Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (1,113)

Search Parameters:
Keywords = cyber-security risks

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
26 pages, 991 KB  
Article
A Multi-Stage Framework for Examining the Internal Activity and Refinement of the Cybersecurity Risk Mitigation System in Financial-Banking Environments
by Laurențiu-Constrantin Stama, Roxana-Mariana Nechita, Dana-Corina Deselnicu, Cătălin-George Alexe and Cătălina-Monica Alexe
FinTech 2026, 5(3), 83; https://doi.org/10.3390/fintech5030083 (registering DOI) - 15 Sep 2026
Abstract
The rapid digitalization of financial banking services has increased the need for effective cybersecurity risk mitigation as institutions rely on interconnected digital infrastructures. Understanding how technological, organizational, and human-related factors interact is important for supporting cybersecurity planning and risk management. This study examines [...] Read more.
The rapid digitalization of financial banking services has increased the need for effective cybersecurity risk mitigation as institutions rely on interconnected digital infrastructures. Understanding how technological, organizational, and human-related factors interact is important for supporting cybersecurity planning and risk management. This study examines the internal structure of cybersecurity risk mitigation in financial banking systems through a framework that combines bibliometric analysis, the Decision Making Trial and Evaluation Laboratory (DEMATEL) method, and the Matrix Impact Cross-reference Multiplication Applied to Classification (MICMAC) technique. The bibliometric analysis identified the factors most frequently associated with cybersecurity risk mitigation in scientific publications indexed in the Web of Science Core Collection. These factors were subsequently evaluated by a panel of IT and cybersecurity experts from the banking sector. DEMATEL was applied to examine the influence relationships among the identified factors, and MICMAC was used to refine the system by classifying the factors according to their driving and dependence power. The analysis provides a structured representation of the cybersecurity risk mitigation system and clarifies the role of each factor within the overall structure. The proposed framework may support managers, cybersecurity specialists and decision makers in cybersecurity planning, resource allocation, and strategic decision making within financial institutions. Full article
29 pages, 9324 KB  
Article
From Single Platforms Towards Coordinated Fleets: Safety- and Security-Bounded Autonomous Multi-Robot Systems for Nuclear Decommissioning in Europe
by Abdenour Benkrid, Omar Zahra, Ankur Shukla, István Szőke, Réka Szőke, Guillaume Hueber, Bruno Angelucci, Jarkko Kotaniemi, An Bielen and Giacomo Pinagli
Computers 2026, 15(9), 620; https://doi.org/10.3390/computers15090620 - 15 Sep 2026
Abstract
Europe’s ageing nuclear fleet creates a growing need for repeated radiological characterisation of contaminated, GPS-denied facilities where human access must be kept to a minimum. However, most deployed robotic systems remain limited to a single platform with a narrow task range. Methods: Building [...] Read more.
Europe’s ageing nuclear fleet creates a growing need for repeated radiological characterisation of contaminated, GPS-denied facilities where human access must be kept to a minimum. However, most deployed robotic systems remain limited to a single platform with a narrow task range. Methods: Building on two earlier conference papers by the authors, this article presents the design, safety engineering and initial field evaluation of the EURATOM project XS-ABILITY, tracing how previous European projects shaped its architecture. The system combines legged, wheeled, rail-based and caged aerial robots equipped with gamma/neutron and beta/gamma instruments. The platforms are coordinated through a ROS 2 architecture supporting distributed SLAM, energy-aware task allocation, risk-aware navigation and a radiological digital twin. A safety and conformity framework consolidates machinery, radiation protection, aviation, cybersecurity and AI regulations, with constraints enforced by a supervisory controller. Results: A campaign at the BR1 and BR3 facilities of SCK CEN, Belgium, in April 2026 evaluated a single wheeled ground platform against criteria fixed before deployment. Radiological and pose streams were paired with a median offset of −8.6 ms and no detectable message loss; LiDAR-only localisation was maintained over a 76 m traverse with the accumulated trajectory error bounded at 0.15 m; and repeat passes agreed to a cloud-to-cloud dispersion of 1.1 cm. Fleet-level coordination, communication reliability, radiation endurance and metrological registration accuracy were not evaluated. Conclusions: The demonstrated capability is integrated single-platform operation at TRL 4–5; coordinated fleet operation remains designed but unvalidated. The forthcoming Ignalina campaign is the next validation step, while supervisory human–robot interaction remains a priority for development. Full article
(This article belongs to the Special Issue Advanced Human–Robot Interaction 2026)
Show Figures

