3% and an increase of approximately two orders of magnitude in the number of traces required for successful key recovery. These security gains are achieved with moderate overheads of 18.3% in execution time and 1.8 KB of additional memory while remaining well within practical IoT constraints. The results indicate that quantum-derived entropy can be leveraged as a practical implementation-level defense against physical attacks, complementing algorithmic post-quantum security. QR-NTT demonstrates a viable path toward strengthening the real-world resilience of post-quantum IoT systems without sacrificing deployability.</description>
	<pubDate>2026-04-27</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 77: IoT-Oriented Digital Signature Defense Against Single-Trace Belief Propagation Attacks in Post-Quantum Cryptography</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/3/77">doi: 10.3390/jcp6030077</a></p>
	<p>Authors:
		Maksim Iavich
		Nursulu Kapalova
		</p>
	<p>Post-quantum cryptographic implementations in Internet-of-Things (IoT) devices are significantly threatened by physical side-channel attacks, where practical attack risks are increased by physical accessibility and resource limitations. In particular, recent work has shown that belief propagation-based attacks can recover secret keys from lattice-based digital signatures using only a single side-channel trace of the Number Theoretic Transform (NTT). This work introduces the Quantum-Randomized Number Theoretic Transform (QR-NTT), an implementation-level defense mechanism that integrates quantum-derived entropy directly into the execution flow of lattice-based signature algorithms. Rather than treating randomness as a static input, QR-NTT uses quantum entropy to introduce controlled variability in execution ordering, arithmetic factor usage, and memory access behavior while preserving mathematical correctness and constant-time execution. The proposed framework is designed for embedded platforms and remains compatible with existing post-quantum cryptographic standards and IoT communication protocols. A complete implementation on an ARM Cortex-M4 platform, coupled with commercial quantum random number generator (QRNG) hardware, demonstrates that QR-NTT significantly degrades the effectiveness of template matching and belief propagation attacks. Experimental evaluation shows a reduction in single-trace attack success rates from over 90% to below 3% and an increase of approximately two orders of magnitude in the number of traces required for successful key recovery. These security gains are achieved with moderate overheads of 18.3% in execution time and 1.8 KB of additional memory while remaining well within practical IoT constraints. The results indicate that quantum-derived entropy can be leveraged as a practical implementation-level defense against physical attacks, complementing algorithmic post-quantum security. QR-NTT demonstrates a viable path toward strengthening the real-world resilience of post-quantum IoT systems without sacrificing deployability.</p>
	]]></content:encoded>

	<dc:title>IoT-Oriented Digital Signature Defense Against Single-Trace Belief Propagation Attacks in Post-Quantum Cryptography</dc:title>
			<dc:creator>Maksim Iavich</dc:creator>
			<dc:creator>Nursulu Kapalova</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6030077</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-27</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-27</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>3</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>77</prism:startingPage>
		<prism:doi>10.3390/jcp6030077</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/3/77</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/76">

	<title>JCP, Vol. 6, Pages 76: An Ontology-Based Framework for Semantic Representation of the Cyber Range Domain</title>
	<link>https://www.mdpi.com/2624-800X/6/2/76</link>
	<description>Cyber Ranges (CRs) are complex socio-technical ecosystems, combining infrastructure resources, software services, learning mechanisms, and human-in-the-loop processes for cybersecurity training, education, and experimentation. However, their design and representation are conventionally described by diverse architectural representations and a lack of standardization, making them difficult to compare, integrate, and reason in an automated manner. This paper proposes a novel framework that uniquely integrates the structural, functional, informational, and decisional aspects of CR platforms, formalizing them into a common semantic framework. It models the architectural and learning characteristics of CRs, allowing the representation of design choices, operational processes, information resources, and capability development. The ontology is implemented using OWL 2 DL, which includes logical constraints and enables consistency checking and automated reasoning. Validation through instantiation and competency question assessment shows that the model allows for structured querying, traceability across abstraction levels, and capability-level reasoning. The findings indicate that ontology-based modeling can serve as a basis for more formalized CR configuration analysis and capability-focused evaluation of diverse CR platforms.</description>
	<pubDate>2026-04-21</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 76: An Ontology-Based Framework for Semantic Representation of the Cyber Range Domain</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/76">doi: 10.3390/jcp6020076</a></p>
	<p>Authors:
		Vyron Kampourakis
		Michail Takaronis
		Vasileios Gkioulos
		Sokratis Katsikas
		</p>
	<p>Cyber Ranges (CRs) are complex socio-technical ecosystems, combining infrastructure resources, software services, learning mechanisms, and human-in-the-loop processes for cybersecurity training, education, and experimentation. However, their design and representation are conventionally described by diverse architectural representations and a lack of standardization, making them difficult to compare, integrate, and reason in an automated manner. This paper proposes a novel framework that uniquely integrates the structural, functional, informational, and decisional aspects of CR platforms, formalizing them into a common semantic framework. It models the architectural and learning characteristics of CRs, allowing the representation of design choices, operational processes, information resources, and capability development. The ontology is implemented using OWL 2 DL, which includes logical constraints and enables consistency checking and automated reasoning. Validation through instantiation and competency question assessment shows that the model allows for structured querying, traceability across abstraction levels, and capability-level reasoning. The findings indicate that ontology-based modeling can serve as a basis for more formalized CR configuration analysis and capability-focused evaluation of diverse CR platforms.</p>
	]]></content:encoded>

	<dc:title>An Ontology-Based Framework for Semantic Representation of the Cyber Range Domain</dc:title>
			<dc:creator>Vyron Kampourakis</dc:creator>
			<dc:creator>Michail Takaronis</dc:creator>
			<dc:creator>Vasileios Gkioulos</dc:creator>
			<dc:creator>Sokratis Katsikas</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020076</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-21</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-21</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>76</prism:startingPage>
		<prism:doi>10.3390/jcp6020076</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/76</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/75">

	<title>JCP, Vol. 6, Pages 75: Tracking the Gaze of Secure Coders: Behavioral Insights into Attention, Transitions, and Training</title>
	<link>https://www.mdpi.com/2624-800X/6/2/75</link>
	<description>Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers&amp;amp;rsquo; visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments to reflect authentic coding development. By visualizing gaze transitions and attention shifts, we expose how developers allocate effort during secure coding. By leveraging techniques that reveal gaze transitions, attention levels, and pupil size changes, we are able to gain insight into their behavior. Our study provides a fine-grained, process-oriented account of behavior in CWE-based secure coding educational tasks, uncovering attentional patterns and decision timelines that traditional methods may not capture. These contributions provide a foundation for improving training and understanding developer differences.</description>
	<pubDate>2026-04-20</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 75: Tracking the Gaze of Secure Coders: Behavioral Insights into Attention, Transitions, and Training</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/75">doi: 10.3390/jcp6020075</a></p>
	<p>Authors:
		Daniel Davis
		Feng Zhu
		</p>
	<p>Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers&amp;amp;rsquo; visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments to reflect authentic coding development. By visualizing gaze transitions and attention shifts, we expose how developers allocate effort during secure coding. By leveraging techniques that reveal gaze transitions, attention levels, and pupil size changes, we are able to gain insight into their behavior. Our study provides a fine-grained, process-oriented account of behavior in CWE-based secure coding educational tasks, uncovering attentional patterns and decision timelines that traditional methods may not capture. These contributions provide a foundation for improving training and understanding developer differences.</p>
	]]></content:encoded>

	<dc:title>Tracking the Gaze of Secure Coders: Behavioral Insights into Attention, Transitions, and Training</dc:title>
			<dc:creator>Daniel Davis</dc:creator>
			<dc:creator>Feng Zhu</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020075</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-20</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-20</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>75</prism:startingPage>
		<prism:doi>10.3390/jcp6020075</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/75</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/74">

	<title>JCP, Vol. 6, Pages 74: Contextual Integrity in Large Language Models: A Review</title>
	<link>https://www.mdpi.com/2624-800X/6/2/74</link>
	<description>The rapid advancements in large language models (LLMs) have transformed natural language processing, enabling their application in diverse domains such as conversational agents and decision-support systems in sensitive areas like healthcare, finance, and eldercare. However, as LLMs are increasingly integrated into real-world contexts, concerns about their adherence to ethical principles, privacy norms, and contextual expectations have become critical. Privacy preservation is particularly pressing in interactions involving personal or sensitive data, where ensuring that LLMs align with societal norms while mitigating risks of information leakage is essential to fostering trust and ensuring responsible deployment. Contextual integrity (CI) provides a robust framework to address these challenges, emphasizing that information flows should adhere to context-specific social norms. This principle is especially vital in sensitive applications, where LLMs must evaluate roles, information attributes, and transmission principles to maintain ethical behavior. Despite their linguistic proficiency, LLMs often fail to recognize and adapt to nuanced contextual norms, a limitation exacerbated by their probabilistic nature and the biases in their training data, which can lead to inappropriate or harmful outputs. Addressing these shortcomings requires rigorous evaluation methodologies and fine-tuning strategies that embed societal and contextual norms into the models.</description>
	<pubDate>2026-04-15</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 74: Contextual Integrity in Large Language Models: A Review</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/74">doi: 10.3390/jcp6020074</a></p>
	<p>Authors:
		Ahmad Hassanpour
		Bian Yang
		</p>
	<p>The rapid advancements in large language models (LLMs) have transformed natural language processing, enabling their application in diverse domains such as conversational agents and decision-support systems in sensitive areas like healthcare, finance, and eldercare. However, as LLMs are increasingly integrated into real-world contexts, concerns about their adherence to ethical principles, privacy norms, and contextual expectations have become critical. Privacy preservation is particularly pressing in interactions involving personal or sensitive data, where ensuring that LLMs align with societal norms while mitigating risks of information leakage is essential to fostering trust and ensuring responsible deployment. Contextual integrity (CI) provides a robust framework to address these challenges, emphasizing that information flows should adhere to context-specific social norms. This principle is especially vital in sensitive applications, where LLMs must evaluate roles, information attributes, and transmission principles to maintain ethical behavior. Despite their linguistic proficiency, LLMs often fail to recognize and adapt to nuanced contextual norms, a limitation exacerbated by their probabilistic nature and the biases in their training data, which can lead to inappropriate or harmful outputs. Addressing these shortcomings requires rigorous evaluation methodologies and fine-tuning strategies that embed societal and contextual norms into the models.</p>
	]]></content:encoded>

	<dc:title>Contextual Integrity in Large Language Models: A Review</dc:title>
			<dc:creator>Ahmad Hassanpour</dc:creator>
			<dc:creator>Bian Yang</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020074</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-15</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-15</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>74</prism:startingPage>
		<prism:doi>10.3390/jcp6020074</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/74</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/73">

	<title>JCP, Vol. 6, Pages 73: Evaluating the Effectiveness of Information Security Management Systems: An Analysis Framework and Key Metrics</title>
	<link>https://www.mdpi.com/2624-800X/6/2/73</link>
	<description>As large scale digitization continues to reform business processes, one critical challenge organizations are currently facing is managing the staggering amount of data flowing. Further, with large datasets comes the added complexity of insuring a cyber secure environment and shielding the information security management system (ISMS) from undesirable manipulations. Today&amp;amp;rsquo;s drastic rise of cyberattacks urges the need for effective security frameworks to guard against unauthorized access and malicious acts impeding business operations. The latter of which compelled organizations to adopt holistic information security approaches, commonly implemented via ISMS frameworks. Further, to maintain an effective ISMS, ongoing monitoring and measurements are highly required. Considering the aforementioned points, this paper explores how organizations measure the effectiveness of their ISMS focusing on key performance indicators, metrics, and foundational components involved in information security management by categorizing metrics into governance, risk, and incident response as well as determining the maturity level based on ISO alignment, the presence, specificity and automation of KPIs. Based on empirical interviews with eight diverse organizations, the research findings reveal a wide range of maturity among organizations, from those lacking clear defined KPIs to those with sophisticated multi-layered systems. While special attention is paid to incident-response management, companies with a strong ISMS stand out because they use automated and proactive metrics for strategic reporting, whereas companies with a weaker ISMS often do not have organized KPIs and depend on random manual audits. Based on these results, the present work suggests an analysis framework for evaluating ISMS effectiveness. While previous studies have struggled to define clear ISMS measurement practices, this paper aims to provide insights on measurements by identifying the core building blocks of ISMS and revealing how they are evaluated to drive continual ISMS improvement.</description>
	<pubDate>2026-04-14</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 73: Evaluating the Effectiveness of Information Security Management Systems: An Analysis Framework and Key Metrics</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/73">doi: 10.3390/jcp6020073</a></p>
	<p>Authors:
		Safia El Moutaouakil
		John Lindström
		Karl Andersson
		</p>
	<p>As large scale digitization continues to reform business processes, one critical challenge organizations are currently facing is managing the staggering amount of data flowing. Further, with large datasets comes the added complexity of insuring a cyber secure environment and shielding the information security management system (ISMS) from undesirable manipulations. Today&amp;amp;rsquo;s drastic rise of cyberattacks urges the need for effective security frameworks to guard against unauthorized access and malicious acts impeding business operations. The latter of which compelled organizations to adopt holistic information security approaches, commonly implemented via ISMS frameworks. Further, to maintain an effective ISMS, ongoing monitoring and measurements are highly required. Considering the aforementioned points, this paper explores how organizations measure the effectiveness of their ISMS focusing on key performance indicators, metrics, and foundational components involved in information security management by categorizing metrics into governance, risk, and incident response as well as determining the maturity level based on ISO alignment, the presence, specificity and automation of KPIs. Based on empirical interviews with eight diverse organizations, the research findings reveal a wide range of maturity among organizations, from those lacking clear defined KPIs to those with sophisticated multi-layered systems. While special attention is paid to incident-response management, companies with a strong ISMS stand out because they use automated and proactive metrics for strategic reporting, whereas companies with a weaker ISMS often do not have organized KPIs and depend on random manual audits. Based on these results, the present work suggests an analysis framework for evaluating ISMS effectiveness. While previous studies have struggled to define clear ISMS measurement practices, this paper aims to provide insights on measurements by identifying the core building blocks of ISMS and revealing how they are evaluated to drive continual ISMS improvement.</p>
	]]></content:encoded>

	<dc:title>Evaluating the Effectiveness of Information Security Management Systems: An Analysis Framework and Key Metrics</dc:title>
			<dc:creator>Safia El Moutaouakil</dc:creator>
			<dc:creator>John Lindström</dc:creator>
			<dc:creator>Karl Andersson</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020073</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-14</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-14</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>73</prism:startingPage>
		<prism:doi>10.3390/jcp6020073</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/73</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/72">

	<title>JCP, Vol. 6, Pages 72: De-Anonymization Techniques in the Tor Network Using an Experimental Testbed</title>
	<link>https://www.mdpi.com/2624-800X/6/2/72</link>
	<description>Tor is an anonymization network that enables access to hidden services and protects user identity through layered encryption. While its core technology offers strong privacy, users can still be exposed through indirect attack methods or configuration mistakes. This research not only explores de-anonymization techniques but also provides a practical guide for constructing a fully functional experimental Tor environment using virtual machines. The custom-built testbed allows for safe simulation of attacks without impacting the public Tor network. Within this environment, three key information-gathering approaches were evaluated: (1) malware-based reverse shells that establish external communication, (2) malicious PDF and Office files used to trigger outbound connections, and (3) analysis of service misconfigurations that may reveal the IP address of hidden services. The results confirm that although the Tor network itself is resilient, user behavior, improper configurations, and insecure content handling can lead to significant privacy risks. By combining practical environment setup with real-world attack scenarios, this paper serves both as a reference for building experimental Tor networks and as a security-oriented analysis of known de-anonymization vectors. The findings emphasize the critical need for user awareness and precise configuration in privacy-focused technologies.</description>
	<pubDate>2026-04-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 72: De-Anonymization Techniques in the Tor Network Using an Experimental Testbed</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/72">doi: 10.3390/jcp6020072</a></p>
	<p>Authors:
		Ondrej Kainz
		Sebastián Petro
		Miroslav Michalko
		Miroslav Murin
		Ervín Šimko
		</p>
	<p>Tor is an anonymization network that enables access to hidden services and protects user identity through layered encryption. While its core technology offers strong privacy, users can still be exposed through indirect attack methods or configuration mistakes. This research not only explores de-anonymization techniques but also provides a practical guide for constructing a fully functional experimental Tor environment using virtual machines. The custom-built testbed allows for safe simulation of attacks without impacting the public Tor network. Within this environment, three key information-gathering approaches were evaluated: (1) malware-based reverse shells that establish external communication, (2) malicious PDF and Office files used to trigger outbound connections, and (3) analysis of service misconfigurations that may reveal the IP address of hidden services. The results confirm that although the Tor network itself is resilient, user behavior, improper configurations, and insecure content handling can lead to significant privacy risks. By combining practical environment setup with real-world attack scenarios, this paper serves both as a reference for building experimental Tor networks and as a security-oriented analysis of known de-anonymization vectors. The findings emphasize the critical need for user awareness and precise configuration in privacy-focused technologies.</p>
	]]></content:encoded>

	<dc:title>De-Anonymization Techniques in the Tor Network Using an Experimental Testbed</dc:title>
			<dc:creator>Ondrej Kainz</dc:creator>
			<dc:creator>Sebastián Petro</dc:creator>
			<dc:creator>Miroslav Michalko</dc:creator>
			<dc:creator>Miroslav Murin</dc:creator>
			<dc:creator>Ervín Šimko</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020072</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>72</prism:startingPage>
		<prism:doi>10.3390/jcp6020072</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/72</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/71">

	<title>JCP, Vol. 6, Pages 71: A Novel Hybrid Quantum Circuit for Integer Factorization: End-to-End Evaluation in Simulation and Real Quantum Hardware</title>
	<link>https://www.mdpi.com/2624-800X/6/2/71</link>
	<description>The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime therefore remains an important open research objective. This work proposes a hybrid classical&amp;amp;ndash;quantum algorithm that uses a classical modular exponentiation subroutine with a Quantum Number Theoretic Transform (QNTT) circuit to increase the speed and reduce the required quantum resources relative to Shor&amp;amp;rsquo;s algorithm for integer factorization, which underpins cryptographic systems like RSA and ECC. We evaluate multiple coprime numbers, the result of multiplication of two primes, in both simulation and real quantum hardware, using IBM&amp;amp;rsquo;s reference Shor implementation as the baseline. Because Shor and proposed Jesse&amp;amp;ndash;Victor&amp;amp;ndash;Gharabaghi (JVG) use different register sizes for the same coprime N, the reported gate/depth reductions should be interpreted as end-to-end quantum-resource budgets for factoring the same N, rather than a per-qubit or transform-only efficiency claim. In simulation, the JVG algorithm achieved substantial practical reductions in computational resources, decreasing runtime from 174.1 s to 5.4 s, memory usage from 12.5 GB to 0.27 GB, and quantum gate counts by approximately 99%. On quantum hardware, JVG reduced the required runtime from 67.8 s to 2 s, and the quantum gate counts by over 98%. We showed that the proposed algorithm can address the relevant RSA-1024 case scenario, establishing that this method can provide validation for large-scale situations. Furthermore, extrapolation to RSA-2048 indicates that the JVG algorithm significantly outperforms Shor&amp;amp;rsquo;s approach, requiring a projected quantum runtime of 29 h for ten thousand runs for factorization under identical scaling assumptions. Overall, these results support JVG as a more hardware-compatible and robust noise-tolerant substitute for Shor&amp;amp;rsquo;s framework, offering a viable research direction toward practical quantum integer factorization on near-term Noisy Intermediate-Scale Quantum (NISQ) devices.</description>
	<pubDate>2026-04-10</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 71: A Novel Hybrid Quantum Circuit for Integer Factorization: End-to-End Evaluation in Simulation and Real Quantum Hardware</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/71">doi: 10.3390/jcp6020071</a></p>
	<p>Authors:
		Jesse Van Griensven Thé
		Victor Oliveira Santos
		Bahram Gharabaghi
		</p>
	<p>The literature indicates that the qubit requirements for factoring RSA-2048 remain on the order of 1 million, under commonly assumed architectures and error-correction models, leaving a substantial gap between current resource estimates and near-term practical feasibility. Reducing this requirement to the low-thousand-qubit regime therefore remains an important open research objective. This work proposes a hybrid classical&amp;amp;ndash;quantum algorithm that uses a classical modular exponentiation subroutine with a Quantum Number Theoretic Transform (QNTT) circuit to increase the speed and reduce the required quantum resources relative to Shor&amp;amp;rsquo;s algorithm for integer factorization, which underpins cryptographic systems like RSA and ECC. We evaluate multiple coprime numbers, the result of multiplication of two primes, in both simulation and real quantum hardware, using IBM&amp;amp;rsquo;s reference Shor implementation as the baseline. Because Shor and proposed Jesse&amp;amp;ndash;Victor&amp;amp;ndash;Gharabaghi (JVG) use different register sizes for the same coprime N, the reported gate/depth reductions should be interpreted as end-to-end quantum-resource budgets for factoring the same N, rather than a per-qubit or transform-only efficiency claim. In simulation, the JVG algorithm achieved substantial practical reductions in computational resources, decreasing runtime from 174.1 s to 5.4 s, memory usage from 12.5 GB to 0.27 GB, and quantum gate counts by approximately 99%. On quantum hardware, JVG reduced the required runtime from 67.8 s to 2 s, and the quantum gate counts by over 98%. We showed that the proposed algorithm can address the relevant RSA-1024 case scenario, establishing that this method can provide validation for large-scale situations. Furthermore, extrapolation to RSA-2048 indicates that the JVG algorithm significantly outperforms Shor&amp;amp;rsquo;s approach, requiring a projected quantum runtime of 29 h for ten thousand runs for factorization under identical scaling assumptions. Overall, these results support JVG as a more hardware-compatible and robust noise-tolerant substitute for Shor&amp;amp;rsquo;s framework, offering a viable research direction toward practical quantum integer factorization on near-term Noisy Intermediate-Scale Quantum (NISQ) devices.</p>
	]]></content:encoded>

	<dc:title>A Novel Hybrid Quantum Circuit for Integer Factorization: End-to-End Evaluation in Simulation and Real Quantum Hardware</dc:title>
			<dc:creator>Jesse Van Griensven Thé</dc:creator>
			<dc:creator>Victor Oliveira Santos</dc:creator>
			<dc:creator>Bahram Gharabaghi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020071</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-10</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-10</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>71</prism:startingPage>
		<prism:doi>10.3390/jcp6020071</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/71</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/70">

	<title>JCP, Vol. 6, Pages 70: AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web</title>
	<link>https://www.mdpi.com/2624-800X/6/2/70</link>
	<description>Ransomware operations have evolved from isolated malware incidents into organized ransomware-as-a-service (RaaS) ecosystems that employ coordinated tactics, techniques, and procedures and increasingly rely on automation and artificial intelligence to scale intrusions. However, most assessments remain artifact-centric, focusing on malware signatures or aggregate victim counts, which provide limited visibility into differences in actor-level behavior and operational capability. This study introduces the AI-Amplification Indicator (AIAI), an interpretable actor-level scoring framework that transforms publicly observable leak-site disclosures and verifiable open-source evidence into quantitative behavioral profiles. Using continuous monitoring of dark web leak portals, we construct a standardized dataset of ransomware disclosures for 2025 with temporal, geographic, and sector metadata. AIAI measures four complementary dimensions: GenAI-enabled social engineering, operational tempo and orchestration, targeting breadth and diversification, and temporal scaling dynamics. Indicators are computed for all observed actors, while comparative profiling focuses on the ten most active actors to ensure stable behavioral estimation. The analysis reveals substantial heterogeneity in posting cadence, targeting strategies, and scaling dynamics, as well as limited but measurable evidence of automated or AI-assisted deception. These differences are not captured by victim counts alone. The proposed framework provides a transparent and reproducible approach for actor-level ransomware intelligence, enabling systematic comparison of operational styles and supporting data-driven defensive prioritization.</description>
	<pubDate>2026-04-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 70: AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/70">doi: 10.3390/jcp6020070</a></p>
	<p>Authors:
		Mostafa Moallim
		Seokhee Lee
		Ibrahim Alzahrani
		Faisal Abdulaziz Alfouzan
		Kyounggon Kim
		</p>
	<p>Ransomware operations have evolved from isolated malware incidents into organized ransomware-as-a-service (RaaS) ecosystems that employ coordinated tactics, techniques, and procedures and increasingly rely on automation and artificial intelligence to scale intrusions. However, most assessments remain artifact-centric, focusing on malware signatures or aggregate victim counts, which provide limited visibility into differences in actor-level behavior and operational capability. This study introduces the AI-Amplification Indicator (AIAI), an interpretable actor-level scoring framework that transforms publicly observable leak-site disclosures and verifiable open-source evidence into quantitative behavioral profiles. Using continuous monitoring of dark web leak portals, we construct a standardized dataset of ransomware disclosures for 2025 with temporal, geographic, and sector metadata. AIAI measures four complementary dimensions: GenAI-enabled social engineering, operational tempo and orchestration, targeting breadth and diversification, and temporal scaling dynamics. Indicators are computed for all observed actors, while comparative profiling focuses on the ten most active actors to ensure stable behavioral estimation. The analysis reveals substantial heterogeneity in posting cadence, targeting strategies, and scaling dynamics, as well as limited but measurable evidence of automated or AI-assisted deception. These differences are not captured by victim counts alone. The proposed framework provides a transparent and reproducible approach for actor-level ransomware intelligence, enabling systematic comparison of operational styles and supporting data-driven defensive prioritization.</p>
	]]></content:encoded>

	<dc:title>AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web</dc:title>
			<dc:creator>Mostafa Moallim</dc:creator>
			<dc:creator>Seokhee Lee</dc:creator>
			<dc:creator>Ibrahim Alzahrani</dc:creator>
			<dc:creator>Faisal Abdulaziz Alfouzan</dc:creator>
			<dc:creator>Kyounggon Kim</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020070</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>70</prism:startingPage>
		<prism:doi>10.3390/jcp6020070</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/70</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/69">

	<title>JCP, Vol. 6, Pages 69: Automating the Detection of Evasive Windows Malware: An Evaluated YARA Rule Library for Anti-VM and Anti-Sandbox Techniques</title>
	<link>https://www.mdpi.com/2624-800X/6/2/69</link>
	<description>Anti-analysis techniques, also known as evasive techniques, enable Windows malware to detect and evade dynamic inspection environments, undermining the effectiveness of virtual-machine and sandbox-based inspection. Despite extensive prior research, no unified classification has been paired with a large-scale empirical evaluation of static detection capabilities for these behaviors. This paper addresses this gap by presenting a comprehensive classification and detection framework. We consolidate 94 anti-analysis techniques from academic, community, and threat-intelligence sources into nine mechanistic categories and derive corresponding YARA rules for static identification. In total, 82 YARA signatures were authored or refined and evaluated on 459,508 malware and 92,508 goodware samples. After iterative refinement using precision thresholds, 42 rules achieved high accuracy (&amp;amp;ge;75%), 16 showed moderate precision (50&amp;amp;ndash;75%), and 24 were discarded due to unreliability. The results indicate strong static detectability for firmware- and BIOS-based checks, but limited precision for timing-based evasions, which frequently overlap with benign behavior. Although YARA provides broad coverage of observable artifacts, its static nature limits detection under obfuscation or runtime mutation; our measurements therefore represent conservative estimates of technique prevalence. All validated rules are released in an open-source repository to support reproducibility, improve incident-response workflows, and strengthen prevention and mitigation against real-world threats. Future work will explore hybrid validation, container-evasion extensions, and forensic attribution based on signature co-occurrence patterns.</description>
	<pubDate>2026-04-08</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 69: Automating the Detection of Evasive Windows Malware: An Evaluated YARA Rule Library for Anti-VM and Anti-Sandbox Techniques</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/69">doi: 10.3390/jcp6020069</a></p>
	<p>Authors:
		Sebastien Kanj
		Gorka Vila
		Josep Pegueroles
		</p>
	<p>Anti-analysis techniques, also known as evasive techniques, enable Windows malware to detect and evade dynamic inspection environments, undermining the effectiveness of virtual-machine and sandbox-based inspection. Despite extensive prior research, no unified classification has been paired with a large-scale empirical evaluation of static detection capabilities for these behaviors. This paper addresses this gap by presenting a comprehensive classification and detection framework. We consolidate 94 anti-analysis techniques from academic, community, and threat-intelligence sources into nine mechanistic categories and derive corresponding YARA rules for static identification. In total, 82 YARA signatures were authored or refined and evaluated on 459,508 malware and 92,508 goodware samples. After iterative refinement using precision thresholds, 42 rules achieved high accuracy (&amp;amp;ge;75%), 16 showed moderate precision (50&amp;amp;ndash;75%), and 24 were discarded due to unreliability. The results indicate strong static detectability for firmware- and BIOS-based checks, but limited precision for timing-based evasions, which frequently overlap with benign behavior. Although YARA provides broad coverage of observable artifacts, its static nature limits detection under obfuscation or runtime mutation; our measurements therefore represent conservative estimates of technique prevalence. All validated rules are released in an open-source repository to support reproducibility, improve incident-response workflows, and strengthen prevention and mitigation against real-world threats. Future work will explore hybrid validation, container-evasion extensions, and forensic attribution based on signature co-occurrence patterns.</p>
	]]></content:encoded>

	<dc:title>Automating the Detection of Evasive Windows Malware: An Evaluated YARA Rule Library for Anti-VM and Anti-Sandbox Techniques</dc:title>
			<dc:creator>Sebastien Kanj</dc:creator>
			<dc:creator>Gorka Vila</dc:creator>
			<dc:creator>Josep Pegueroles</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020069</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-08</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-08</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>69</prism:startingPage>
		<prism:doi>10.3390/jcp6020069</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/69</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/68">

	<title>JCP, Vol. 6, Pages 68: Enhancing Darknet Traffic Classification: Integrating Traffic-Aware SMOTE and Adaptive Weighted Feature Aggregation</title>
	<link>https://www.mdpi.com/2624-800X/6/2/68</link>
	<description>With the widespread adoption of anonymity networks such as Tor, I2P, and JonDonym, reliably classifying darknet traffic remains challenging due to feature redundancy and severe class imbalance in encrypted flows. Existing approaches often rely on static feature-selection strategies and generic oversampling methods, which limit robustness and may distort traffic semantics. This study proposes an adaptive classification framework integrating Adaptive Weighted Feature Aggregation (AWFA) for reliability-aware feature selection and Traffic-Aware SMOTE (TA-SMOTE) for semantically constrained perturbations of packet-size and timing features while preserving flow-level structure. The framework is evaluated on a two-layer hierarchy comprising browser-level (L1) and application-level (L2) classification. At the L2, the proposed AWFA and TA-SMOTE pipeline attains a macro-F1 score of 73.81%, significantly exceeding PCA-based reduction and traditional RF-based selection with SMOTE. At the browser level (L1), macro-F1 rises from 91.58% to 96.09% while reducing the feature space from 84 to 40 attributes, highlighting both performance improvements and structural efficiency gains. Additional semantic validation confirms that the balancing process preserves the statistical and structural characteristics of genuine darknet traffic. These results indicate that reliability-aware feature aggregation and traffic-aware balancing provide a practical, trustworthy approach to modern darknet traffic classification.</description>
	<pubDate>2026-04-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 68: Enhancing Darknet Traffic Classification: Integrating Traffic-Aware SMOTE and Adaptive Weighted Feature Aggregation</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/68">doi: 10.3390/jcp6020068</a></p>
	<p>Authors:
		Javeriah Saleem
		Rafiqul Islam
		Irfan Altas
		Md Zahidul Islam
		</p>
	<p>With the widespread adoption of anonymity networks such as Tor, I2P, and JonDonym, reliably classifying darknet traffic remains challenging due to feature redundancy and severe class imbalance in encrypted flows. Existing approaches often rely on static feature-selection strategies and generic oversampling methods, which limit robustness and may distort traffic semantics. This study proposes an adaptive classification framework integrating Adaptive Weighted Feature Aggregation (AWFA) for reliability-aware feature selection and Traffic-Aware SMOTE (TA-SMOTE) for semantically constrained perturbations of packet-size and timing features while preserving flow-level structure. The framework is evaluated on a two-layer hierarchy comprising browser-level (L1) and application-level (L2) classification. At the L2, the proposed AWFA and TA-SMOTE pipeline attains a macro-F1 score of 73.81%, significantly exceeding PCA-based reduction and traditional RF-based selection with SMOTE. At the browser level (L1), macro-F1 rises from 91.58% to 96.09% while reducing the feature space from 84 to 40 attributes, highlighting both performance improvements and structural efficiency gains. Additional semantic validation confirms that the balancing process preserves the statistical and structural characteristics of genuine darknet traffic. These results indicate that reliability-aware feature aggregation and traffic-aware balancing provide a practical, trustworthy approach to modern darknet traffic classification.</p>
	]]></content:encoded>

	<dc:title>Enhancing Darknet Traffic Classification: Integrating Traffic-Aware SMOTE and Adaptive Weighted Feature Aggregation</dc:title>
			<dc:creator>Javeriah Saleem</dc:creator>
			<dc:creator>Rafiqul Islam</dc:creator>
			<dc:creator>Irfan Altas</dc:creator>
			<dc:creator>Md Zahidul Islam</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020068</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>68</prism:startingPage>
		<prism:doi>10.3390/jcp6020068</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/68</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/67">

	<title>JCP, Vol. 6, Pages 67: An Evidence-Based Architecture for Trustworthy Asset Discovery in Cybersecurity-Critical IT Environments</title>
	<link>https://www.mdpi.com/2624-800X/6/2/67</link>
	<description>Asset discovery is a fundamental but inherently flawed capability in cybersecurity, as current methodologies frequently confuse preliminary discovery observations with definitive asset inventories, thereby obscuring uncertainty, restricting auditability, and eroding trust in security-critical decision-making. This work addresses the issue of inconsistent asset identification in dynamic IT settings by presenting an evidence-based architectural paradigm that clearly distinguishes observation, identity resolution, and inventory representation. The principal research aim is to develop and authenticate an architecture that maintains discovery evidence, facilitates deterministic, verifiable identity resolution, and supports interpretable inventory derivation. In contrast to state-centric and model-driven methodologies, the proposed architecture enhances (i) traceability through the preservation of time-scoped, method-attributed observations, (ii) identity continuity amidst dynamic conditions such as IP reassignment and infrastructure modifications, and (iii) auditability by facilitating the reconstruction of inventory claims from foundational evidence. An examined proof-of-concept implementation in a controlled yet realistic network environment shows superior identity stability, greater discovery traceability, and retention of historical context relative to traditional inventory models. The results validate the practicality and architectural benefits of the strategy; nevertheless, the evaluation is constrained by a lack of formalised performance indicators and adversarial robustness, which are recognised as priorities for further investigation.</description>
	<pubDate>2026-04-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 67: An Evidence-Based Architecture for Trustworthy Asset Discovery in Cybersecurity-Critical IT Environments</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/67">doi: 10.3390/jcp6020067</a></p>
	<p>Authors:
		Ivana Ogrizek Biškupić
		Mislav Balković
		Ivan Bencarić
		</p>
	<p>Asset discovery is a fundamental but inherently flawed capability in cybersecurity, as current methodologies frequently confuse preliminary discovery observations with definitive asset inventories, thereby obscuring uncertainty, restricting auditability, and eroding trust in security-critical decision-making. This work addresses the issue of inconsistent asset identification in dynamic IT settings by presenting an evidence-based architectural paradigm that clearly distinguishes observation, identity resolution, and inventory representation. The principal research aim is to develop and authenticate an architecture that maintains discovery evidence, facilitates deterministic, verifiable identity resolution, and supports interpretable inventory derivation. In contrast to state-centric and model-driven methodologies, the proposed architecture enhances (i) traceability through the preservation of time-scoped, method-attributed observations, (ii) identity continuity amidst dynamic conditions such as IP reassignment and infrastructure modifications, and (iii) auditability by facilitating the reconstruction of inventory claims from foundational evidence. An examined proof-of-concept implementation in a controlled yet realistic network environment shows superior identity stability, greater discovery traceability, and retention of historical context relative to traditional inventory models. The results validate the practicality and architectural benefits of the strategy; nevertheless, the evaluation is constrained by a lack of formalised performance indicators and adversarial robustness, which are recognised as priorities for further investigation.</p>
	]]></content:encoded>

	<dc:title>An Evidence-Based Architecture for Trustworthy Asset Discovery in Cybersecurity-Critical IT Environments</dc:title>
			<dc:creator>Ivana Ogrizek Biškupić</dc:creator>
			<dc:creator>Mislav Balković</dc:creator>
			<dc:creator>Ivan Bencarić</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020067</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>67</prism:startingPage>
		<prism:doi>10.3390/jcp6020067</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/67</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/66">