Figure 1

60 pages, 5001 KB  
Article
Ethicality Analysis Framework for Active OSINT Research
by Jared Byers, Eavan Driscoll, Annabelle Lu and Alan J. Michaels
Electronics 2026, 15(18), 4164; https://doi.org/10.3390/electronics15184164 - 14 Sep 2026
Abstract
Open-source intelligence (OSINT), a research method crucial to many security fields, has become a critical capability in cybersecurity investigations, missing persons reports, sex trafficking cases, and other domains. Most OSINT processes, particularly active approaches, require some level of deception or interaction with subjects, [...] Read more.
Open-source intelligence (OSINT), a research method crucial to many security fields, has become a critical capability in cybersecurity investigations, missing persons reports, sex trafficking cases, and other domains. Most OSINT processes, particularly active approaches, require some level of deception or interaction with subjects, emphasizing the need for ethics guidance tailored to these methods. Existing structures fall short in addressing the nuances of cyber research, especially when human subject involvement is indirect or unclear. Drawing from active OSINT field experience, we recognize persistent ethical “gray areas” surrounding active OSINT, including ethical hacking, Terms of Service violations, online privacy expectations, artificial intelligence use, fake accounts, and more. This paper is an attempt to clarify where and how to address these issues while filling the gap in proactively designing ethical and quantitative OSINT experiments. We propose a quantitative, adaptable framework integrating an ethics scorecard, risk–reward analysis, and expert advisory review to complement and enhance existing ethics oversight structures. This model is designed to guide both active OSINT projects and broader cyber research initiatives to enable consistent ethical experimental designs. Full article
46 pages, 4823 KB  
Article
A Human-Centered Trust and Optimization Framework for Adaptive Access Management in Industrial IoT Water Treatment Systems
by Abderrahim Rafae, Aicha Aiche, Mohammed Erritali and Pierre-Martin Tardif
Computers 2026, 15(9), 616; https://doi.org/10.3390/computers15090616 - 14 Sep 2026
Abstract
Industrial Internet of Things (IIoT) technologies have significantly improved the automation and monitoring of critical infrastructures such as water treatment facilities. However, the increasing interaction between human operators and cyber-physical systems has intensified insider-related cybersecurity risks. Existing trust management approaches primarily focus on [...] Read more.
Industrial Internet of Things (IIoT) technologies have significantly improved the automation and monitoring of critical infrastructures such as water treatment facilities. However, the increasing interaction between human operators and cyber-physical systems has intensified insider-related cybersecurity risks. Existing trust management approaches primarily focus on connected devices or static role-based access control mechanisms, providing limited support for continuously assessing employee trustworthiness. This paper proposes a Human-Centered Trust Framework for adaptive access management in Industrial IoT water treatment systems. The framework integrates organizational, behavioral, and operational information into a unified employee decision matrix. Criterion importance is objectively determined using the CRITIC method, while employee trustworthiness is evaluated through the TOPSIS multi-criteria decision-making approach. The resulting trust coefficients are then incorporated into a Simulated Annealing optimization model to assign employees to safety-critical industrial tasks under operational and security constraints. The framework was validated using the IBM HR Analytics Employee Attrition and Performance dataset, semantically adapted to represent employee profiles in Industrial IoT environments. Experimental results across four task-allocation scenarios involving 30, 60, 120, and 240 tasks demonstrate that the proposed trust-aware optimization strategy consistently outperforms the evaluated baseline approaches. The Simulated Annealing solution achieved average improvements of 12.53% over Random Feasible Assignment and 11.36% over the RBAC-like strategy, while remaining slightly superior to the stronger Risk-Aware Access-Control baseline, with an average improvement of 0.03%. Furthermore, the proposed optimization procedure maintained an average optimality gap of only 1.21% relative to the exact optimization solution. The proposed framework provides an explainable, data-driven, and optimization-based approach for integrating human trust assessment into Industrial IoT access management, thereby strengthening resilience against insider threats while improving the security, transparency, and adaptability of critical industrial infrastructures. Full article
(This article belongs to the Special Issue IoT: Security, Privacy and Best Practices (3rd Edition))
40 pages, 3230 KB  
Article
Dual-Channel Multi-Level Model for Quantitative Assessment of Data Security in Corporate Networks
by Pavlo Oliinyk, Łukasz Ścisło, Bohdan Rusyn, Oleg Savenko, Tomasz Ciszewski, Sergii Lysenko, Anatoliy Sachenko, Bohdan Savenko and Rafał Rucki
Appl. Sci. 2026, 16(18), 9090; https://doi.org/10.3390/app16189090 - 13 Sep 2026
Abstract
Modern corporate networks operate in increasingly complex and heterogeneous environments, which complicates the objective assessment of their current security state. This study proposes a dual-channel multi-level model for quantitative assessment of data security in corporate networks using a predefined list of indicators aligned [...] Read more.
Modern corporate networks operate in increasingly complex and heterogeneous environments, which complicates the objective assessment of their current security state. This study proposes a dual-channel multi-level model for quantitative assessment of data security in corporate networks using a predefined list of indicators aligned with international cybersecurity standards. The model combines two analytical channels: compliance with security requirements and policies and absence of signs of compromise. Indicator values are normalized and successively aggregated to the levels of confidentiality, integrity and availability aspects; then to node-level scores; and finally to integrated network-level assessments, taking into account node criticality weights. The model was evaluated in a simulation environment using a 14-day scenario with four phases, including normal operation, controlled degradation of security-related indicators, partial recovery and active compromise of a critical node. The results showed that the proposed approach can distinguish between different types of security degradation, localize problematic nodes, identify the most affected security aspects and reveal the indicators responsible for the decline in integrated scores. A comparison with a simplified direct averaging approach was used as an analytical baseline to illustrate the difference between compensatory and non-compensatory channel integration under identical input data and scenario conditions. The results should therefore be interpreted as a controlled numerical demonstration of the model’s aggregation behavior rather than as a complete empirical validation against external cybersecurity assessment frameworks. The proposed model can serve as a basis for analytical security assessment and decision support in corporate networks. Full article
(This article belongs to the Special Issue Advances in Technologies for Data Privacy and Security)
Show Figures