	<title>JCP, Vol. 6, Pages 66: Deciding on Cybersecurity Awareness Initiatives: Insights from the Public Sector</title>
	<link>https://www.mdpi.com/2624-800X/6/2/66</link>
	<description>Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA activities for organisations to choose from. Nevertheless, research consistently reports that organisations struggle to raise CSA to an appropriate level, and a core issue lies in their ability to select CSA activities and effectively adopt them. This paper used semi-structured interviews with practitioners working on CSA adoption in public-sector organisations to identify what practitioners perceive as success factors. The interviews were analysed through a socio-technical lens and resulted in a taxonomy that groups success factors for CSA adoption in the three socio-technical dimensions: organisational, user-centric, and technical. The taxonomy outlines ten success factors and demonstrates how the participants see success of CSA activities as not only dependent on technical factors but also, and perhaps even more important, user-adaptability and organisational readiness. The results were validated in a workshop with CSA experts across Europe, who highlighted the practical usefulness of the taxonomy as both a map of potential challenges and a teaching tool for educating new CSA practitioners.</description>
	<pubDate>2026-04-06</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 66: Deciding on Cybersecurity Awareness Initiatives: Insights from the Public Sector</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/66">doi: 10.3390/jcp6020066</a></p>
	<p>Authors:
		Joakim Kävrestad
		Erik Bergström
		Rebecca Gunnarsson
		Ali Mazeh
		Linus Stenlund
		</p>
	<p>Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA activities for organisations to choose from. Nevertheless, research consistently reports that organisations struggle to raise CSA to an appropriate level, and a core issue lies in their ability to select CSA activities and effectively adopt them. This paper used semi-structured interviews with practitioners working on CSA adoption in public-sector organisations to identify what practitioners perceive as success factors. The interviews were analysed through a socio-technical lens and resulted in a taxonomy that groups success factors for CSA adoption in the three socio-technical dimensions: organisational, user-centric, and technical. The taxonomy outlines ten success factors and demonstrates how the participants see success of CSA activities as not only dependent on technical factors but also, and perhaps even more important, user-adaptability and organisational readiness. The results were validated in a workshop with CSA experts across Europe, who highlighted the practical usefulness of the taxonomy as both a map of potential challenges and a teaching tool for educating new CSA practitioners.</p>
	]]></content:encoded>

	<dc:title>Deciding on Cybersecurity Awareness Initiatives: Insights from the Public Sector</dc:title>
			<dc:creator>Joakim Kävrestad</dc:creator>
			<dc:creator>Erik Bergström</dc:creator>
			<dc:creator>Rebecca Gunnarsson</dc:creator>
			<dc:creator>Ali Mazeh</dc:creator>
			<dc:creator>Linus Stenlund</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020066</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-06</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-06</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>66</prism:startingPage>
		<prism:doi>10.3390/jcp6020066</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/66</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/65">

	<title>JCP, Vol. 6, Pages 65: An Examination of LPWAN Security in Maritime Applications</title>
	<link>https://www.mdpi.com/2624-800X/6/2/65</link>
	<description>LoRaWAN&amp;amp;rsquo;s role in global maritime logistics has allowed for efficient monitoring of ships and cargo, but it also comes with critical cybersecurity vulnerabilities. Experimental validation of three attack vectors&amp;amp;mdash;replay attacks, narrowband jamming and metadata inference&amp;amp;mdash;is conducted using a reproducible digital-twin LoRaWAN dataset reflecting Rotterdam port-like operational patterns (N = 20,000 baseline transmissions). Using controlled simulations and Kolmogorov&amp;amp;ndash;Smirnov statistical analysis, we show that: (1) replay attacks are feasible under Activation by Personalization (ABP) configurations lacking enforced frame-counter validation and exhibit no univariate separation from legitimate traffic under Kolmogorov&amp;amp;ndash;Smirnov analysis (p &amp;amp;gt; 0.46 for all evaluated radio features); (2) narrowband jamming leads to significant SNR degradation (p = 2.36 &amp;amp;times; 10&amp;amp;minus;5) on targeted channels without inducing broad distributional anomalies across other radio features; and (3) metadata-only analysis supports elevated metadata-based re-identification susceptibility (median Rd=0.834), indicating high predictability under passive observation which can reveal operationally relevant signals even when AES-128 is employed. Our proposed layered mitigation framework consists of mandatory Over-the-Air Activation (OTAA), cryptographic key rotation, channel diversity incorporating Adaptive Data Rate (ADR), gateway hardening, and protocol-level enforcement considerations, customized for maritime LPWAN scenarios. We provide experiment-backed evidence and actionable recommendations to connect academic LPWAN security research to that of industrial maritime practice.</description>
	<pubDate>2026-04-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 65: An Examination of LPWAN Security in Maritime Applications</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/65">doi: 10.3390/jcp6020065</a></p>
	<p>Authors:
		Zachary Larkin
		Chuck Easttom
		</p>
	<p>LoRaWAN&amp;amp;rsquo;s role in global maritime logistics has allowed for efficient monitoring of ships and cargo, but it also comes with critical cybersecurity vulnerabilities. Experimental validation of three attack vectors&amp;amp;mdash;replay attacks, narrowband jamming and metadata inference&amp;amp;mdash;is conducted using a reproducible digital-twin LoRaWAN dataset reflecting Rotterdam port-like operational patterns (N = 20,000 baseline transmissions). Using controlled simulations and Kolmogorov&amp;amp;ndash;Smirnov statistical analysis, we show that: (1) replay attacks are feasible under Activation by Personalization (ABP) configurations lacking enforced frame-counter validation and exhibit no univariate separation from legitimate traffic under Kolmogorov&amp;amp;ndash;Smirnov analysis (p &amp;amp;gt; 0.46 for all evaluated radio features); (2) narrowband jamming leads to significant SNR degradation (p = 2.36 &amp;amp;times; 10&amp;amp;minus;5) on targeted channels without inducing broad distributional anomalies across other radio features; and (3) metadata-only analysis supports elevated metadata-based re-identification susceptibility (median Rd=0.834), indicating high predictability under passive observation which can reveal operationally relevant signals even when AES-128 is employed. Our proposed layered mitigation framework consists of mandatory Over-the-Air Activation (OTAA), cryptographic key rotation, channel diversity incorporating Adaptive Data Rate (ADR), gateway hardening, and protocol-level enforcement considerations, customized for maritime LPWAN scenarios. We provide experiment-backed evidence and actionable recommendations to connect academic LPWAN security research to that of industrial maritime practice.</p>
	]]></content:encoded>

	<dc:title>An Examination of LPWAN Security in Maritime Applications</dc:title>
			<dc:creator>Zachary Larkin</dc:creator>
			<dc:creator>Chuck Easttom</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020065</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>65</prism:startingPage>
		<prism:doi>10.3390/jcp6020065</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/65</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/64">

	<title>JCP, Vol. 6, Pages 64: Hybrid-Pipeline-Based Detection and Classification of HTTP Slow Denial-of-Service Attacks Using Radial Basis Function Neural Networks</title>
	<link>https://www.mdpi.com/2624-800X/6/2/64</link>
	<description>Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop a lightweight pipeline that learns a low-dimensional latent representation of tabular flow features using an autoencoder and performs classification using Random Forest, LightGBM, and a radial basis function neural network. Using the CICIDS 2017 dataset, the best performing configurations achieve 99.43 percent accuracy with autoencoder plus Random Forest and 99.39 percent with autoencoder plus LightGBM, while autoencoder plus radial basis function neural network achieves 98.27 percent, with consistently strong precision, recall, and F1-score. The findings support practice by showing that high detection performance can be achieved using compact learned features that reduce input complexity for downstream models, which is beneficial for operational monitoring environments. The study advances knowledge by providing a reproducible evaluation of representation learning as a feature compression step for tabular intrusion detection, and by linking model performance to measurable computational considerations relevant to real-world deployment.</description>
	<pubDate>2026-04-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 64: Hybrid-Pipeline-Based Detection and Classification of HTTP Slow Denial-of-Service Attacks Using Radial Basis Function Neural Networks</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/64">doi: 10.3390/jcp6020064</a></p>
	<p>Authors:
		Bashaer H. Alrashid
		Mazen Alwadi
		Qasem Abu Al-Haija
		</p>
	<p>Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop a lightweight pipeline that learns a low-dimensional latent representation of tabular flow features using an autoencoder and performs classification using Random Forest, LightGBM, and a radial basis function neural network. Using the CICIDS 2017 dataset, the best performing configurations achieve 99.43 percent accuracy with autoencoder plus Random Forest and 99.39 percent with autoencoder plus LightGBM, while autoencoder plus radial basis function neural network achieves 98.27 percent, with consistently strong precision, recall, and F1-score. The findings support practice by showing that high detection performance can be achieved using compact learned features that reduce input complexity for downstream models, which is beneficial for operational monitoring environments. The study advances knowledge by providing a reproducible evaluation of representation learning as a feature compression step for tabular intrusion detection, and by linking model performance to measurable computational considerations relevant to real-world deployment.</p>
	]]></content:encoded>

	<dc:title>Hybrid-Pipeline-Based Detection and Classification of HTTP Slow Denial-of-Service Attacks Using Radial Basis Function Neural Networks</dc:title>
			<dc:creator>Bashaer H. Alrashid</dc:creator>
			<dc:creator>Mazen Alwadi</dc:creator>
			<dc:creator>Qasem Abu Al-Haija</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020064</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>64</prism:startingPage>
		<prism:doi>10.3390/jcp6020064</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/64</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/62">

	<title>JCP, Vol. 6, Pages 62: Assessing Information Privacy Awareness, Expectations, and Confidence of Students: Evidence from a Diagnostic Survey in a Developing Country&amp;rsquo;s Higher Education Sector</title>
	<link>https://www.mdpi.com/2624-800X/6/2/62</link>
	<description>The protection of personal information has become a defining challenge for higher education institutions, particularly in developing contexts where regulatory frameworks are often strong on paper but weak in practice. This study investigates student perceptions of privacy within Zimbabwe&amp;amp;rsquo;s higher education system, focusing on three constructs: awareness, expectations, and confidence across nine core privacy components derived from international principles (FIPPs, OECD, GDPR) and the Zimbabwe Data Protection Act (ZDPA). Using survey data from 287 students across diverse programmes and modes of study, descriptive and comparative analyses reveal a striking pattern: students demonstrate high awareness and very strong expectations, yet their confidence in institutional compliance remains significantly lower. The largest deficits were found in privacy education, consent, and notice/openness, suggesting that institutions are perceived as technically competent in data handling but weak in transparency, accountability, and student engagement. The research extends privacy perception models by considering the discrepancy between the students&amp;amp;rsquo; expectations and the institutional trust. It also encourages universities to go beyond mere compliance by implementing concrete measures such as privacy training, clear consent, and frequent data audits. The findings contribute to global debates on privacy by offering evidence from the Global South, showing that the key challenge is not student ignorance but institutional trustworthiness. Bridging this awareness-confidence gap is essential for building a privacy-conscious academic environment.</description>
	<pubDate>2026-04-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 62: Assessing Information Privacy Awareness, Expectations, and Confidence of Students: Evidence from a Diagnostic Survey in a Developing Country&amp;rsquo;s Higher Education Sector</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/62">doi: 10.3390/jcp6020062</a></p>
	<p>Authors:
		Kudakwashe Maguraushe
		Adéle Da Veiga
		Nico Martins
		</p>
	<p>The protection of personal information has become a defining challenge for higher education institutions, particularly in developing contexts where regulatory frameworks are often strong on paper but weak in practice. This study investigates student perceptions of privacy within Zimbabwe&amp;amp;rsquo;s higher education system, focusing on three constructs: awareness, expectations, and confidence across nine core privacy components derived from international principles (FIPPs, OECD, GDPR) and the Zimbabwe Data Protection Act (ZDPA). Using survey data from 287 students across diverse programmes and modes of study, descriptive and comparative analyses reveal a striking pattern: students demonstrate high awareness and very strong expectations, yet their confidence in institutional compliance remains significantly lower. The largest deficits were found in privacy education, consent, and notice/openness, suggesting that institutions are perceived as technically competent in data handling but weak in transparency, accountability, and student engagement. The research extends privacy perception models by considering the discrepancy between the students&amp;amp;rsquo; expectations and the institutional trust. It also encourages universities to go beyond mere compliance by implementing concrete measures such as privacy training, clear consent, and frequent data audits. The findings contribute to global debates on privacy by offering evidence from the Global South, showing that the key challenge is not student ignorance but institutional trustworthiness. Bridging this awareness-confidence gap is essential for building a privacy-conscious academic environment.</p>
	]]></content:encoded>

	<dc:title>Assessing Information Privacy Awareness, Expectations, and Confidence of Students: Evidence from a Diagnostic Survey in a Developing Country&amp;amp;rsquo;s Higher Education Sector</dc:title>
			<dc:creator>Kudakwashe Maguraushe</dc:creator>
			<dc:creator>Adéle Da Veiga</dc:creator>
			<dc:creator>Nico Martins</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020062</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>62</prism:startingPage>
		<prism:doi>10.3390/jcp6020062</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/62</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/63">

	<title>JCP, Vol. 6, Pages 63: Securing the Cognitive Layer: A Survey on Security Threats, Defenses, and Privacy-Preserving Architectures for LLM-IoT Integration</title>
	<link>https://www.mdpi.com/2624-800X/6/2/63</link>
	<description>The convergence of Large Language Models (LLMs) and Internet of Things (IoT) systems has created a new class of intelligent applications across healthcare, industrial automation, smart cities, and connected homes. However, this integration introduces a complex and largely underexplored security landscape. LLMs deployed in IoT contexts face threats spanning both the AI and embedded systems domains, including prompt injection through sensor-driven inputs, model extraction from edge devices, data poisoning of IoT data streams, and privacy leakage through LLM-generated responses grounded in personal data. Simultaneously, LLMs are proving to be powerful tools for IoT security, with LLM-based intrusion detection systems achieving 95&amp;amp;ndash;99% accuracy on standard IoT datasets and LLM-driven threat intelligence outperforming traditional machine learning by significant margins. We systematically review 88 papers from IEEE, ACM, MDPI, and arXiv (2020&amp;amp;ndash;2025), providing: (1) a structured taxonomy of security threats targeting LLM-IoT systems, (2) a review of LLMs as security enablers for IoT, (3) an evaluation of privacy-preserving architectures including federated learning, differential privacy, homomorphic encryption, and trusted execution environments, (4) domain-specific security analysis across healthcare, industrial, smart home, smart grid, and vehicular IoT, and (5) a literature-based comparative analysis of LLM-based security systems. A central finding is the accuracy&amp;amp;ndash;efficiency&amp;amp;ndash;privacy trilemma: the model compression techniques needed to deploy LLMs on resource-constrained IoT devices can degrade security and even introduce new vulnerabilities. Our analysis provides researchers and practitioners with a structured understanding of both the risks and opportunities at the frontier of LLM-IoT security.</description>
	<pubDate>2026-04-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 63: Securing the Cognitive Layer: A Survey on Security Threats, Defenses, and Privacy-Preserving Architectures for LLM-IoT Integration</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/63">doi: 10.3390/jcp6020063</a></p>
	<p>Authors:
		Ayan Joshi
		Sabur Baidya
		</p>
	<p>The convergence of Large Language Models (LLMs) and Internet of Things (IoT) systems has created a new class of intelligent applications across healthcare, industrial automation, smart cities, and connected homes. However, this integration introduces a complex and largely underexplored security landscape. LLMs deployed in IoT contexts face threats spanning both the AI and embedded systems domains, including prompt injection through sensor-driven inputs, model extraction from edge devices, data poisoning of IoT data streams, and privacy leakage through LLM-generated responses grounded in personal data. Simultaneously, LLMs are proving to be powerful tools for IoT security, with LLM-based intrusion detection systems achieving 95&amp;amp;ndash;99% accuracy on standard IoT datasets and LLM-driven threat intelligence outperforming traditional machine learning by significant margins. We systematically review 88 papers from IEEE, ACM, MDPI, and arXiv (2020&amp;amp;ndash;2025), providing: (1) a structured taxonomy of security threats targeting LLM-IoT systems, (2) a review of LLMs as security enablers for IoT, (3) an evaluation of privacy-preserving architectures including federated learning, differential privacy, homomorphic encryption, and trusted execution environments, (4) domain-specific security analysis across healthcare, industrial, smart home, smart grid, and vehicular IoT, and (5) a literature-based comparative analysis of LLM-based security systems. A central finding is the accuracy&amp;amp;ndash;efficiency&amp;amp;ndash;privacy trilemma: the model compression techniques needed to deploy LLMs on resource-constrained IoT devices can degrade security and even introduce new vulnerabilities. Our analysis provides researchers and practitioners with a structured understanding of both the risks and opportunities at the frontier of LLM-IoT security.</p>
	]]></content:encoded>

	<dc:title>Securing the Cognitive Layer: A Survey on Security Threats, Defenses, and Privacy-Preserving Architectures for LLM-IoT Integration</dc:title>
			<dc:creator>Ayan Joshi</dc:creator>
			<dc:creator>Sabur Baidya</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020063</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Review</prism:section>
	<prism:startingPage>63</prism:startingPage>
		<prism:doi>10.3390/jcp6020063</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/63</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/61">

	<title>JCP, Vol. 6, Pages 61: Evaluating the Operational Impact of Automated Endpoint Compliance and Security Monitoring in Linux Environments</title>
	<link>https://www.mdpi.com/2624-800X/6/2/61</link>
	<description>Ensuring ongoing endpoint security compliance across diverse, hybrid IT infrastructures poses a continual operational challenge, especially in enterprise Linux systems, where manual verification methods are difficult to scale and prone to inconsistency. This study offers an empirical assessment of an automated methodology for monitoring endpoint compliance and security, applied within a mid-sized IT consulting firm. The suggested methodology incorporates automated compliance scanning, malware detection, endpoint verification, and remediation utilising open-source technology, all orchestrated through centralised automation and reporting systems. The evaluation follows an observational comparative methodology, contrasting manual compliance operations with automated enforcement across 60 Linux endpoints (30 Fedora and 30 Ubuntu systems) over two equivalent eight-week operational periods. The analysis emphasises operational parameters such as administrative workload, configuration uniformity, and audit preparedness. The findings demonstrate that automation reduced manual compliance-related tasks by roughly 70&amp;amp;ndash;80%, enhanced configuration consistency across endpoints through continuous enforcement, and enabled automated production of audit-ready compliance reports. The findings provide concrete evidence that operational security automation can markedly improve endpoint compliance management in business Linux and hybrid IT environments.</description>
	<pubDate>2026-04-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 61: Evaluating the Operational Impact of Automated Endpoint Compliance and Security Monitoring in Linux Environments</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/61">doi: 10.3390/jcp6020061</a></p>
	<p>Authors:
		Zlatan Morić
		Mislav Balković
		Donis Isić
		</p>
	<p>Ensuring ongoing endpoint security compliance across diverse, hybrid IT infrastructures poses a continual operational challenge, especially in enterprise Linux systems, where manual verification methods are difficult to scale and prone to inconsistency. This study offers an empirical assessment of an automated methodology for monitoring endpoint compliance and security, applied within a mid-sized IT consulting firm. The suggested methodology incorporates automated compliance scanning, malware detection, endpoint verification, and remediation utilising open-source technology, all orchestrated through centralised automation and reporting systems. The evaluation follows an observational comparative methodology, contrasting manual compliance operations with automated enforcement across 60 Linux endpoints (30 Fedora and 30 Ubuntu systems) over two equivalent eight-week operational periods. The analysis emphasises operational parameters such as administrative workload, configuration uniformity, and audit preparedness. The findings demonstrate that automation reduced manual compliance-related tasks by roughly 70&amp;amp;ndash;80%, enhanced configuration consistency across endpoints through continuous enforcement, and enabled automated production of audit-ready compliance reports. The findings provide concrete evidence that operational security automation can markedly improve endpoint compliance management in business Linux and hybrid IT environments.</p>
	]]></content:encoded>

	<dc:title>Evaluating the Operational Impact of Automated Endpoint Compliance and Security Monitoring in Linux Environments</dc:title>
			<dc:creator>Zlatan Morić</dc:creator>
			<dc:creator>Mislav Balković</dc:creator>
			<dc:creator>Donis Isić</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020061</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>61</prism:startingPage>
		<prism:doi>10.3390/jcp6020061</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/61</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/60">

	<title>JCP, Vol. 6, Pages 60: Towards Effective Cybersecurity Governance: Jordan Compliance System and Self-Assessment Tools</title>
	<link>https://www.mdpi.com/2624-800X/6/2/60</link>
	<description>Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations&amp;amp;rsquo; safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements and needs. These countries also provide assessment tools to check that organizations comply with these frameworks. This research emphasizes the importance of efficient cybersecurity governance practices, highlighting the Jordanian National Cyber Security Framework (JNCSF) that was announced in 2019. We have chosen this framework because, since its launch, it has not been presented or analyzed thoroughly by any of the existing studies. Moreover, the National Cyber Security Center (NCSC) in Jordan has not announced any public self-assessment tools for organizations to evaluate their compliance with the JNCSF. Therefore, the absence of a structured and publicly available self-assessment mechanism for the JNCSF creates a challenge for organizations in objectively measuring their cybersecurity governance readiness. Accordingly, the main contributions of this paper are to provide a detailed breakdown and discussion of the JNCSF, which supports organizations in Jordan and also shares the JNCSF philosophy regionally and internationally. Additionally, this study introduces an efficient self-assessment tool (named JCCT) that can be used both offline and online. JCCT accurately measures the institution&amp;amp;rsquo;s cybersecurity compliance against JNCSF and international standards (ISO and NIST), reflecting its current state and the potential impact on its risk profile. Moreover, this paper proposes new compliance score equations based on a comprehensive mathematical model that generally benefits any governance system. The JCCT tool offers rich, interactive, customized dashboards and automatically generates reports with recommended action plans for the organization.</description>
	<pubDate>2026-04-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 60: Towards Effective Cybersecurity Governance: Jordan Compliance System and Self-Assessment Tools</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/60">doi: 10.3390/jcp6020060</a></p>
	<p>Authors:
		Iman Almomani
		Shahed Mehdawi
		Yazeed Allabadi
		</p>
	<p>Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations&amp;amp;rsquo; safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements and needs. These countries also provide assessment tools to check that organizations comply with these frameworks. This research emphasizes the importance of efficient cybersecurity governance practices, highlighting the Jordanian National Cyber Security Framework (JNCSF) that was announced in 2019. We have chosen this framework because, since its launch, it has not been presented or analyzed thoroughly by any of the existing studies. Moreover, the National Cyber Security Center (NCSC) in Jordan has not announced any public self-assessment tools for organizations to evaluate their compliance with the JNCSF. Therefore, the absence of a structured and publicly available self-assessment mechanism for the JNCSF creates a challenge for organizations in objectively measuring their cybersecurity governance readiness. Accordingly, the main contributions of this paper are to provide a detailed breakdown and discussion of the JNCSF, which supports organizations in Jordan and also shares the JNCSF philosophy regionally and internationally. Additionally, this study introduces an efficient self-assessment tool (named JCCT) that can be used both offline and online. JCCT accurately measures the institution&amp;amp;rsquo;s cybersecurity compliance against JNCSF and international standards (ISO and NIST), reflecting its current state and the potential impact on its risk profile. Moreover, this paper proposes new compliance score equations based on a comprehensive mathematical model that generally benefits any governance system. The JCCT tool offers rich, interactive, customized dashboards and automatically generates reports with recommended action plans for the organization.</p>
	]]></content:encoded>

	<dc:title>Towards Effective Cybersecurity Governance: Jordan Compliance System and Self-Assessment Tools</dc:title>
			<dc:creator>Iman Almomani</dc:creator>
			<dc:creator>Shahed Mehdawi</dc:creator>
			<dc:creator>Yazeed Allabadi</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020060</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>60</prism:startingPage>
		<prism:doi>10.3390/jcp6020060</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/60</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/59">

	<title>JCP, Vol. 6, Pages 59: A Novel Approach to Sybil Attack Detection in VANETs Using Verifiable Delay Functions and Hierarchical Fog-Cloud Architecture</title>
	<link>https://www.mdpi.com/2624-800X/6/2/59</link>
	<description>Vehicular Ad Hoc Networks (VANETs) have become the foundation for the implementation of intelligent transportation systems and new vistas for road safety and traffic efficiency. However, these networks are still susceptible to Sybil attacks, a form of attack that requires malicious entities to create a series of fake identities in order to have an out-of-proportion influence. The present paper puts forth a new Sybil attack detection framework that combines Verifiable Delay Functions (VDFs) in synergistic cooperation with a hierarchical fog-cloud computing structure. Our method does not rely on any additional properties of VDFs but uses them to prove uniqueness computationally, deploying purposefully placed fog nodes for effective localized detection. We mathematically formulate a multi-layered detection algorithm that processes interactions between vehicles on two fog (and cloud) layers to produce suspicion scores using spatiotemporal consistency and VDF challenge-response patterns. Security analysis proves the system&amp;amp;rsquo;s ability to resist a range of Sybil attack variants with performance evaluation outperforming at detection above 97.8% and false positives below 2.3%. The incorporation of machine learning techniques also extends detection capabilities, and our hybrid VDF-ML method proves better adaptation to the changing attack patterns. Details of implementation and detailed simulations in various traffic situations prove the feasibility and efficiency of our proposed solution to set a new level playing ground for secure VANET communications.</description>
	<pubDate>2026-04-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 59: A Novel Approach to Sybil Attack Detection in VANETs Using Verifiable Delay Functions and Hierarchical Fog-Cloud Architecture</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/59">doi: 10.3390/jcp6020059</a></p>
	<p>Authors:
		Habiba Hadri
		Mourad Ouadou
		Khalid Minaoui
		</p>
	<p>Vehicular Ad Hoc Networks (VANETs) have become the foundation for the implementation of intelligent transportation systems and new vistas for road safety and traffic efficiency. However, these networks are still susceptible to Sybil attacks, a form of attack that requires malicious entities to create a series of fake identities in order to have an out-of-proportion influence. The present paper puts forth a new Sybil attack detection framework that combines Verifiable Delay Functions (VDFs) in synergistic cooperation with a hierarchical fog-cloud computing structure. Our method does not rely on any additional properties of VDFs but uses them to prove uniqueness computationally, deploying purposefully placed fog nodes for effective localized detection. We mathematically formulate a multi-layered detection algorithm that processes interactions between vehicles on two fog (and cloud) layers to produce suspicion scores using spatiotemporal consistency and VDF challenge-response patterns. Security analysis proves the system&amp;amp;rsquo;s ability to resist a range of Sybil attack variants with performance evaluation outperforming at detection above 97.8% and false positives below 2.3%. The incorporation of machine learning techniques also extends detection capabilities, and our hybrid VDF-ML method proves better adaptation to the changing attack patterns. Details of implementation and detailed simulations in various traffic situations prove the feasibility and efficiency of our proposed solution to set a new level playing ground for secure VANET communications.</p>
	]]></content:encoded>

	<dc:title>A Novel Approach to Sybil Attack Detection in VANETs Using Verifiable Delay Functions and Hierarchical Fog-Cloud Architecture</dc:title>
			<dc:creator>Habiba Hadri</dc:creator>
			<dc:creator>Mourad Ouadou</dc:creator>
			<dc:creator>Khalid Minaoui</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020059</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>59</prism:startingPage>
		<prism:doi>10.3390/jcp6020059</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/59</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/58">

	<title>JCP, Vol. 6, Pages 58: Machine Learning-Based Static Ransomware Detection Using PE Header Features and SHAP Interpretation</title>
	<link>https://www.mdpi.com/2624-800X/6/2/58</link>
	<description>Cybercriminals use advanced techniques to launch an attack against organizations, which causes disruption of normal business activities. The traditional signature-based malware detection methods are not effective in the detection of ransomware. Therefore, the use of machine learning and deep learning for malware detection is becoming a major area of research. There are two types of malware detection strategies, namely, static and dynamic. This work investigates the task-dependent effectiveness of static PE header-based detection by systematically evaluating three binary classification problems of increasing difficulty: ransomware vs. benign, malware vs. benign, and ransomware vs. other malware families. An end-to-end machine learning pipeline is implemented, including dataset-specific preprocessing, class imbalance handling, model training, and evaluation using imbalance-aware metrics. Random Forest, Support Vector Machine, and XGBoost models are assessed across all tasks, with SHAP used to analyze feature contribution and explain performance degradation. The experimental results demonstrate that tree-based ensemble models, particularly XGBoost, achieve strong detection performance when class boundaries are structurally distinct, but they struggle when ransomware must be distinguished from structurally similar malware. The results indicate that static analysis based on PE header features can be a viable approach for pre-execution triage, but they exhibit clear limitations for fine-grained ransomware discrimination.</description>
	<pubDate>2026-04-01</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 58: Machine Learning-Based Static Ransomware Detection Using PE Header Features and SHAP Interpretation</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/58">doi: 10.3390/jcp6020058</a></p>
	<p>Authors:
		Gabryella Barnes
		Ahmad Ghafarian
		</p>
	<p>Cybercriminals use advanced techniques to launch an attack against organizations, which causes disruption of normal business activities. The traditional signature-based malware detection methods are not effective in the detection of ransomware. Therefore, the use of machine learning and deep learning for malware detection is becoming a major area of research. There are two types of malware detection strategies, namely, static and dynamic. This work investigates the task-dependent effectiveness of static PE header-based detection by systematically evaluating three binary classification problems of increasing difficulty: ransomware vs. benign, malware vs. benign, and ransomware vs. other malware families. An end-to-end machine learning pipeline is implemented, including dataset-specific preprocessing, class imbalance handling, model training, and evaluation using imbalance-aware metrics. Random Forest, Support Vector Machine, and XGBoost models are assessed across all tasks, with SHAP used to analyze feature contribution and explain performance degradation. The experimental results demonstrate that tree-based ensemble models, particularly XGBoost, achieve strong detection performance when class boundaries are structurally distinct, but they struggle when ransomware must be distinguished from structurally similar malware. The results indicate that static analysis based on PE header features can be a viable approach for pre-execution triage, but they exhibit clear limitations for fine-grained ransomware discrimination.</p>
	]]></content:encoded>

	<dc:title>Machine Learning-Based Static Ransomware Detection Using PE Header Features and SHAP Interpretation</dc:title>
			<dc:creator>Gabryella Barnes</dc:creator>
			<dc:creator>Ahmad Ghafarian</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020058</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-04-01</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-04-01</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>58</prism:startingPage>
		<prism:doi>10.3390/jcp6020058</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/58</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/57">

	<title>JCP, Vol. 6, Pages 57: An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards</title>
	<link>https://www.mdpi.com/2624-800X/6/2/57</link>
	<description>The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational settings. A multi-case methodology was employed, encompassing a multinational corporate criminal investigation, an internal employee misbehaviour probe, and an examination into mobile- and cloud-based data leaks. The effect of synchronized standard implementation was evaluated using audit-based and quantitative indicators that measure forensic process quality as a system attribute. The findings demonstrate that the systematic implementation of ISO/IEC 27037 and ISO/IEC 27041 improves investigative traceability, documentation quality, and evidentiary robustness. In the worldwide case study, documentation completeness increased by 18%, and all digital evidence was deemed admissible in judicial proceedings, surpassing the institutional baseline admissibility rate of 82%. In other instances, evidence gathered within the same framework was acknowledged in organizational or disciplinary review processes, resulting in similar enhancements in documentation quality and procedural consistency, notwithstanding technological and organizational limitations. The paper develops and empirically substantiates an integrated procedural validation model that connects evidence-handling practices with method and instrument validation. The results indicate that the synchronized implementation of ISO/IEC forensic standards improves the transparency, dependability, and auditability of digital forensic investigations.</description>
	<pubDate>2026-03-30</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 57: An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/57">doi: 10.3390/jcp6020057</a></p>
	<p>Authors:
		Zlatan Morić
		Vedran Dakić
		Ivana Ogrizek Biškupić
		</p>
	<p>The escalating scale and complexity of cybercrime necessitate standardized digital forensic protocols to ensure the integrity and admissibility of digital evidence. This study empirically assesses the use of ISO/IEC 27037 and ISO/IEC 27041 through three real-world digital forensic case studies conducted in organizational settings. A multi-case methodology was employed, encompassing a multinational corporate criminal investigation, an internal employee misbehaviour probe, and an examination into mobile- and cloud-based data leaks. The effect of synchronized standard implementation was evaluated using audit-based and quantitative indicators that measure forensic process quality as a system attribute. The findings demonstrate that the systematic implementation of ISO/IEC 27037 and ISO/IEC 27041 improves investigative traceability, documentation quality, and evidentiary robustness. In the worldwide case study, documentation completeness increased by 18%, and all digital evidence was deemed admissible in judicial proceedings, surpassing the institutional baseline admissibility rate of 82%. In other instances, evidence gathered within the same framework was acknowledged in organizational or disciplinary review processes, resulting in similar enhancements in documentation quality and procedural consistency, notwithstanding technological and organizational limitations. The paper develops and empirically substantiates an integrated procedural validation model that connects evidence-handling practices with method and instrument validation. The results indicate that the synchronized implementation of ISO/IEC forensic standards improves the transparency, dependability, and auditability of digital forensic investigations.</p>
	]]></content:encoded>

	<dc:title>An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards</dc:title>
			<dc:creator>Zlatan Morić</dc:creator>
			<dc:creator>Vedran Dakić</dc:creator>
			<dc:creator>Ivana Ogrizek Biškupić</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020057</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-30</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-30</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>57</prism:startingPage>
		<prism:doi>10.3390/jcp6020057</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/57</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/56">

	<title>JCP, Vol. 6, Pages 56: HyperShield: An Automated Evaluation Platform for Security and Performance Trade-Offs in Virtual Systems</title>
	<link>https://www.mdpi.com/2624-800X/6/2/56</link>
	<description>Virtualization is the building block of modern cloud computing infrastructure. However, it remains vulnerable to a range of security threats, including malicious co-located tenants, hypervisor vulnerabilities, and side-channel attacks. These threats are generally mitigated by developing and deploying advanced and complex security solutions that incur significant performance overhead. Prior work on virtual machines (VMs) and containers has mainly evaluated basic security solutions, such as firewalls, using narrow performance metrics and synthetic models within limited evaluation frameworks. These studies often overlook advanced security modules in both user and kernel space, lack the flexibility to incorporate emerging features, and fail to capture detailed system-level impacts. We address these gaps with HyperShield, an open-source framework for unified security evaluation across VMs and containers that mimics a realistic cloud infrastructure. HyperShield supports advanced security modules in both user and kernel space, providing rich system-level performance metrics for comprehensive evaluation. Our performance evaluation shows that containers generally outperform VMs due to their lower virtualization overhead, achieving a throughput of 9.38 Gb/s compared to 1.98 Gb/s for VMs for our benchmarks. However, VMs&amp;amp;rsquo; performance is comparable for kernel-space deployments, as Docker uses the shared kernel space of the Docker bridge, which can result in packet congestion. In latency-sensitive workloads, VM access latency of 14.91 ms is comparable to Docker&amp;amp;rsquo;s 12.86 ms. In storage benchmarks, FIO, however, VMs outperform Docker due to the overhead of Docker&amp;amp;rsquo;s layered, copy-on-write file system, whereas VMs leverage optimized virtual block devices with near-native I/O performance. These results highlight performance dependencies on benchmark choice, trade-offs in deploying security workloads between user and kernel space, and the choice of containers and virtual machines as virtualization environments. Therefore, HyperShield provides a comprehensive evaluation toolkit for exploring an optimal security-module deployment strategy.</description>
	<pubDate>2026-03-24</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 56: HyperShield: An Automated Evaluation Platform for Security and Performance Trade-Offs in Virtual Systems</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/56">doi: 10.3390/jcp6020056</a></p>
	<p>Authors:
		Faiz Alam
		Mohammed Mubeen Mifthak
		Sahil Bhalchandra Purohit
		Md Shadab
		Gregory T. Byrd
		Khaled Harfoush
		</p>
	<p>Virtualization is the building block of modern cloud computing infrastructure. However, it remains vulnerable to a range of security threats, including malicious co-located tenants, hypervisor vulnerabilities, and side-channel attacks. These threats are generally mitigated by developing and deploying advanced and complex security solutions that incur significant performance overhead. Prior work on virtual machines (VMs) and containers has mainly evaluated basic security solutions, such as firewalls, using narrow performance metrics and synthetic models within limited evaluation frameworks. These studies often overlook advanced security modules in both user and kernel space, lack the flexibility to incorporate emerging features, and fail to capture detailed system-level impacts. We address these gaps with HyperShield, an open-source framework for unified security evaluation across VMs and containers that mimics a realistic cloud infrastructure. HyperShield supports advanced security modules in both user and kernel space, providing rich system-level performance metrics for comprehensive evaluation. Our performance evaluation shows that containers generally outperform VMs due to their lower virtualization overhead, achieving a throughput of 9.38 Gb/s compared to 1.98 Gb/s for VMs for our benchmarks. However, VMs&amp;amp;rsquo; performance is comparable for kernel-space deployments, as Docker uses the shared kernel space of the Docker bridge, which can result in packet congestion. In latency-sensitive workloads, VM access latency of 14.91 ms is comparable to Docker&amp;amp;rsquo;s 12.86 ms. In storage benchmarks, FIO, however, VMs outperform Docker due to the overhead of Docker&amp;amp;rsquo;s layered, copy-on-write file system, whereas VMs leverage optimized virtual block devices with near-native I/O performance. These results highlight performance dependencies on benchmark choice, trade-offs in deploying security workloads between user and kernel space, and the choice of containers and virtual machines as virtualization environments. Therefore, HyperShield provides a comprehensive evaluation toolkit for exploring an optimal security-module deployment strategy.</p>
	]]></content:encoded>