Figure 1

47 pages, 2391 KB  
Systematic Review
Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review
by Majed Alzahrani, Priyadarsi Nanda, Manoranjan Mohanty and Farag El Zegil
Network 2026, 6(3), 76; https://doi.org/10.3390/network6030076 - 10 Sep 2026
Viewed by 98
Abstract
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned [...] Read more.
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned against 2024–2025 EU regulatory requirements (NIS2, the Cyber Resilience Act). Eligibility criteria: Peer-reviewed empirical studies proposing or evaluating a machine learning or deep learning IoT intrusion detection method published in English from January 2018 (limited pre-2018 exceptions for seminal works). Information sources: IEEE Xplore, SpringerLink, Elsevier ScienceDirect, Scopus, Web of Science, and Google Scholar, searched on 12 February 2025. Risk of bias: Each candidate was scored against four criteria (objectives clarity, methodological soundness, reproducibility, IoT-security relevance); studies scoring at least 3 out of 4 were retained. Screening and scoring were performed by one reviewer, with a second reviewer independently checking 20 percent of records. Synthesis methods: Narrative thematic synthesis; heterogeneous metrics and incompatible datasets across studies precluded quantitative meta-analysis. Included studies: Of 427 records identified, 52 studies initially met inclusion criteria; a post hoc independently validated reconstruction of individual QA1–QA4 scores subsequently found that six did not meet the threshold or topical eligibility criteria, yielding a final 46-study corpus. Main findings: Generative adversarial networks (GANs) dominate dataset augmentation work, graph-based communication analysis addresses dependency modelling, and methods based on transformers or federated learning emerge from 2023 onward. Certainty of evidence: No formal grading (GRADE) applies to this narrative synthesis. Confidence in the corpus composition is high, following independent QA1–QA4 validation, while confidence in the thematic findings is moderate given single-reviewer screening and judgment-based classification. Conclusions: We identify three recurring gaps: real-time detection under resource constraints, dependency-aware detection, and regulatory compliance. Closing these gaps requires detection methods that treat IoT security as a networked and regulated system rather than an isolated device classification problem. Registration: Open Science Framework, 10.17605/OSF.IO/NMAK4 (registered retrospectively). No external funding supported this review. Full article
Show Figures