	<dc:title>HyperShield: An Automated Evaluation Platform for Security and Performance Trade-Offs in Virtual Systems</dc:title>
			<dc:creator>Faiz Alam</dc:creator>
			<dc:creator>Mohammed Mubeen Mifthak</dc:creator>
			<dc:creator>Sahil Bhalchandra Purohit</dc:creator>
			<dc:creator>Md Shadab</dc:creator>
			<dc:creator>Gregory T. Byrd</dc:creator>
			<dc:creator>Khaled Harfoush</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020056</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-24</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-24</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>56</prism:startingPage>
		<prism:doi>10.3390/jcp6020056</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/56</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/55">

	<title>JCP, Vol. 6, Pages 55: Tracking Real-Time Anomalies in Cyber&amp;ndash;Physical Systems Through Dynamic Behavioral Analysis</title>
	<link>https://www.mdpi.com/2624-800X/6/2/55</link>
	<description>Embedded devices in modern power systems offer increased connectivity and remote reprogrammability/reconfigurability. These features along with interconnections between Information Technology (IT) and Operational Technology (OT) networks enable greater agility, reduced operator workload, and enhanced power system performance and capabilities, as well as expanding the cyber-attack surface. This increased cyber-attack surface, as well as increasingly complex, diverse, and potentially untrustworthy software/hardware supply chains, increases the need for robust real-time monitoring in power systems, and more generally in cyber&amp;amp;ndash;physical systems (CPS). We propose a novel framework for real-time monitoring and anomaly detection in CPS, specifically smart grid substations and SCADA systems. The proposed framework enables real-time signal temporal logic condition-based anomaly monitoring by processing raw captured packets from the communication network through a hierarchical semantic extraction and tag processing pipeline into a time series of semantic events and observations, that are then evaluated against expected temporal properties to detect and localize anomalies. We demonstrate the efficacy of our methodology on a hardware in the loop (HITL) testbed under several attack scenarios. The HITL testbed includes multiple physical power system devices (real-time automation controllers and relays) and simulated devices (Phasor Measurement Units&amp;amp;mdash;PMUs, relays, Phasor Data Concentrators&amp;amp;mdash;PDCs), all interfaced to a dynamic power system simulator.</description>
	<pubDate>2026-03-23</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 55: Tracking Real-Time Anomalies in Cyber&amp;ndash;Physical Systems Through Dynamic Behavioral Analysis</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/55">doi: 10.3390/jcp6020055</a></p>
	<p>Authors:
		Prashanth Krishnamurthy
		Ali Rasteh
		Ramesh Karri
		Farshad Khorrami
		</p>
	<p>Embedded devices in modern power systems offer increased connectivity and remote reprogrammability/reconfigurability. These features along with interconnections between Information Technology (IT) and Operational Technology (OT) networks enable greater agility, reduced operator workload, and enhanced power system performance and capabilities, as well as expanding the cyber-attack surface. This increased cyber-attack surface, as well as increasingly complex, diverse, and potentially untrustworthy software/hardware supply chains, increases the need for robust real-time monitoring in power systems, and more generally in cyber&amp;amp;ndash;physical systems (CPS). We propose a novel framework for real-time monitoring and anomaly detection in CPS, specifically smart grid substations and SCADA systems. The proposed framework enables real-time signal temporal logic condition-based anomaly monitoring by processing raw captured packets from the communication network through a hierarchical semantic extraction and tag processing pipeline into a time series of semantic events and observations, that are then evaluated against expected temporal properties to detect and localize anomalies. We demonstrate the efficacy of our methodology on a hardware in the loop (HITL) testbed under several attack scenarios. The HITL testbed includes multiple physical power system devices (real-time automation controllers and relays) and simulated devices (Phasor Measurement Units&amp;amp;mdash;PMUs, relays, Phasor Data Concentrators&amp;amp;mdash;PDCs), all interfaced to a dynamic power system simulator.</p>
	]]></content:encoded>

	<dc:title>Tracking Real-Time Anomalies in Cyber&amp;amp;ndash;Physical Systems Through Dynamic Behavioral Analysis</dc:title>
			<dc:creator>Prashanth Krishnamurthy</dc:creator>
			<dc:creator>Ali Rasteh</dc:creator>
			<dc:creator>Ramesh Karri</dc:creator>
			<dc:creator>Farshad Khorrami</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020055</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-23</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-23</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>55</prism:startingPage>
		<prism:doi>10.3390/jcp6020055</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/55</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/54">

	<title>JCP, Vol. 6, Pages 54: Blockchain as a Cybersecurity Enabler in Federated Networks for Resilience and Interoperability</title>
	<link>https://www.mdpi.com/2624-800X/6/2/54</link>
	<description>In increasingly interconnected tactical environments, cybersecurity, trust, and interoperability must evolve in tandem. Federated Coalition Networks (FCNs) enable multinational cooperation while preserving national sovereignty; however, the secure management of identities, policies, and configurations across coalition domains remains a critical challenge, particularly under adversarial and resource-constrained conditions. This paper proposes a blockchain-enabled management framework aligned with the defense-in-depth paradigm, focusing on management-plane functions such as policy enforcement, public key infrastructure (PKI) management, and auditable governance, rather than time-critical tactical communications. The solution relies on a permissioned blockchain architecture with Byzantine Fault Tolerant consensus, avoiding energy-intensive Proof-of-Work mechanisms and supporting operation under Disconnected, Intermittent, and Low-bandwidth (DIL) conditions. A coalition-level trust-and-governance model is introduced to prevent unilateral control while preserving national autonomy. A realistic use case and a proof-of-concept implementation demonstrate the feasibility of the approach, showing bounded latency, limited energy overhead, and sufficient throughput for FCN management. These results indicate that appropriately tailored blockchain solutions can effectively enhance resilience, trust, and compliance in federated defense networks.</description>
	<pubDate>2026-03-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 54: Blockchain as a Cybersecurity Enabler in Federated Networks for Resilience and Interoperability</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/54">doi: 10.3390/jcp6020054</a></p>
	<p>Authors:
		Jorge Álvaro González
		Ana María Saiz García
		Victor Monzon Baeza
		</p>
	<p>In increasingly interconnected tactical environments, cybersecurity, trust, and interoperability must evolve in tandem. Federated Coalition Networks (FCNs) enable multinational cooperation while preserving national sovereignty; however, the secure management of identities, policies, and configurations across coalition domains remains a critical challenge, particularly under adversarial and resource-constrained conditions. This paper proposes a blockchain-enabled management framework aligned with the defense-in-depth paradigm, focusing on management-plane functions such as policy enforcement, public key infrastructure (PKI) management, and auditable governance, rather than time-critical tactical communications. The solution relies on a permissioned blockchain architecture with Byzantine Fault Tolerant consensus, avoiding energy-intensive Proof-of-Work mechanisms and supporting operation under Disconnected, Intermittent, and Low-bandwidth (DIL) conditions. A coalition-level trust-and-governance model is introduced to prevent unilateral control while preserving national autonomy. A realistic use case and a proof-of-concept implementation demonstrate the feasibility of the approach, showing bounded latency, limited energy overhead, and sufficient throughput for FCN management. These results indicate that appropriately tailored blockchain solutions can effectively enhance resilience, trust, and compliance in federated defense networks.</p>
	]]></content:encoded>

	<dc:title>Blockchain as a Cybersecurity Enabler in Federated Networks for Resilience and Interoperability</dc:title>
			<dc:creator>Jorge Álvaro González</dc:creator>
			<dc:creator>Ana María Saiz García</dc:creator>
			<dc:creator>Victor Monzon Baeza</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020054</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>54</prism:startingPage>
		<prism:doi>10.3390/jcp6020054</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/54</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/53">

	<title>JCP, Vol. 6, Pages 53: Security Compliance as a Catalyst for Sustainable Partnerships: A Design Science Approach for SMEs</title>
	<link>https://www.mdpi.com/2624-800X/6/2/53</link>
	<description>Small-and-medium-sized enterprises (SMEs) increasingly depend on business partnerships to access markets and scale operations, yet they often face trust barriers during contract formation due to the complexity of the verification of their cybersecurity posture and compliance status by their partners. This problem is intensified by rising regulatory expectations, notably the EU Cyber Resilience Act (CRA), which many SMEs struggle to interpret and operationalize under constraints of budget, skills, and fragmented responsibilities. This study adopts a Design Science Research approach to blueprint and evaluate a lightweight mapping framework that links commonly implemented security controls to CRA requirements and to widely recognized benchmarks (ISO/IEC 27001 and CIS). Grounded in Institutional Theory and Socio-Technical Systems Theory, the artefact translates regulatory obligations into actionable, evidence-backed controls and produces partner-facing outputs that support transparency in negotiations and service level agreements. The framework is iteratively co-created with a multidisciplinary expert community. Expected contributions include a practical mechanism for making cybersecurity maturity visible, accelerating partnership formation, and enabling sustainable interorganizational relationships while remaining feasible for resource-constrained SMEs.</description>
	<pubDate>2026-03-13</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 53: Security Compliance as a Catalyst for Sustainable Partnerships: A Design Science Approach for SMEs</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/53">doi: 10.3390/jcp6020053</a></p>
	<p>Authors:
		Francisco Conceição
		Manuel Rocha
		Fernando Almeida
		</p>
	<p>Small-and-medium-sized enterprises (SMEs) increasingly depend on business partnerships to access markets and scale operations, yet they often face trust barriers during contract formation due to the complexity of the verification of their cybersecurity posture and compliance status by their partners. This problem is intensified by rising regulatory expectations, notably the EU Cyber Resilience Act (CRA), which many SMEs struggle to interpret and operationalize under constraints of budget, skills, and fragmented responsibilities. This study adopts a Design Science Research approach to blueprint and evaluate a lightweight mapping framework that links commonly implemented security controls to CRA requirements and to widely recognized benchmarks (ISO/IEC 27001 and CIS). Grounded in Institutional Theory and Socio-Technical Systems Theory, the artefact translates regulatory obligations into actionable, evidence-backed controls and produces partner-facing outputs that support transparency in negotiations and service level agreements. The framework is iteratively co-created with a multidisciplinary expert community. Expected contributions include a practical mechanism for making cybersecurity maturity visible, accelerating partnership formation, and enabling sustainable interorganizational relationships while remaining feasible for resource-constrained SMEs.</p>
	]]></content:encoded>

	<dc:title>Security Compliance as a Catalyst for Sustainable Partnerships: A Design Science Approach for SMEs</dc:title>
			<dc:creator>Francisco Conceição</dc:creator>
			<dc:creator>Manuel Rocha</dc:creator>
			<dc:creator>Fernando Almeida</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020053</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-13</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-13</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>53</prism:startingPage>
		<prism:doi>10.3390/jcp6020053</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/53</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/52">

	<title>JCP, Vol. 6, Pages 52: Security Aspects of Zones and Conduits in IEC 62443</title>
	<link>https://www.mdpi.com/2624-800X/6/2/52</link>
	<description>The IEC 62443 standard defines that, based on risk assessment, different parts of an Industrial Automation and Control System (IACS) may have different security levels, and that parts with the same security level can be designated as separate zones. Furthermore, communication between different zones, both intra-IACS and inter-IACS, can be done via conduits. In this article, we argue that zones and particularly conduits can benefit from more detailed discussions of their architecture and implementation. Consequently, as novel contributions we (1) describe detailed principles for implementing conduits; (2) outline a process for connecting zones with potentially different Security Levels (SLs), expressed in the form of a flow chart; and (3) discuss challenges related to the application of zones and conduits in practice.</description>
	<pubDate>2026-03-12</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 52: Security Aspects of Zones and Conduits in IEC 62443</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/52">doi: 10.3390/jcp6020052</a></p>
	<p>Authors:
		Martin Gilje Jaatun
		Mary Ann Lundteigen
		Christoph Thieme
		Lars Halvdan Flå
		Karin Bernsmed
		Roald Lygre
		Fredrik Gratte
		</p>
	<p>The IEC 62443 standard defines that, based on risk assessment, different parts of an Industrial Automation and Control System (IACS) may have different security levels, and that parts with the same security level can be designated as separate zones. Furthermore, communication between different zones, both intra-IACS and inter-IACS, can be done via conduits. In this article, we argue that zones and particularly conduits can benefit from more detailed discussions of their architecture and implementation. Consequently, as novel contributions we (1) describe detailed principles for implementing conduits; (2) outline a process for connecting zones with potentially different Security Levels (SLs), expressed in the form of a flow chart; and (3) discuss challenges related to the application of zones and conduits in practice.</p>
	]]></content:encoded>

	<dc:title>Security Aspects of Zones and Conduits in IEC 62443</dc:title>
			<dc:creator>Martin Gilje Jaatun</dc:creator>
			<dc:creator>Mary Ann Lundteigen</dc:creator>
			<dc:creator>Christoph Thieme</dc:creator>
			<dc:creator>Lars Halvdan Flå</dc:creator>
			<dc:creator>Karin Bernsmed</dc:creator>
			<dc:creator>Roald Lygre</dc:creator>
			<dc:creator>Fredrik Gratte</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020052</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-12</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-12</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>52</prism:startingPage>
		<prism:doi>10.3390/jcp6020052</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/52</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/51">

	<title>JCP, Vol. 6, Pages 51: Beyond Semantic Noise: A Dual-Verification Framework for Thai&amp;ndash;English Code-Mixed Malicious Script Detection via XAI-Guided Selective Integration</title>
	<link>https://www.mdpi.com/2624-800X/6/2/51</link>
	<description>In the evolving cybersecurity landscape, detecting Thai-English code-mixed malicious scripts within high-trust domains such as governmental and academic portals presents a significant defensive challenge. While Transformer-based architectures excel in semantic parsing, they often exhibit &amp;amp;lsquo;Structural Bias,&amp;amp;rsquo; misinterpreting the high-entropy syntax of benign legacy HyperText Markup Language (HTML) as malicious obfuscation due to inherent &amp;amp;lsquo;Attention Deficit&amp;amp;rsquo; in token-limited models. To address this, we propose an Explainable AI (XAI)-Driven Hybrid Architecture grounded in a &amp;amp;lsquo;Selective Integration&amp;amp;rsquo; strategy. Unlike traditional hybrid models, our framework mathematically formalizes the fusion process by synergizing context-aware WangChanBERTa embeddings with orthogonal structural statistics through Dempster-Shafer Theory and Conditional Mutual Information (CMI). The proposed model was validated on a high-fidelity corpus, achieving a state-of-the-art F1-score of 0.9908, significantly outperforming standalone Transformers, Random Forest, and unsupervised baselines. XAI diagnostics revealed a &amp;amp;lsquo;Dual-Validation&amp;amp;rsquo; mechanism where structural features act as an epistemic anchor. This mechanism effectively triggers a &amp;amp;lsquo;Semantic Veto&amp;amp;rsquo; to filter hallucinations caused by benign complexity, achieving a remarkably low False Positive Rate (FPR) of 0.0116. Our findings demonstrate that hybridization is most effective when engineered features provide mathematical orthogonality to semantic embeddings. This work offers a robust, theoretically grounded framework for securing critical digital infrastructures in low-resource linguistic environments.</description>
	<pubDate>2026-03-09</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 51: Beyond Semantic Noise: A Dual-Verification Framework for Thai&amp;ndash;English Code-Mixed Malicious Script Detection via XAI-Guided Selective Integration</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/51">doi: 10.3390/jcp6020051</a></p>
	<p>Authors:
		Prasert Teppap
		Wirot Ponglangka
		Panudech Tipauksorn
		Prasert Luekhong
		</p>
	<p>In the evolving cybersecurity landscape, detecting Thai-English code-mixed malicious scripts within high-trust domains such as governmental and academic portals presents a significant defensive challenge. While Transformer-based architectures excel in semantic parsing, they often exhibit &amp;amp;lsquo;Structural Bias,&amp;amp;rsquo; misinterpreting the high-entropy syntax of benign legacy HyperText Markup Language (HTML) as malicious obfuscation due to inherent &amp;amp;lsquo;Attention Deficit&amp;amp;rsquo; in token-limited models. To address this, we propose an Explainable AI (XAI)-Driven Hybrid Architecture grounded in a &amp;amp;lsquo;Selective Integration&amp;amp;rsquo; strategy. Unlike traditional hybrid models, our framework mathematically formalizes the fusion process by synergizing context-aware WangChanBERTa embeddings with orthogonal structural statistics through Dempster-Shafer Theory and Conditional Mutual Information (CMI). The proposed model was validated on a high-fidelity corpus, achieving a state-of-the-art F1-score of 0.9908, significantly outperforming standalone Transformers, Random Forest, and unsupervised baselines. XAI diagnostics revealed a &amp;amp;lsquo;Dual-Validation&amp;amp;rsquo; mechanism where structural features act as an epistemic anchor. This mechanism effectively triggers a &amp;amp;lsquo;Semantic Veto&amp;amp;rsquo; to filter hallucinations caused by benign complexity, achieving a remarkably low False Positive Rate (FPR) of 0.0116. Our findings demonstrate that hybridization is most effective when engineered features provide mathematical orthogonality to semantic embeddings. This work offers a robust, theoretically grounded framework for securing critical digital infrastructures in low-resource linguistic environments.</p>
	]]></content:encoded>

	<dc:title>Beyond Semantic Noise: A Dual-Verification Framework for Thai&amp;amp;ndash;English Code-Mixed Malicious Script Detection via XAI-Guided Selective Integration</dc:title>
			<dc:creator>Prasert Teppap</dc:creator>
			<dc:creator>Wirot Ponglangka</dc:creator>
			<dc:creator>Panudech Tipauksorn</dc:creator>
			<dc:creator>Prasert Luekhong</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020051</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-09</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-09</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>51</prism:startingPage>
		<prism:doi>10.3390/jcp6020051</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/51</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/50">