Figure 1

26 pages, 436 KB  
Article
Threat Model for Hybrid Cloud–Edge Cyber–Physical Systems: Mapping STRIDE to MITRE ATT&CK for ICS
by Mieszko Cichoń, Andrzej Mycek and Paweł Pławiak
Electronics 2026, 15(18), 4097; https://doi.org/10.3390/electronics15184097 - 10 Sep 2026
Viewed by 184
Abstract
Hybrid cyber–physical systems (CPS) integrate cloud services used in enterprise environments with operational technology (OT), which controls physical processes. However, most threat models applied to such systems implicitly assume that an adversary necessarily causes any loss of process availability. This perspective is reflected [...] Read more.
Hybrid cyber–physical systems (CPS) integrate cloud services used in enterprise environments with operational technology (OT), which controls physical processes. However, most threat models applied to such systems implicitly assume that an adversary necessarily causes any loss of process availability. This perspective is reflected in both the STRIDE model and the MITRE ATT&CK for ICS knowledge base, which primarily focus on adversarial activities. As a result, they do not explicitly account for a scenario that is becoming increasingly relevant in hybrid architectures: the intentional shutdown of a physical process by the organization defending the system. The loss of availability resulting from the activation of protective mechanisms is not, in itself, a new problem. The concept of a spurious trip has been recognized in safety engineering for decades and is addressed in standards such as IEC 61511. Related dependencies are also considered within the STPA-Sec methodology. Therefore, the objective of this work is not to introduce a new type of threat, but rather to demonstrate that this phenomenon is not adequately represented in widely used threat-modeling taxonomies that are primarily attacker-centric. In addition, a specific trust boundary within the hybrid architecture at which this problem manifests itself is identified. This makes it possible to incorporate the phenomenon into the risk analysis of systems in which a compromise of the IT layer alone can ultimately lead to the shutdown of physical processes. The proposed threat model is based on trust-boundary analysis. The reference hybrid architecture was divided into seven trust boundaries, and each STRIDE category was subsequently mapped to the corresponding MITRE ATT&CK techniques for ICS, based on the trust boundary crossed by a given attack scenario. The resulting threat vectors were then ranked using the fundamental metrics defined in CVSS v4.0. The attack vector was derived from the trust boundary crossed by each scenario and, where applicable, was correlated with published CVE vulnerability assessments. The model was validated against four widely documented industrial cybersecurity incidents: Stuxnet, Triton, Industroyer, and Colonial Pipeline. Full article
Show Figures

Figure 1

16 pages, 965 KB  
Article
An Organizational Decision-Support System for Cybersecurity Risk Management: Classifying Breach Types Using XGBoost and Real-World Incident Data
by Muhammed Samancı, Emrah Noyan and Nuri Avşarlıgil
FinTech 2026, 5(3), 80; https://doi.org/10.3390/fintech5030080 - 10 Sep 2026
Viewed by 98
Abstract
Financial institutions face an escalating volume of cybersecurity threats, yet existing decision frameworks rarely link predictive analytics to operational security priorities. Drawing on Task-Technology Fit theory, this study develops a machine learning-based decision-support framework to classify cybersecurity breach types in financial institutions and [...] Read more.
Financial institutions face an escalating volume of cybersecurity threats, yet existing decision frameworks rarely link predictive analytics to operational security priorities. Drawing on Task-Technology Fit theory, this study develops a machine learning-based decision-support framework to classify cybersecurity breach types in financial institutions and to identify the organizational risk factors that determine them. Analyzing 935 publicly disclosed incidents from the VERIS Community Database (VCDB, NAICS 52), we compare XGBoost against Random Forest, Logistic Regression, and Decision Tree. XGBoost achieves the most balanced performance (accuracy: 95.19%; weighted F1: 0.9519; 5-fold CV: 96.68% ± 0.21%). Feature importance analysis reveals ATM/kiosk infrastructure and breach pattern as the strongest predictors, translating into concrete SOC monitoring priorities. This framework supports UN/SDG 9 (Industry, Innovation and Infrastructure) and UN/SDG 16 (Peace, Justice and Strong Institutions) by strengthening the cyber resilience of financial institutions through open, replicable, data-driven methods. The open-data framework is replicable without commercial threat intelligence licenses. Full article
(This article belongs to the Special Issue FinTech and Financial Stability: Opportunities and Risks)
Show Figures

Figure 1

19 pages, 1536 KB  
Review
Smart Farming Cybersecurity: Key Risks and Security Principles
by Sunmi Kong, Chang Ha Park, Kyung Jun Lee, Tae-Su Kim, Yeong-Seon Won, Min-Ho Jo, SongYi Han, Ju Eun Ko, Hyeon Ju Nam and Hyeon Ji Yeo
Electronics 2026, 15(18), 4087; https://doi.org/10.3390/electronics15184087 - 10 Sep 2026
Viewed by 199
Abstract
By combining digital sensing, network connectivity, data-driven analyses, cloud services, and automated controls, smart farming has been increasingly adopted in agricultural production. Although these technologies have improved the precision and efficiency of farm management, they also increase cybersecurity exposure as agricultural facilities are [...] Read more.
By combining digital sensing, network connectivity, data-driven analyses, cloud services, and automated controls, smart farming has been increasingly adopted in agricultural production. Although these technologies have improved the precision and efficiency of farm management, they also increase cybersecurity exposure as agricultural facilities are connected to external networks, platforms, and remote-control environments. This review seeks to clarify why cybersecurity should be considered a fundamental requirement in smart farming and details the major system components, cybersecurity risks, and network design considerations required for secure operation. This review first explains the concept and application scope of smart farming, and then examines how sensors, communication networks, gateways, control systems, data platforms, user interfaces, cloud infrastructure, and physical support systems contribute to farm management and cybersecurity exposure. The review also emphasizes that smart farming differs from ordinary information systems because digital data and control commands can directly affect physical processes, such as irrigation, ventilation, heating, nutrient supply, and livestock management. Based on these cyber-physical characteristics, the review summarizes the key architectural considerations for reducing cybersecurity risks, including network segmentation, data and command flow mapping, gateway and wireless security, remote access management, cloud access control, device inventory, logging, monitoring, resilience, and local fail-safe operation. Overall, ensuring cybersecurity in smart farming requires an integrated approach that protects not only data and accounts but also the reliability and continuity of agricultural production. Full article
Show Figures