	<title>JCP, Vol. 6, Pages 50: Performance Evaluation of Advanced Encryption Standard and Blowfish Encryption on WearOS: Implications for Wearable Device Security</title>
	<link>https://www.mdpi.com/2624-800X/6/2/50</link>
	<description>In this study, we evaluated the performance of the Advanced Encryption Standard (AES)-128, AES-256, and Blowfish algorithms on WearOS for messages ranging from 8 to 128 bytes, which are typical message sizes for contemporary smartwatch applications. Using a WearOS emulator, we measured encryption time, memory usage, central processing unit (CPU) utilization, and battery consumption across 16 messages sizes with 10 repetitions over each configuration. The AES-128 algorithm consistently outperformed the others with approximately 1.0 ms of encryption time at 128 bytes, less than 6 KB memory, and less than 39% peak CPU utilization. The AES-256 algorithm added 25&amp;amp;ndash;30% processing overhead and higher energy consumption with negligible extra memory cost. The Blowfish algorithm consumed approximately three times more memory and exhibited the highest battery consumption per operation. It also scales poorly due to its 64-bit block size and large key scheduling approach. In addition, all performance differences are highly statistically significant (p &amp;amp;lt; 0.001). Given the widespread hardware AES acceleration on WearOS devices and memory constraints, AES-128 is recommended as the default symmetric encryption algorithm for confidentiality in smartwatch applications.</description>
	<pubDate>2026-03-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 50: Performance Evaluation of Advanced Encryption Standard and Blowfish Encryption on WearOS: Implications for Wearable Device Security</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/50">doi: 10.3390/jcp6020050</a></p>
	<p>Authors:
		Sirapat Boonkrong
		Papitchaya Kaensawan
		</p>
	<p>In this study, we evaluated the performance of the Advanced Encryption Standard (AES)-128, AES-256, and Blowfish algorithms on WearOS for messages ranging from 8 to 128 bytes, which are typical message sizes for contemporary smartwatch applications. Using a WearOS emulator, we measured encryption time, memory usage, central processing unit (CPU) utilization, and battery consumption across 16 messages sizes with 10 repetitions over each configuration. The AES-128 algorithm consistently outperformed the others with approximately 1.0 ms of encryption time at 128 bytes, less than 6 KB memory, and less than 39% peak CPU utilization. The AES-256 algorithm added 25&amp;amp;ndash;30% processing overhead and higher energy consumption with negligible extra memory cost. The Blowfish algorithm consumed approximately three times more memory and exhibited the highest battery consumption per operation. It also scales poorly due to its 64-bit block size and large key scheduling approach. In addition, all performance differences are highly statistically significant (p &amp;amp;lt; 0.001). Given the widespread hardware AES acceleration on WearOS devices and memory constraints, AES-128 is recommended as the default symmetric encryption algorithm for confidentiality in smartwatch applications.</p>
	]]></content:encoded>

	<dc:title>Performance Evaluation of Advanced Encryption Standard and Blowfish Encryption on WearOS: Implications for Wearable Device Security</dc:title>
			<dc:creator>Sirapat Boonkrong</dc:creator>
			<dc:creator>Papitchaya Kaensawan</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020050</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>50</prism:startingPage>
		<prism:doi>10.3390/jcp6020050</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/50</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/49">

	<title>JCP, Vol. 6, Pages 49: Operational Threat Modeling of Adversarial Disturbances in Continuous-Variable Quantum Communication</title>
	<link>https://www.mdpi.com/2624-800X/6/2/49</link>
	<description>Continuous-variable quantum communication (CVQC) relies on finite-window estimation of phase space moments, making receiver decisions sensitive to finite measurement resolution, calibration uncertainty, and confidence-calibrated tolerances. This paper develops a receiver-centric threat modeling framework for structured (including adversarial) physical-layer disturbances under finite-sample inference. We introduce an operational taxonomy, reconnaissance, exploratory, and denial-of-service, defined by statistical visibility relative to acceptance regions rather than by assumed physical mechanisms. Using an effective estimator space Gaussian model r^&amp;amp;prime;=Gr^+&amp;amp;xi; with additive covariance N, we show how distinct mechanisms can be observationally equivalent within finite tolerances and we propose a protocol-agnostic scalar severity coordinate &amp;amp;Delta;E based on the covariance trace. We derive &amp;amp;chi;2-based missed-detection expressions and a soft detectability boundary scaling as 1/n, and we corroborate the predicted Pmiss(&amp;amp;nu;) behavior via Monte Carlo simulations across representative block sizes. The resulting framework clarifies the delimitation from conventional CV-QKD excess noise parameterization and provides a structured basis for monitoring-layer design and comparative threat-taxonomy mapping.</description>
	<pubDate>2026-03-07</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 49: Operational Threat Modeling of Adversarial Disturbances in Continuous-Variable Quantum Communication</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/49">doi: 10.3390/jcp6020049</a></p>
	<p>Authors:
		José R. Rosas-Bustos
		Jesse Van Griensven Thé
		Roydon Andrew Fraser
		Nadeem Said
		Sebastian Ratto Valderrama
		Mark Pecen
		Alexander Truskovsky
		Andy Thanos
		</p>
	<p>Continuous-variable quantum communication (CVQC) relies on finite-window estimation of phase space moments, making receiver decisions sensitive to finite measurement resolution, calibration uncertainty, and confidence-calibrated tolerances. This paper develops a receiver-centric threat modeling framework for structured (including adversarial) physical-layer disturbances under finite-sample inference. We introduce an operational taxonomy, reconnaissance, exploratory, and denial-of-service, defined by statistical visibility relative to acceptance regions rather than by assumed physical mechanisms. Using an effective estimator space Gaussian model r^&amp;amp;prime;=Gr^+&amp;amp;xi; with additive covariance N, we show how distinct mechanisms can be observationally equivalent within finite tolerances and we propose a protocol-agnostic scalar severity coordinate &amp;amp;Delta;E based on the covariance trace. We derive &amp;amp;chi;2-based missed-detection expressions and a soft detectability boundary scaling as 1/n, and we corroborate the predicted Pmiss(&amp;amp;nu;) behavior via Monte Carlo simulations across representative block sizes. The resulting framework clarifies the delimitation from conventional CV-QKD excess noise parameterization and provides a structured basis for monitoring-layer design and comparative threat-taxonomy mapping.</p>
	]]></content:encoded>

	<dc:title>Operational Threat Modeling of Adversarial Disturbances in Continuous-Variable Quantum Communication</dc:title>
			<dc:creator>José R. Rosas-Bustos</dc:creator>
			<dc:creator>Jesse Van Griensven Thé</dc:creator>
			<dc:creator>Roydon Andrew Fraser</dc:creator>
			<dc:creator>Nadeem Said</dc:creator>
			<dc:creator>Sebastian Ratto Valderrama</dc:creator>
			<dc:creator>Mark Pecen</dc:creator>
			<dc:creator>Alexander Truskovsky</dc:creator>
			<dc:creator>Andy Thanos</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020049</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-07</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-07</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>49</prism:startingPage>
		<prism:doi>10.3390/jcp6020049</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/49</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/48">

	<title>JCP, Vol. 6, Pages 48: Small Language Models for Phishing Website Detection: Cost, Performance, and Privacy Trade-Offs</title>
	<link>https://www.mdpi.com/2624-800X/6/2/48</link>
	<description>Phishing websites pose a major cybersecurity threat, exploiting unsuspecting users and causing significant financial and organisational harm. Traditional machine learning approaches for phishing detection often require extensive feature engineering, continuous retraining, and costly infrastructure maintenance. At the same time, proprietary large language models (LLMs) have demonstrated strong performance in phishing-related classification tasks, but their operational costs and reliance on external providers limit their practical adoption in many business environments. This paper presents a detection pipeline for malicious websites and investigates the feasibility of Small Language Models (SLMs) using raw HTML code and URLs. A key advantage of these models is that they can be deployed on local infrastructure, providing organisations with greater control over data and operations. We systematically evaluate 15 commonly used SLMs, ranging from 1 billion to 70 billion parameters, benchmarking their classification accuracy, computational requirements, and cost-efficiency. Our results highlight the trade-offs between detection performance and resource consumption. While SLMs underperform compared to state-of-the-art proprietary LLMs, the gap is moderate: the best SLM achieves an F1-score of 0.893 (Llama3.3:70B), compared to 0.929 for GPT-5.2, indicating that open-source models can provide a viable and scalable alternative to external LLM services.</description>
	<pubDate>2026-03-05</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 48: Small Language Models for Phishing Website Detection: Cost, Performance, and Privacy Trade-Offs</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/48">doi: 10.3390/jcp6020048</a></p>
	<p>Authors:
		Georg Goldenits
		Philip König
		Sebastian Raubitzek
		Andreas Ekelhart
		</p>
	<p>Phishing websites pose a major cybersecurity threat, exploiting unsuspecting users and causing significant financial and organisational harm. Traditional machine learning approaches for phishing detection often require extensive feature engineering, continuous retraining, and costly infrastructure maintenance. At the same time, proprietary large language models (LLMs) have demonstrated strong performance in phishing-related classification tasks, but their operational costs and reliance on external providers limit their practical adoption in many business environments. This paper presents a detection pipeline for malicious websites and investigates the feasibility of Small Language Models (SLMs) using raw HTML code and URLs. A key advantage of these models is that they can be deployed on local infrastructure, providing organisations with greater control over data and operations. We systematically evaluate 15 commonly used SLMs, ranging from 1 billion to 70 billion parameters, benchmarking their classification accuracy, computational requirements, and cost-efficiency. Our results highlight the trade-offs between detection performance and resource consumption. While SLMs underperform compared to state-of-the-art proprietary LLMs, the gap is moderate: the best SLM achieves an F1-score of 0.893 (Llama3.3:70B), compared to 0.929 for GPT-5.2, indicating that open-source models can provide a viable and scalable alternative to external LLM services.</p>
	]]></content:encoded>

	<dc:title>Small Language Models for Phishing Website Detection: Cost, Performance, and Privacy Trade-Offs</dc:title>
			<dc:creator>Georg Goldenits</dc:creator>
			<dc:creator>Philip König</dc:creator>
			<dc:creator>Sebastian Raubitzek</dc:creator>
			<dc:creator>Andreas Ekelhart</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020048</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-05</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-05</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>48</prism:startingPage>
		<prism:doi>10.3390/jcp6020048</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/48</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/47">

	<title>JCP, Vol. 6, Pages 47: Gated Residual Chebyshev KAN for Lightweight IoT DDoS Detection</title>
	<link>https://www.mdpi.com/2624-800X/6/2/47</link>
	<description>Distributed denial-of-service (DDoS) attacks have become a critical threat to Internet of Things (IoT) infrastructures due to their high traffic dynamics, strong class imbalance, and strict resource constraints at the edge. This paper proposes ChebyKANRes, a lightweight intrusion detection model that combines Chebyshev polynomial expansions to parameterize learnable univariate transformations, a gate mechanism to modulate feature flow, and residual connections to stabilize optimization in deeper KAN-style stacks. Experiments were conducted on the CICIoT2023 dataset focusing on benign traffic and 12 DDoS subtypes, using a reproducible pipeline with stratified splitting, cross-validation (k = 5), and early stopping. The proposed model consistently improves multi-class performance (Accuracy: 0.9983) over an optimized MLP baseline (Accuracy: 0.9641), while maintaining a compact size suitable for edge deployment (&amp;amp;asymp;123 k parameters; ~0.47 MB). Within CICIoT2023 and the evaluated split/training protocol, the proposed ChebyKANRes configuration shows improved imbalance-robust multiclass detection while maintaining a compact model size and comparable batch inference time.</description>
	<pubDate>2026-03-04</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 47: Gated Residual Chebyshev KAN for Lightweight IoT DDoS Detection</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/47">doi: 10.3390/jcp6020047</a></p>
	<p>Authors:
		Fray L. Becerra-Suarez
		Edwin Valencia-Castillo
		Ana G. Borrero-Ramírez
		Manuel G. Forero
		</p>
	<p>Distributed denial-of-service (DDoS) attacks have become a critical threat to Internet of Things (IoT) infrastructures due to their high traffic dynamics, strong class imbalance, and strict resource constraints at the edge. This paper proposes ChebyKANRes, a lightweight intrusion detection model that combines Chebyshev polynomial expansions to parameterize learnable univariate transformations, a gate mechanism to modulate feature flow, and residual connections to stabilize optimization in deeper KAN-style stacks. Experiments were conducted on the CICIoT2023 dataset focusing on benign traffic and 12 DDoS subtypes, using a reproducible pipeline with stratified splitting, cross-validation (k = 5), and early stopping. The proposed model consistently improves multi-class performance (Accuracy: 0.9983) over an optimized MLP baseline (Accuracy: 0.9641), while maintaining a compact size suitable for edge deployment (&amp;amp;asymp;123 k parameters; ~0.47 MB). Within CICIoT2023 and the evaluated split/training protocol, the proposed ChebyKANRes configuration shows improved imbalance-robust multiclass detection while maintaining a compact model size and comparable batch inference time.</p>
	]]></content:encoded>

	<dc:title>Gated Residual Chebyshev KAN for Lightweight IoT DDoS Detection</dc:title>
			<dc:creator>Fray L. Becerra-Suarez</dc:creator>
			<dc:creator>Edwin Valencia-Castillo</dc:creator>
			<dc:creator>Ana G. Borrero-Ramírez</dc:creator>
			<dc:creator>Manuel G. Forero</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020047</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-04</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-04</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>47</prism:startingPage>
		<prism:doi>10.3390/jcp6020047</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/47</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/46">

	<title>JCP, Vol. 6, Pages 46: A Conceptual Framework for a Morphological Scenario Library and Playbook Mapping in Cognitive Warfare Defense</title>
	<link>https://www.mdpi.com/2624-800X/6/2/46</link>
	<description>Cognitive warfare is a hybrid threat that combines information manipulation with psychological influence, often amplified by digital platforms and synthetic media. Conventional cybersecurity tooling is optimized for technical intrusion and offers limited support for anticipating and responding to influence operations. This paper presents a conceptual framework that structures cognitive warfare threats with General Morphological Analysis (GMA) and links plausible configurations to indicator profiles and response playbooks. We first conduct a PRISMA-informed literature review (2018&amp;amp;ndash;2025) to derive a five-dimensional taxonomy (actor, tactic, medium, target, objective). We then apply cross-consistency assessment to remove implausible state-pair combinations and obtain a reduced library of internally consistent scenarios. To support analyst-guided triage, we outline an AI-enabled workflow that maps observable signals to taxonomy states, matches events to scenarios, and prioritizes responses via an auditable, policy-set risk score. Finally, we illustrate the framework on three publicly documented cases and show how each case maps to scenario vectors, indicators, and playbooks. No end-to-end system implementation or performance metrics are reported; the contribution is the structured scenario library and the traceable mapping from observations to response guidance.</description>
	<pubDate>2026-03-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 46: A Conceptual Framework for a Morphological Scenario Library and Playbook Mapping in Cognitive Warfare Defense</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/46">doi: 10.3390/jcp6020046</a></p>
	<p>Authors:
		Dojin Ryu
		</p>
	<p>Cognitive warfare is a hybrid threat that combines information manipulation with psychological influence, often amplified by digital platforms and synthetic media. Conventional cybersecurity tooling is optimized for technical intrusion and offers limited support for anticipating and responding to influence operations. This paper presents a conceptual framework that structures cognitive warfare threats with General Morphological Analysis (GMA) and links plausible configurations to indicator profiles and response playbooks. We first conduct a PRISMA-informed literature review (2018&amp;amp;ndash;2025) to derive a five-dimensional taxonomy (actor, tactic, medium, target, objective). We then apply cross-consistency assessment to remove implausible state-pair combinations and obtain a reduced library of internally consistent scenarios. To support analyst-guided triage, we outline an AI-enabled workflow that maps observable signals to taxonomy states, matches events to scenarios, and prioritizes responses via an auditable, policy-set risk score. Finally, we illustrate the framework on three publicly documented cases and show how each case maps to scenario vectors, indicators, and playbooks. No end-to-end system implementation or performance metrics are reported; the contribution is the structured scenario library and the traceable mapping from observations to response guidance.</p>
	]]></content:encoded>

	<dc:title>A Conceptual Framework for a Morphological Scenario Library and Playbook Mapping in Cognitive Warfare Defense</dc:title>
			<dc:creator>Dojin Ryu</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020046</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>46</prism:startingPage>
		<prism:doi>10.3390/jcp6020046</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/46</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/45">

	<title>JCP, Vol. 6, Pages 45: Generation of Distances Between Feature Vectors Derived from a Siamese Neural Network for Continuous Authentication</title>
	<link>https://www.mdpi.com/2624-800X/6/2/45</link>
	<description>Continuous authentication is a promising method for protecting computer systems in the event of compromise of primary authentication factors, such as passwords or tokens. Systems employing continuous authentication that rely on biometrics may not be restricted to a single biometric characteristic; rather, they can simultaneously utilize multiple characteristics and subsequently arrive at a conclusive decision based on their collective analysis outcomes. One of the significant challenges researchers encounter when investigating effective fusion in decision-making is the lack of data. At present, data generation primarily involves the creation of feature vectors or attack simulation. This paper introduces a method for directly generating distances derived from a Siamese neural network, utilizing the probability density function of an existing distribution. Through statistical analysis, we successfully generated 5000 samples that correspond to the initial distribution, which were then employed to discover the threshold values at which FAR and FRR were less than 1%. The methods developed can be further applied to identify the most efficient strategies for integrating the results of continuous authentication in systems that incorporate multiple biometric characteristics.</description>
	<pubDate>2026-03-03</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 45: Generation of Distances Between Feature Vectors Derived from a Siamese Neural Network for Continuous Authentication</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/45">doi: 10.3390/jcp6020045</a></p>
	<p>Authors:
		Sergey Davydenko
		Pavel Laptev
		Evgeny Kostyuchenko
		</p>
	<p>Continuous authentication is a promising method for protecting computer systems in the event of compromise of primary authentication factors, such as passwords or tokens. Systems employing continuous authentication that rely on biometrics may not be restricted to a single biometric characteristic; rather, they can simultaneously utilize multiple characteristics and subsequently arrive at a conclusive decision based on their collective analysis outcomes. One of the significant challenges researchers encounter when investigating effective fusion in decision-making is the lack of data. At present, data generation primarily involves the creation of feature vectors or attack simulation. This paper introduces a method for directly generating distances derived from a Siamese neural network, utilizing the probability density function of an existing distribution. Through statistical analysis, we successfully generated 5000 samples that correspond to the initial distribution, which were then employed to discover the threshold values at which FAR and FRR were less than 1%. The methods developed can be further applied to identify the most efficient strategies for integrating the results of continuous authentication in systems that incorporate multiple biometric characteristics.</p>
	]]></content:encoded>