Figure 1

50 pages, 607 KB  
Systematic Review
LLM-Based Agents for Cybersecurity: A Systematic Review of Architectures, Applications, and Open Challenges
by George Fatouros, Konstantinos Mavrogiorgos, Georgios Makridis, John Soldatos and Dimosthenis Kyriazis
J. Cybersecur. Priv. 2026, 6(5), 159; https://doi.org/10.3390/jcp6050159 - 9 Sep 2026
Viewed by 240
Abstract
The rapid evolution of Large Language Models (LLMs) has opened new frontiers in cybersecurity automation, enabling intelligent agents capable of multi-step reasoning, tool invocation, and autonomous decision-making across complex security tasks. While individual applications have emerged across threat intelligence, vulnerability assessment, penetration testing, [...] Read more.
The rapid evolution of Large Language Models (LLMs) has opened new frontiers in cybersecurity automation, enabling intelligent agents capable of multi-step reasoning, tool invocation, and autonomous decision-making across complex security tasks. While individual applications have emerged across threat intelligence, vulnerability assessment, penetration testing, and security operations center (SOC) automation, a systematic understanding of the LLM-based agent paradigm in cybersecurity—encompassing both single-agent and multi-agent architectures—remains lacking. This paper presents a systematic literature review following PRISMA guidelines, identifying records through 59 structured web-search queries whose results resolve predominantly to arXiv, Semantic Scholar, the ACM Digital Library, IEEE Xplore, USENIX, MDPI, SpringerLink, and Elsevier ScienceDirect, supplemented by citation chaining, for works published between January 2022 and April 2026; the full query record is published with the paper. We applied structured inclusion and exclusion criteria and classified 59 primary studies along five dimensions: security function, agent architecture pattern, knowledge augmentation strategy, human-in-the-loop posture, and evaluation rigor. Our analysis reveals that penetration testing and threat intelligence are the most extensively studied domains, while incident response and compliance verification remain critically underrepresented. Penetration testing alone accounts for over half the corpus (50.8%). Single-agent tool-calling remains the most prevalent architecture (30.5% of studies), whereas centralized multi-agent orchestration—present in 18.6%—yields the strongest reported performance gains, up to 4.3× on zero-day exploitation; prevalence and performance therefore point in opposite directions. No included study achieves production-grade (E4) evaluation: the entire field currently rests on controlled laboratory assessments. An independent search of six bibliographic databases recovers 86.3% of the studies the primary search had surfaced (79.7% of the full corpus) while indicating a total eligible literature of roughly 400 studies, so the corpus is reported as a documented subset rather than an exhaustive census. We propose a unifying taxonomy, identify cross-cutting challenges including hallucination, prompt injection, and benchmark fragmentation, and outline open research directions with particular emphasis on multi-agent orchestration design. Financial sector applicability under DORA and the EU AI Act is treated as a documented evidence gap rather than a synthesis: the corpus’s only compliance and risk assessment study is also its only banking-specific system. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

18 pages, 3561 KB  
Article
Integrated Safety and Security Risk Analysis of Lane Keeping Assistance Using TARA
by Ashutosh Kumar, Vlad-loan Ciutina, Stefania Gall, Christian Esposito and Rahamatullah Khondoker
Electronics 2026, 15(18), 4063; https://doi.org/10.3390/electronics15184063 - 8 Sep 2026
Viewed by 194
Abstract
Lane Keeping Assistance (LKA) systems play a critical role in enhancing vehicular safety and driving comfort by maintaining lane alignment and mitigating risks associated with driver distraction or drowsiness. These systems rely on sensor data to execute corrective steering or braking actions, yet [...] Read more.
Lane Keeping Assistance (LKA) systems play a critical role in enhancing vehicular safety and driving comfort by maintaining lane alignment and mitigating risks associated with driver distraction or drowsiness. These systems rely on sensor data to execute corrective steering or braking actions, yet their dependence on interconnected electronic components exposes them to a range of safety and cybersecurity threats. Attackers can exploit vulnerabilities in sensors, communication protocols, and Electronic Control Units (ECUs), potentially triggering false interventions or disabling safety functions. This paper presents a comparative Threat Analysis and Risk Assessment (TARA) of two LKA system architectures using the Medini Analyze tool. The first architecture employs a hierarchical controller with driver-intention detection and Electronic Stability Control (ESC)-based actuation. The second architecture employs a Learning-Based Model Predictive Control (LBMPC) framework enabling situation-adaptive decision-making. Through systematic identification and evaluation of threats and vulnerabilities, the analysis assesses risk levels associated with each design. The comparative analysis reveals trade-offs among architectural complexity, system robustness, and exposure to potential vulnerabilities, offering practical insights to improve the safety and security of LKA system designs. Full article
(This article belongs to the Special Issue Eco-Safe Intelligent Mobility Development and Application)
Show Figures

Figure 1

35 pages, 16668 KB  
Article
A Provenance-Driven Trust Framework with Physics-Consistent Validation for Secure Wireless Sensor Networks
by Eman Abouelkheir
Sensors 2026, 26(18), 5695; https://doi.org/10.3390/s26185695 - 8 Sep 2026
Viewed by 248
Abstract
Wireless sensor networks (WSNs) play a critical role in cyber-physical applications such as industrial monitoring, environmental sensing, and critical infrastructure management. In these environments, security mechanisms must not only detect malicious activities but also explain how compromised measurements propagate through sensing, aggregation, and [...] Read more.
Wireless sensor networks (WSNs) play a critical role in cyber-physical applications such as industrial monitoring, environmental sensing, and critical infrastructure management. In these environments, security mechanisms must not only detect malicious activities but also explain how compromised measurements propagate through sensing, aggregation, and decision processes while operating under stringent resource constraints. Existing approaches typically address intrusion detection, trust management, provenance analysis, or blockchain-based integrity independently, providing limited support for integrated and explainable security. This paper presents PhyProvTrust-WSN, a physics-aware framework that combines physics-consistency validation, dynamic provenance graphs, evidence-based trust propagation, multi-factor risk fusion, and selective evidence anchoring to improve the transparency and auditability of secure sensor data aggregation. The framework models sensing, forwarding, aggregation, validation, and response events as a bounded provenance directed acyclic graph (DAG), enabling causal tracing of suspicious activities while maintaining low memory and communication overhead. A weighted risk fusion mechanism integrates anomaly evidence, domain-consistency assessment, trust evolution, and inherited provenance risk to support explainable security decisions. Rather than continuously recording all events, only high-risk or decision-relevant evidence hashes are anchored to a permissioned audit layer, reducing storage and communication costs. To avoid overclaiming, the proposed framework is evaluated using a hybrid methodology that combines attack-labeled WSN datasets, real sensor measurements for physics-consistency validation, and simulation-based overhead analysis. The results demonstrate that the integrated framework provides strong detection capability while improving explainability, supporting root-cause analysis, and maintaining bounded communication and storage overhead suitable for resource-constrained WSN deployments. Full article
(This article belongs to the Special Issue Advances and Challenges in Sensor Security Systems)
Show Figures

Figure 1

48 pages, 12100 KB  
Article
A Simulation-Based Quantum-Synchronized Ephemeral Encryption Framework for QKD-Secured IoT Networks with Transformer-Based Cyber-Quantum Attack Detection
by Mohammad Sameer Aloun, Ala Mughaid, Bashar S. Khassawneh and Mahmoud AlJamal
Computation 2026, 14(9), 207; https://doi.org/10.3390/computation14090207 - 7 Sep 2026
Viewed by 145
Abstract
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer [...] Read more.
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer adversarial attack injection, and AI-based multiclass detection. Unlike conventional IoT intrusion datasets that mainly capture packet- or flow-level abnormalities, the generated dataset represents the joint behavior of IoT sessions, network delay, queue pressure, QKD state, key consumption, encryption-mode transitions, ciphertext metadata, and cyber-quantum risk. A Python/SimPy/NetworkX simulation was developed using 80 IoT devices, 3 gateways, 2 edge servers, 4 cyber-quantum control-plane nodes, and 1 adversarial orchestrator. The final simulation produced 46,351 records with 76 features covering normal traffic, five traditional IoT attacks, and six novel cyber-quantum attacks, including QKD key-pool starvation, QBER camouflage, false QKD-health injection, encryption downgrade induction, queue–key coupling, and multi-vector cyber-quantum orchestration. Q-SEE adaptively selects among QKD-OTP, QKD-synchronized AES-256 ephemeral mode, PQC fallback, degraded mode, and blocked mode according to QBER, secret key rate, key availability, device criticality, downgrade pressure, and risk. A leakage-aware Quantum-Aware Kolmogorov–Arnold Network (QKAN) was then trained using deployable cyber-quantum evidence. The final nonrisk QKAN achieved 98.79% test accuracy, 98.61% macro-F1, 98.85% weighted-F1, and 99.78% macro-AUC, demonstrating effective detection of traditional and cyber-quantum IoT attacks. Full article
(This article belongs to the Section Computational Intelligence)
Show Figures