	<dc:title>Generation of Distances Between Feature Vectors Derived from a Siamese Neural Network for Continuous Authentication</dc:title>
			<dc:creator>Sergey Davydenko</dc:creator>
			<dc:creator>Pavel Laptev</dc:creator>
			<dc:creator>Evgeny Kostyuchenko</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020045</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-03</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-03</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>45</prism:startingPage>
		<prism:doi>10.3390/jcp6020045</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/45</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/44">

	<title>JCP, Vol. 6, Pages 44: A Lightweight Post-Quantum Anonymous Attestation Framework for Traceable and Comprehensive Privacy Preservation in VANETs</title>
	<link>https://www.mdpi.com/2624-800X/6/2/44</link>
	<description>Vehicular ad hoc networks (VANETs) require authentication systems that balance privacy, scalability, and post-quantum security. While lattice-based V-LDAA offers quantum resistance, it faces challenges in signature size, traceability, and integration. We propose post-quantum traceable direct anonymous attestation (PQ-TDAA), combining National Institute of Standards and Technology (NIST)-standard Dilithium2 and Falcon-512 signatures with adapted Beullens-style blind signatures and Fiat&amp;amp;ndash;Shamir simplified Schnorr proofs, reducing proof size by 69.2% (8 kB vs. V-LDAA&amp;amp;rsquo;s 26 kB) and supporting European Telecommunications Standards Institute Technical Specification (ETSI TS) 102 941-compliant traceability through Road Side Unit (RSU)-assisted verification. Evaluated using SageMath, Python 3.11, and NS-3, PQ-TDAA-Falcon-512 achieves 8.1 ms and 49.7 ms end-to-end delays at 10 and 20 vehicles, respectively, with 64.7 Mbps goodput on congested 802.11p channels, showing promise for densities of &amp;amp;le;50 vehicles and advantages over Dilithium2. Real-world validation on ARM Cortex-A76 (Raspberry Pi 5, emulating automotive OBUs) yields sub-0.5 ms V2V cycles within 100 ms beacon intervals, supporting practical embedded deployment. Future work will extend PQ-TDAA to emerging 5G and NR-V2X settings, integrate more realistic mobility and channel models through coupled NS-3 and SUMO co-simulation, and investigate side-channel resistance for enhanced scalability and robustness in real deployments.</description>
	<pubDate>2026-03-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 44: A Lightweight Post-Quantum Anonymous Attestation Framework for Traceable and Comprehensive Privacy Preservation in VANETs</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/44">doi: 10.3390/jcp6020044</a></p>
	<p>Authors:
		Esti Rahmawati Agustina
		Kalamullah Ramli
		Ruki Harwahyu
		Teddy Surya Gunawan
		Muhammad Salman
		Andriani Adi Lestari
		Arif Rahman Hakim
		</p>
	<p>Vehicular ad hoc networks (VANETs) require authentication systems that balance privacy, scalability, and post-quantum security. While lattice-based V-LDAA offers quantum resistance, it faces challenges in signature size, traceability, and integration. We propose post-quantum traceable direct anonymous attestation (PQ-TDAA), combining National Institute of Standards and Technology (NIST)-standard Dilithium2 and Falcon-512 signatures with adapted Beullens-style blind signatures and Fiat&amp;amp;ndash;Shamir simplified Schnorr proofs, reducing proof size by 69.2% (8 kB vs. V-LDAA&amp;amp;rsquo;s 26 kB) and supporting European Telecommunications Standards Institute Technical Specification (ETSI TS) 102 941-compliant traceability through Road Side Unit (RSU)-assisted verification. Evaluated using SageMath, Python 3.11, and NS-3, PQ-TDAA-Falcon-512 achieves 8.1 ms and 49.7 ms end-to-end delays at 10 and 20 vehicles, respectively, with 64.7 Mbps goodput on congested 802.11p channels, showing promise for densities of &amp;amp;le;50 vehicles and advantages over Dilithium2. Real-world validation on ARM Cortex-A76 (Raspberry Pi 5, emulating automotive OBUs) yields sub-0.5 ms V2V cycles within 100 ms beacon intervals, supporting practical embedded deployment. Future work will extend PQ-TDAA to emerging 5G and NR-V2X settings, integrate more realistic mobility and channel models through coupled NS-3 and SUMO co-simulation, and investigate side-channel resistance for enhanced scalability and robustness in real deployments.</p>
	]]></content:encoded>

	<dc:title>A Lightweight Post-Quantum Anonymous Attestation Framework for Traceable and Comprehensive Privacy Preservation in VANETs</dc:title>
			<dc:creator>Esti Rahmawati Agustina</dc:creator>
			<dc:creator>Kalamullah Ramli</dc:creator>
			<dc:creator>Ruki Harwahyu</dc:creator>
			<dc:creator>Teddy Surya Gunawan</dc:creator>
			<dc:creator>Muhammad Salman</dc:creator>
			<dc:creator>Andriani Adi Lestari</dc:creator>
			<dc:creator>Arif Rahman Hakim</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020044</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>44</prism:startingPage>
		<prism:doi>10.3390/jcp6020044</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/44</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/42">

	<title>JCP, Vol. 6, Pages 42: Two-Factor Cancelable Biometric Key Binding via Euclidean Challenge&amp;ndash;Response Pair Mechanism</title>
	<link>https://www.mdpi.com/2624-800X/6/2/42</link>
	<description>This work proposes a lightweight biometric key-binding scheme that adapts a PUF-style challenge&amp;amp;ndash;response mechanism to face geometry: a two-factor password and session nonce generate random challenge points, Gray-coded Euclidean distances to facial landmarks form responses, and a random key is bound by discarding selected positions so only a reduced subset, the nonce, and a key hash are stored. At authentication, a fresh response set is compared to the subset with a Hamming-distance tolerance, and bounded local search corrects residual errors; each successful session rotates the nonce and refreshes the ephemeral key. We frame this as a conceptual exploration of an interpretable, on-device, controlled-capture design niche&amp;amp;mdash;a per-session nonce-driven cancelable biometric key-binding mechanism&amp;amp;mdash;and we quantify the resulting security&amp;amp;ndash;usability trade-offs. Empirically, the scheme works under stable capture conditions with carefully tuned thresholds, and it is naturally suited to tightly controlled deployments (e.g., access kiosks) where it can also incorporate user-driven micro-gestures as an extra behavioral factor. While the construction is fragile under broader variability and leans on the second factor for security, it offers an alternative to existing mechanisms and a clear niche, and we present it as a conceptual exploration showing how CRP mechanisms can inform cancelable biometrics with per-session revocability.</description>
	<pubDate>2026-03-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 42: Two-Factor Cancelable Biometric Key Binding via Euclidean Challenge&amp;ndash;Response Pair Mechanism</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/42">doi: 10.3390/jcp6020042</a></p>
	<p>Authors:
		Michael Logan Garrett
		Mahafujul Alam
		Michael Partridge
		Julie Heynssens
		</p>
	<p>This work proposes a lightweight biometric key-binding scheme that adapts a PUF-style challenge&amp;amp;ndash;response mechanism to face geometry: a two-factor password and session nonce generate random challenge points, Gray-coded Euclidean distances to facial landmarks form responses, and a random key is bound by discarding selected positions so only a reduced subset, the nonce, and a key hash are stored. At authentication, a fresh response set is compared to the subset with a Hamming-distance tolerance, and bounded local search corrects residual errors; each successful session rotates the nonce and refreshes the ephemeral key. We frame this as a conceptual exploration of an interpretable, on-device, controlled-capture design niche&amp;amp;mdash;a per-session nonce-driven cancelable biometric key-binding mechanism&amp;amp;mdash;and we quantify the resulting security&amp;amp;ndash;usability trade-offs. Empirically, the scheme works under stable capture conditions with carefully tuned thresholds, and it is naturally suited to tightly controlled deployments (e.g., access kiosks) where it can also incorporate user-driven micro-gestures as an extra behavioral factor. While the construction is fragile under broader variability and leans on the second factor for security, it offers an alternative to existing mechanisms and a clear niche, and we present it as a conceptual exploration showing how CRP mechanisms can inform cancelable biometrics with per-session revocability.</p>
	]]></content:encoded>

	<dc:title>Two-Factor Cancelable Biometric Key Binding via Euclidean Challenge&amp;amp;ndash;Response Pair Mechanism</dc:title>
			<dc:creator>Michael Logan Garrett</dc:creator>
			<dc:creator>Mahafujul Alam</dc:creator>
			<dc:creator>Michael Partridge</dc:creator>
			<dc:creator>Julie Heynssens</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020042</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>42</prism:startingPage>
		<prism:doi>10.3390/jcp6020042</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/42</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/43">

	<title>JCP, Vol. 6, Pages 43: XAI-Compliance-by-Design: A Modular Framework for GDPR- and AI Act-Aligned Decision Transparency in High-Risk AI Systems</title>
	<link>https://www.mdpi.com/2624-800X/6/2/43</link>
	<description>High-risk Artificial Intelligence (AI) systems deployed in cybersecurity and privacy-critical contexts must satisfy not only demanding performance targets but also stringent obligations for transparency, accountability, and human oversight under the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act). Existing approaches often treat these concerns in isolation as follows: Explainable Artificial Intelligence (XAI) methods are added ad hoc to machine learning pipelines, while governance and regulatory frameworks remain largely conceptual and weakly connected to the concrete artefacts produced in practice. This article proposes XAI-Compliance-by-Design, a modular framework that integrates XAI techniques, compliance-by-design principles and trustworthy Machine Learning Operations (MLOps) practices into a unified architecture for high-risk AI systems in cybersecurity and privacy domains. The framework follows a dual-flow design that couples an upstream technical pipeline (data, model, explanation, and monitoring) with a downstream governance pipeline (policy, oversight, audit, and decision-making), orchestrated by a Compliance-by-Design Engine and a technical&amp;amp;ndash;regulatory correspondence matrix aligned with the GDPR, the AI Act, and ISO/IEC 42001. The framework is instantiated and evaluated through an end-to-end, Python-based proof of concept using a synthetic, intrusion detection system (IDS)-inspired anomaly detection scenario with a Random Forest (RF) classifier, Shapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME), drift indicators, and tamper-evident evidence bundles and decision dossiers. The results show that, even in a modest, toy setting, the framework systematically produces verifiable artefacts that support auditability and accountability across the model lifecycle. By linking explanation reports, drift statistics and compliance logs to concrete regulatory provisions, the approach illustrates how organisations operating high-risk AI for cybersecurity and privacy can move from model-centric optimisation to evidence-centric governance. The article discusses how the proposed framework can be generalised to real-world high-risk AI applications, contributing to the operationalisation of European digital sovereignty in AI governance. This article does not introduce a new intrusion detection algorithm; instead, it proposes an evidence-centric governance pipeline that captures decision provenance and compliance artefacts so that decisions can be audited and justified against regulatory obligations.</description>
	<pubDate>2026-03-02</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 43: XAI-Compliance-by-Design: A Modular Framework for GDPR- and AI Act-Aligned Decision Transparency in High-Risk AI Systems</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/43">doi: 10.3390/jcp6020043</a></p>
	<p>Authors:
		Antonio Goncalves
		Anacleto Correia
		</p>
	<p>High-risk Artificial Intelligence (AI) systems deployed in cybersecurity and privacy-critical contexts must satisfy not only demanding performance targets but also stringent obligations for transparency, accountability, and human oversight under the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (AI Act). Existing approaches often treat these concerns in isolation as follows: Explainable Artificial Intelligence (XAI) methods are added ad hoc to machine learning pipelines, while governance and regulatory frameworks remain largely conceptual and weakly connected to the concrete artefacts produced in practice. This article proposes XAI-Compliance-by-Design, a modular framework that integrates XAI techniques, compliance-by-design principles and trustworthy Machine Learning Operations (MLOps) practices into a unified architecture for high-risk AI systems in cybersecurity and privacy domains. The framework follows a dual-flow design that couples an upstream technical pipeline (data, model, explanation, and monitoring) with a downstream governance pipeline (policy, oversight, audit, and decision-making), orchestrated by a Compliance-by-Design Engine and a technical&amp;amp;ndash;regulatory correspondence matrix aligned with the GDPR, the AI Act, and ISO/IEC 42001. The framework is instantiated and evaluated through an end-to-end, Python-based proof of concept using a synthetic, intrusion detection system (IDS)-inspired anomaly detection scenario with a Random Forest (RF) classifier, Shapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME), drift indicators, and tamper-evident evidence bundles and decision dossiers. The results show that, even in a modest, toy setting, the framework systematically produces verifiable artefacts that support auditability and accountability across the model lifecycle. By linking explanation reports, drift statistics and compliance logs to concrete regulatory provisions, the approach illustrates how organisations operating high-risk AI for cybersecurity and privacy can move from model-centric optimisation to evidence-centric governance. The article discusses how the proposed framework can be generalised to real-world high-risk AI applications, contributing to the operationalisation of European digital sovereignty in AI governance. This article does not introduce a new intrusion detection algorithm; instead, it proposes an evidence-centric governance pipeline that captures decision provenance and compliance artefacts so that decisions can be audited and justified against regulatory obligations.</p>
	]]></content:encoded>

	<dc:title>XAI-Compliance-by-Design: A Modular Framework for GDPR- and AI Act-Aligned Decision Transparency in High-Risk AI Systems</dc:title>
			<dc:creator>Antonio Goncalves</dc:creator>
			<dc:creator>Anacleto Correia</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020043</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-03-02</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-03-02</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>43</prism:startingPage>
		<prism:doi>10.3390/jcp6020043</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/43</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/41">

	<title>JCP, Vol. 6, Pages 41: Enhancing Federated Data Trading via Trustworthy Identity and Access Management Framework</title>
	<link>https://www.mdpi.com/2624-800X/6/2/41</link>
	<description>Trustworthy Identity and Access Management (IAM) is a foundational requirement for federated data trading platforms, yet existing solutions often rely on centralized Identity Providers (IdPs), lack cross-border interoperability, and offer limited support for user-friendly authorization management. These limitations hinder secure onboarding, fine-grained access control, and regulatory compliance, especially within European Union (EU) data spaces governed by the Electronic Identification, Authentication, and Trust Services (eIDAS) 2.0 framework. This work presents a comprehensive IAM framework designed for federated data trading environments, developed within the EU-funded PISTIS project. The framework is based on Keycloak IAM and offers three major capabilities: (i) a novel IAM architecture tailored to distributed data trading scenarios; (ii) full integration of eIDAS-compliant cross-border authentication and initial support for European Digital Identity (EUDI) Wallets; and (iii) a standalone, web-based Access Policy Editor (APE) that abstracts Keycloak&amp;amp;rsquo;s policy engine and enables non-technical users to define fine-grained, owner-driven access rules. The approach is evaluated across real-world mobility, energy, and automotive industry pilots, demonstrating its effectiveness in enhancing trust, interoperability, and usability within regulated data-sharing ecosystems.</description>
	<pubDate>2026-02-28</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 41: Enhancing Federated Data Trading via Trustworthy Identity and Access Management Framework</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/41">doi: 10.3390/jcp6020041</a></p>
	<p>Authors:
		Kyriakos Stefanidis
		Vasilis Bekos
		Dimitris Karadimas
		</p>
	<p>Trustworthy Identity and Access Management (IAM) is a foundational requirement for federated data trading platforms, yet existing solutions often rely on centralized Identity Providers (IdPs), lack cross-border interoperability, and offer limited support for user-friendly authorization management. These limitations hinder secure onboarding, fine-grained access control, and regulatory compliance, especially within European Union (EU) data spaces governed by the Electronic Identification, Authentication, and Trust Services (eIDAS) 2.0 framework. This work presents a comprehensive IAM framework designed for federated data trading environments, developed within the EU-funded PISTIS project. The framework is based on Keycloak IAM and offers three major capabilities: (i) a novel IAM architecture tailored to distributed data trading scenarios; (ii) full integration of eIDAS-compliant cross-border authentication and initial support for European Digital Identity (EUDI) Wallets; and (iii) a standalone, web-based Access Policy Editor (APE) that abstracts Keycloak&amp;amp;rsquo;s policy engine and enables non-technical users to define fine-grained, owner-driven access rules. The approach is evaluated across real-world mobility, energy, and automotive industry pilots, demonstrating its effectiveness in enhancing trust, interoperability, and usability within regulated data-sharing ecosystems.</p>
	]]></content:encoded>

	<dc:title>Enhancing Federated Data Trading via Trustworthy Identity and Access Management Framework</dc:title>
			<dc:creator>Kyriakos Stefanidis</dc:creator>
			<dc:creator>Vasilis Bekos</dc:creator>
			<dc:creator>Dimitris Karadimas</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020041</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-28</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-28</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>41</prism:startingPage>
		<prism:doi>10.3390/jcp6020041</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/41</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/2/40">

	<title>JCP, Vol. 6, Pages 40: Strengthening Workforce Readiness: Evidence on Work-Based Learning in U.S. Higher Education Cybersecurity Programs</title>
	<link>https://www.mdpi.com/2624-800X/6/2/40</link>
	<description>This study provides a foundational review of work-based learning (WBL) opportunities offered by colleges and universities to students in higher education cybersecurity (CS) programs in the United States, with the goal of mapping the WBL practices across institutional and program contexts. Integrating WBL into CS curricula is widely recognized as an effective way to strengthen essential skills and address employer concerns about the gap between academic preparation and labor market needs. We first outline the characteristics of institutions and CS programs offering WBL. Next, we examine the range of WBL experiences designed to enhance students&amp;amp;rsquo; professional competencies. Finally, we explore characteristics of the partnerships between higher education and industry that support these initiatives. Using a status survey approach, we collected responses from 92 higher education institutions offering CS programs. We analyzed the data using descriptive statistics and linear regression models to explore patterns of association between the type and number of WBL opportunities available to students, institutional characteristics related to the total number of WBL offerings, and program features associated with WBL intensity across Awareness, Exploration, and Direct Experience levels of intensity. Findings reveal a diverse array of WBL opportunities, with notable growth across credential levels. Notably, certificates and associate degrees place particular emphasis on WBL. Both institutional characteristics and program features explain, albeit partially, the number of WBL opportunities implemented and the intensity levels of those WBL. However, results also indicate an ambivalent connection to employers, despite their critical role in providing hands-on, problem-solving experiences. Based on these insights, we recommend expanding WBL beyond internships, strengthening institutional&amp;amp;ndash;industry partnerships, and fostering employer engagement through structured WBL collaboration models. These strategies aim to improve workforce readiness and create a more inclusive, scalable system of experiential learning in cybersecurity education.</description>
	<pubDate>2026-02-25</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 40: Strengthening Workforce Readiness: Evidence on Work-Based Learning in U.S. Higher Education Cybersecurity Programs</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/2/40">doi: 10.3390/jcp6020040</a></p>
	<p>Authors:
		Oscar A. Aliaga
		Noémi Nagy
		Bonnie Gómez Torres
		Ajara Mahmoud
		Courtney N. Callahan
		</p>
	<p>This study provides a foundational review of work-based learning (WBL) opportunities offered by colleges and universities to students in higher education cybersecurity (CS) programs in the United States, with the goal of mapping the WBL practices across institutional and program contexts. Integrating WBL into CS curricula is widely recognized as an effective way to strengthen essential skills and address employer concerns about the gap between academic preparation and labor market needs. We first outline the characteristics of institutions and CS programs offering WBL. Next, we examine the range of WBL experiences designed to enhance students&amp;amp;rsquo; professional competencies. Finally, we explore characteristics of the partnerships between higher education and industry that support these initiatives. Using a status survey approach, we collected responses from 92 higher education institutions offering CS programs. We analyzed the data using descriptive statistics and linear regression models to explore patterns of association between the type and number of WBL opportunities available to students, institutional characteristics related to the total number of WBL offerings, and program features associated with WBL intensity across Awareness, Exploration, and Direct Experience levels of intensity. Findings reveal a diverse array of WBL opportunities, with notable growth across credential levels. Notably, certificates and associate degrees place particular emphasis on WBL. Both institutional characteristics and program features explain, albeit partially, the number of WBL opportunities implemented and the intensity levels of those WBL. However, results also indicate an ambivalent connection to employers, despite their critical role in providing hands-on, problem-solving experiences. Based on these insights, we recommend expanding WBL beyond internships, strengthening institutional&amp;amp;ndash;industry partnerships, and fostering employer engagement through structured WBL collaboration models. These strategies aim to improve workforce readiness and create a more inclusive, scalable system of experiential learning in cybersecurity education.</p>
	]]></content:encoded>