Figure 1

22 pages, 2354 KB  
Article
Machine Learning-Based Domain Risk Assessment for Cybersecurity Monitoring in Industrial Systems
by Jacek Łukasz Wilk-Jakubowski, Aleksandra Sikora and Jakub Piotr Zapała
Processes 2026, 14(17), 2835; https://doi.org/10.3390/pr14172835 - 3 Sep 2026
Viewed by 303
Abstract
In the field of cybersecurity, malicious website classification plays a crucial role in protecting industrial systems. For this reason, research has been undertaken to analyze cybersecurity threats, with the long-term objective of developing methods for the effective detection and classification of malicious websites. [...] Read more.
In the field of cybersecurity, malicious website classification plays a crucial role in protecting industrial systems. For this reason, research has been undertaken to analyze cybersecurity threats, with the long-term objective of developing methods for the effective detection and classification of malicious websites. This article evaluates the use of domain features for classifying malicious websites with machine learning methods. The feature vector consisted of 44 infrastructural, lexical, structural, and reputation-related characteristics. The model comparison included Logistic Regression, Support Vector Machine, Random Forest, AdaBoost, and XGBoost. Experiments were conducted on 247,730 URLs from the malicious_phish dataset (2021), with features extracted as part of this study in April 2026. The most predictive features were related to domain registration history, DNS infrastructure, and reputation-based rankings, as confirmed by ANOVA F-test, SHAP values, XGBoost gain, and permutation importance. Validation of the best-performing model on 1000 active phishing domains from the PhishDestroy list dated 30 May 2026, achieved a recall of 70%, while the application of a three-tier risk scale allowed 84.9% of domains to be flagged as malicious or suspicious. Full article
Show Figures

Figure 1

50 pages, 14774 KB  
Article
QKD-Secured Industrial Smart-Grid Cyber-Physical Systems: Simulation and Q-MambaKAN Detection of Adaptive Side-Channel Attacks
by Ayoub Alsarhan, Bashar S. Khassawneh, Laith Alzboon, Kholoud Alkayid, Mahmoud AlJamal, Eslam Al Maghayreh, Fiyad Ahmad Alenazi and Hussein Al-Ofeishat
Future Internet 2026, 18(9), 468; https://doi.org/10.3390/fi18090468 - 3 Sep 2026
Viewed by 270
Abstract
The increasing interconnection of smart-grid operational technology, industrial-edge services, and utility information systems creates a critical need for resilient and continuously monitored industrial cyber-physical communication. Although quantum key distribution (QKD) can strengthen session-key establishment for advanced metering infrastructure, distributed energy resources, substation automation, [...] Read more.
The increasing interconnection of smart-grid operational technology, industrial-edge services, and utility information systems creates a critical need for resilient and continuously monitored industrial cyber-physical communication. Although quantum key distribution (QKD) can strengthen session-key establishment for advanced metering infrastructure, distributed energy resources, substation automation, supervisory control, and utility-core services, practical QKD deployments remain vulnerable to implementation-level side-channel attacks that can compromise the cryptographic protection layer without directly targeting conventional network packets. This paper presents a QKD-secured industrial smart-grid cyber-physical system framework for simulating and detecting adaptive side-channel attacks. The proposed 36-node industrial communication architecture integrates AMI devices, DER controllers, PMU and substation automation components, industrial-edge gateways, QKD modules, key-management services, SCADA and utility-core servers, security-operation-center components, and adversarial access points. A 100,000-record cyber-quantum dataset is generated across 12 operating conditions comprising normal communication and 11 adaptive QKD side-channel attacks: detector blinding, time shift, wavelength switching, Trojan-horse probing, photon-number splitting, decoy-state spoofing, RNG bias, calibration manipulation, local-oscillator manipulation, synchronization spoofing, and combined adaptive quantum hacking. Each scenario introduces coupled primary and secondary perturbations across optical, detector, timing, synchronization, randomness, calibration, photon-statistical, leakage, key-generation, encryption, and industrial-network-performance features. To support intelligent industrial security monitoring, the proposed Quantum-aware Mamba–Kolmogorov–Arnold Network (Q-MambaKAN) organizes device, network, QKD, side-channel, encryption, and risk evidence into an ordered cyber-quantum representation processed through selective state-space learning, side-channel attention, nonlinear KAN mapping, adaptive fusion, and multi-task prediction heads. Results show that the QBER increases from 0.071 during normal operation to 0.426 under combined adaptive quantum hacking, while encryption success decreases from 98.1% to 0%. Q-MambaKAN achieves a 99.48% binary detection accuracy, a 99.70% binary F1-score, a 97.60% multiclass macro-F1, and a risk RMSE of 0.021. Full article
(This article belongs to the Special Issue Cyber-Physical Systems in Industrial Communication Systems)
Show Figures

Figure 1

Back to TopTop