	<dc:title>Strengthening Workforce Readiness: Evidence on Work-Based Learning in U.S. Higher Education Cybersecurity Programs</dc:title>
			<dc:creator>Oscar A. Aliaga</dc:creator>
			<dc:creator>Noémi Nagy</dc:creator>
			<dc:creator>Bonnie Gómez Torres</dc:creator>
			<dc:creator>Ajara Mahmoud</dc:creator>
			<dc:creator>Courtney N. Callahan</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6020040</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-25</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-25</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>2</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>40</prism:startingPage>
		<prism:doi>10.3390/jcp6020040</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/2/40</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/1/39">

	<title>JCP, Vol. 6, Pages 39: Comparing the Use of EMBA for IoT Firmware Security Analysis on Cloud Services and Standalone Servers</title>
	<link>https://www.mdpi.com/2624-800X/6/1/39</link>
	<description>This paper presents an experimental comparison of the EMBA firmware security analysis framework deployed in cloud-based and standalone environments. Unlike prior studies that primarily focus on EMBA’s analytical capabilities, this work examines how deployment choices influence performance and execution time during IoT firmware analysis. Using identical EMBA configurations and analysis modules, firmware images of varying sizes were analyzed on a standalone personal computer and a Microsoft Azure cloud-based virtual machine. Execution time, detected vulnerabilities, and resource utilization were systematically recorded to evaluate the impact of the deployment environment. The results indicate that scan duration is affected by both firmware size and execution context. For example, using EMBA v1.5.0, a 25.5 MB firmware image required approximately 14 h on a standalone system and over 25 h in the cloud. In contrast, a 30.2 MB image was completed in approximately 18 h locally and 17 h in the cloud. Despite these differences in execution time, the type and number of identified vulnerabilities were largely consistent across both environments, suggesting comparable analytical coverage. Overall, this deployment-focused evaluation provides empirical insight into performance-related trade-offs relevant to practitioners selecting local or cloud-based environments for firmware security analysis.</description>
	<pubDate>2026-02-22</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 39: Comparing the Use of EMBA for IoT Firmware Security Analysis on Cloud Services and Standalone Servers</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/1/39">doi: 10.3390/jcp6010039</a></p>
	<p>Authors:
		Kenan Nuray
		Oren Upton
		Nicole Beebe
		</p>
	<p>This paper presents an experimental comparison of the EMBA firmware security analysis framework deployed in cloud-based and standalone environments. Unlike prior studies that primarily focus on EMBA’s analytical capabilities, this work examines how deployment choices influence performance and execution time during IoT firmware analysis. Using identical EMBA configurations and analysis modules, firmware images of varying sizes were analyzed on a standalone personal computer and a Microsoft Azure cloud-based virtual machine. Execution time, detected vulnerabilities, and resource utilization were systematically recorded to evaluate the impact of the deployment environment. The results indicate that scan duration is affected by both firmware size and execution context. For example, using EMBA v1.5.0, a 25.5 MB firmware image required approximately 14 h on a standalone system and over 25 h in the cloud. In contrast, a 30.2 MB image was completed in approximately 18 h locally and 17 h in the cloud. Despite these differences in execution time, the type and number of identified vulnerabilities were largely consistent across both environments, suggesting comparable analytical coverage. Overall, this deployment-focused evaluation provides empirical insight into performance-related trade-offs relevant to practitioners selecting local or cloud-based environments for firmware security analysis.</p>
	]]></content:encoded>

	<dc:title>Comparing the Use of EMBA for IoT Firmware Security Analysis on Cloud Services and Standalone Servers</dc:title>
			<dc:creator>Kenan Nuray</dc:creator>
			<dc:creator>Oren Upton</dc:creator>
			<dc:creator>Nicole Beebe</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6010039</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-22</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-22</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>1</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>39</prism:startingPage>
		<prism:doi>10.3390/jcp6010039</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/1/39</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/1/38">

	<title>JCP, Vol. 6, Pages 38: Privacy Risks of Cybersquatting Attacks</title>
	<link>https://www.mdpi.com/2624-800X/6/1/38</link>
	<description>Cybersquatting is a collection of methods commonly used by malicious actors to mislead or trick internet users into accessing fraudulent or malicious content. Much of the current research has concentrated on the specific techniques used by attackers in this domain, such as typosquatting, combosquatting, and sound squatting. Some research has explored the financial and time impacts of cybersquatting; however, an understanding of user privacy impacts is limited. Prior research into privacy implications has primarily relied on passive techniques such as analyzing DNS records, HTML content, and domain registrations. These passive approaches limit the ability to interact with these domains and track the downstream impact of sharing personally identifiable information (PII). This research develops an active open-source intelligence (OSINT) collection system capable of rapidly collecting and analyzing squatting domains through both passive and active techniques, with a particular emphasis on identifying those that solicit user information. Synthetic identities are then registered with these domains, and their associated communications are collected and analyzed to identify privacy-related risks and determine whether shared PII propagates.</description>
	<pubDate>2026-02-19</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 38: Privacy Risks of Cybersquatting Attacks</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/1/38">doi: 10.3390/jcp6010038</a></p>
	<p>Authors:
		Jack Kolenbrander
		Elliott Rheault
		Alan J. Michaels
		</p>
	<p>Cybersquatting is a collection of methods commonly used by malicious actors to mislead or trick internet users into accessing fraudulent or malicious content. Much of the current research has concentrated on the specific techniques used by attackers in this domain, such as typosquatting, combosquatting, and sound squatting. Some research has explored the financial and time impacts of cybersquatting; however, an understanding of user privacy impacts is limited. Prior research into privacy implications has primarily relied on passive techniques such as analyzing DNS records, HTML content, and domain registrations. These passive approaches limit the ability to interact with these domains and track the downstream impact of sharing personally identifiable information (PII). This research develops an active open-source intelligence (OSINT) collection system capable of rapidly collecting and analyzing squatting domains through both passive and active techniques, with a particular emphasis on identifying those that solicit user information. Synthetic identities are then registered with these domains, and their associated communications are collected and analyzed to identify privacy-related risks and determine whether shared PII propagates.</p>
	]]></content:encoded>

	<dc:title>Privacy Risks of Cybersquatting Attacks</dc:title>
			<dc:creator>Jack Kolenbrander</dc:creator>
			<dc:creator>Elliott Rheault</dc:creator>
			<dc:creator>Alan J. Michaels</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6010038</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-19</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-19</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>1</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>38</prism:startingPage>
		<prism:doi>10.3390/jcp6010038</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/1/38</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/1/37">

	<title>JCP, Vol. 6, Pages 37: Investigating Security Vulnerabilities in 5G Control and User Planes: Attack Patterns and Protection Strategies</title>
	<link>https://www.mdpi.com/2624-800X/6/1/37</link>
	<description>The rollout of 5G Standalone networks introduces unprecedented flexibility and performance through service-based architecture (SBA), virtualization, open APIs, and network slicing, while simultaneously expanding the attack surface across control, user, and cross-plane interfaces. This article provides a systematic, vulnerability-prioritized, selective characterization of the current state of weaknesses specific to the 5G control and user planes and transparent risk scoring. Using a PRISMA-aligned methodology, vulnerabilities are mapped explicitly to 3GPP network functions and interfaces (e.g., AMF, SMF, UPF; N2, N4, SBA APIs) and categorized by operational evidence level ranging from theoretical analysis to documented live-network exploitation. A normalized criticality scoring model integrates likelihood, impact, exploitability, and CVSS-derived severity. The analysis shows that control-plane signaling floods, PFCP misuse, and container escapes stand out as the most pressing risks. It also exposes how little attention has been given to securing the user plane and strengthening slice isolation. The paper wraps up with clear, evidence-based hardening priorities for each plane, along with research areas that matter for today&amp;amp;rsquo;s 5G networks and the shift toward 6G.</description>
	<pubDate>2026-02-17</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 37: Investigating Security Vulnerabilities in 5G Control and User Planes: Attack Patterns and Protection Strategies</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/1/37">doi: 10.3390/jcp6010037</a></p>
	<p>Authors:
		Samuel T. Aiello
		Bhaskar P. Rimal
		Frederick T. Sheldon
		Yong Wang
		</p>
	<p>The rollout of 5G Standalone networks introduces unprecedented flexibility and performance through service-based architecture (SBA), virtualization, open APIs, and network slicing, while simultaneously expanding the attack surface across control, user, and cross-plane interfaces. This article provides a systematic, vulnerability-prioritized, selective characterization of the current state of weaknesses specific to the 5G control and user planes and transparent risk scoring. Using a PRISMA-aligned methodology, vulnerabilities are mapped explicitly to 3GPP network functions and interfaces (e.g., AMF, SMF, UPF; N2, N4, SBA APIs) and categorized by operational evidence level ranging from theoretical analysis to documented live-network exploitation. A normalized criticality scoring model integrates likelihood, impact, exploitability, and CVSS-derived severity. The analysis shows that control-plane signaling floods, PFCP misuse, and container escapes stand out as the most pressing risks. It also exposes how little attention has been given to securing the user plane and strengthening slice isolation. The paper wraps up with clear, evidence-based hardening priorities for each plane, along with research areas that matter for today&amp;amp;rsquo;s 5G networks and the shift toward 6G.</p>
	]]></content:encoded>

	<dc:title>Investigating Security Vulnerabilities in 5G Control and User Planes: Attack Patterns and Protection Strategies</dc:title>
			<dc:creator>Samuel T. Aiello</dc:creator>
			<dc:creator>Bhaskar P. Rimal</dc:creator>
			<dc:creator>Frederick T. Sheldon</dc:creator>
			<dc:creator>Yong Wang</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6010037</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-17</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-17</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>1</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>37</prism:startingPage>
		<prism:doi>10.3390/jcp6010037</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/1/37</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/1/36">

	<title>JCP, Vol. 6, Pages 36: IoT Vulnerability Severity Prediction Using Lightweight Transformer Models</title>
	<link>https://www.mdpi.com/2624-800X/6/1/36</link>
	<description>Vulnerability severity assessment plays a critical role in cybersecurity risk management by quantifying risk based on vulnerability disclosure reports. However, interpreting these reports and assigning reliable risk levels remains challenging in Internet of Things (IoT) environments. This paper proposes an IoT vulnerability severity prediction framework aligned with the Common Vulnerability Scoring System (CVSS). The framework is based on a lightweight transformer architecture. It uses a distilled version of Bidirectional Encoder Representations from Transformers (BERT). The model is fine-tuned using transfer learning to capture contextual semantic information from vulnerability descriptions. The lightweight design preserves computational efficiency. Experimental evaluation on an IoT vulnerability dataset shows strong and consistent performance across all severity classes. The proposed model achieves double-digit improvements across key evaluation metrics. In most cases, the improvement exceeds 20% compared with traditional machine learning and baseline deep learning approaches. These results show that lightweight transformer models are well suited for IoT security. They provide a practical and effective solution for automated vulnerability severity classification in resource- and data-constrained environments.</description>
	<pubDate>2026-02-14</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 36: IoT Vulnerability Severity Prediction Using Lightweight Transformer Models</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/1/36">doi: 10.3390/jcp6010036</a></p>
	<p>Authors:
		Samira A. Baho
		Jemal Abawajy
		</p>
	<p>Vulnerability severity assessment plays a critical role in cybersecurity risk management by quantifying risk based on vulnerability disclosure reports. However, interpreting these reports and assigning reliable risk levels remains challenging in Internet of Things (IoT) environments. This paper proposes an IoT vulnerability severity prediction framework aligned with the Common Vulnerability Scoring System (CVSS). The framework is based on a lightweight transformer architecture. It uses a distilled version of Bidirectional Encoder Representations from Transformers (BERT). The model is fine-tuned using transfer learning to capture contextual semantic information from vulnerability descriptions. The lightweight design preserves computational efficiency. Experimental evaluation on an IoT vulnerability dataset shows strong and consistent performance across all severity classes. The proposed model achieves double-digit improvements across key evaluation metrics. In most cases, the improvement exceeds 20% compared with traditional machine learning and baseline deep learning approaches. These results show that lightweight transformer models are well suited for IoT security. They provide a practical and effective solution for automated vulnerability severity classification in resource- and data-constrained environments.</p>
	]]></content:encoded>

	<dc:title>IoT Vulnerability Severity Prediction Using Lightweight Transformer Models</dc:title>
			<dc:creator>Samira A. Baho</dc:creator>
			<dc:creator>Jemal Abawajy</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6010036</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-14</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-14</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>1</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>36</prism:startingPage>
		<prism:doi>10.3390/jcp6010036</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/1/36</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
        <item rdf:about="https://www.mdpi.com/2624-800X/6/1/35">

	<title>JCP, Vol. 6, Pages 35: Security Challenges in 5G Network Slicing: A Risk-Based Analysis and Conceptual Framework</title>
	<link>https://www.mdpi.com/2624-800X/6/1/35</link>
	<description>Network slicing is a core enabler of multi-tenant 5th Generation (5G) architectures, allowing heterogeneous services to coexist over shared infrastructure. However, ensuring effective isolation between slices remains a critical security challenge, as failures may enable cross-slice interference, data leakage, or cascading service disruption. This article analyses security vulnerabilities affecting 5G network slicing from a risk-oriented perspective, with particular emphasis on isolation weaknesses across orchestration, virtualization, network, and interface layers. Due to the technical immaturity and instability of current open-source slicing platforms, experimental validation of security mechanisms proved infeasible. These limitations are therefore treated as empirical evidence informing a structured vulnerability taxonomy and a qualitative risk assessment grounded in confidentiality, integrity, and availability. Building on this analysis, the article proposes a conceptual security framework that integrates defence-in-depth, zero-trust principles, continuous monitoring, and adaptive response mechanisms to enforce isolation dynamically. Aligned with established standards and regulatory references, the framework provides a coherent theoretical foundation for future experimental validation and the secure design of resilient 5G network slicing architectures.</description>
	<pubDate>2026-02-12</pubDate>

	<content:encoded><![CDATA[
	<p><b>JCP, Vol. 6, Pages 35: Security Challenges in 5G Network Slicing: A Risk-Based Analysis and Conceptual Framework</b></p>
	<p>Journal of Cybersecurity and Privacy <a href="https://www.mdpi.com/2624-800X/6/1/35">doi: 10.3390/jcp6010035</a></p>
	<p>Authors:
		José Dias
		Silvestre Malta
		Ricardo Santos
		</p>
	<p>Network slicing is a core enabler of multi-tenant 5th Generation (5G) architectures, allowing heterogeneous services to coexist over shared infrastructure. However, ensuring effective isolation between slices remains a critical security challenge, as failures may enable cross-slice interference, data leakage, or cascading service disruption. This article analyses security vulnerabilities affecting 5G network slicing from a risk-oriented perspective, with particular emphasis on isolation weaknesses across orchestration, virtualization, network, and interface layers. Due to the technical immaturity and instability of current open-source slicing platforms, experimental validation of security mechanisms proved infeasible. These limitations are therefore treated as empirical evidence informing a structured vulnerability taxonomy and a qualitative risk assessment grounded in confidentiality, integrity, and availability. Building on this analysis, the article proposes a conceptual security framework that integrates defence-in-depth, zero-trust principles, continuous monitoring, and adaptive response mechanisms to enforce isolation dynamically. Aligned with established standards and regulatory references, the framework provides a coherent theoretical foundation for future experimental validation and the secure design of resilient 5G network slicing architectures.</p>
	]]></content:encoded>

	<dc:title>Security Challenges in 5G Network Slicing: A Risk-Based Analysis and Conceptual Framework</dc:title>
			<dc:creator>José Dias</dc:creator>
			<dc:creator>Silvestre Malta</dc:creator>
			<dc:creator>Ricardo Santos</dc:creator>
		<dc:identifier>doi: 10.3390/jcp6010035</dc:identifier>
	<dc:source>Journal of Cybersecurity and Privacy</dc:source>
	<dc:date>2026-02-12</dc:date>

	<prism:publicationName>Journal of Cybersecurity and Privacy</prism:publicationName>
	<prism:publicationDate>2026-02-12</prism:publicationDate>
	<prism:volume>6</prism:volume>
	<prism:number>1</prism:number>
	<prism:section>Article</prism:section>
	<prism:startingPage>35</prism:startingPage>
		<prism:doi>10.3390/jcp6010035</prism:doi>
	<prism:url>https://www.mdpi.com/2624-800X/6/1/35</prism:url>
	
	<cc:license rdf:resource="CC BY 4.0"/>
</item>
    
<cc:License rdf:about="https://creativecommons.org/licenses/by/4.0/">
	<cc:permits rdf:resource="https://creativecommons.org/ns#Reproduction" />
	<cc:permits rdf:resource="https://creativecommons.org/ns#Distribution" />
	<cc:permits rdf:resource="https://creativecommons.org/ns#DerivativeWorks" />
</cc:License>

</rdf:RDF>
