Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (56)

Search Parameters:
Keywords = cybersecurity behaviour

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
19 pages, 695 KB  
Review
Recent Progress in Optimising Sustainable Energy Smart Grids Using Swarm Robotics: A Systematic Narrative Review
by Dimitris Ziouzios and Vayos Karayannis
Electronics 2026, 15(18), 4174; https://doi.org/10.3390/electronics15184174 - 14 Sep 2026
Abstract
This systematic narrative review examines recent advances in the application of swarm robotics and swarm intelligence to smart grid systems in the context of renewable energy sources. Smart grids represent a transformative paradigm in power systems, integrating advanced communication, monitoring, and control technologies [...] Read more.
This systematic narrative review examines recent advances in the application of swarm robotics and swarm intelligence to smart grid systems in the context of renewable energy sources. Smart grids represent a transformative paradigm in power systems, integrating advanced communication, monitoring, and control technologies to enhance the reliability, performance, and sustainability of power distribution. Swarm robotics, drawing inspiration from the collective behaviour of social insects, enables the coordination of numerous autonomous agents to carry out complex tasks in a decentralised, scalable, and fault-tolerant manner. Over the past decade, swarm intelligence approaches—including Particle Swarm Optimisation, Ant Colony Optimisation, and consensus-based distributed control—have emerged as promising methods for addressing smart grid challenges such as decentralised energy management, fault detection, infrastructure monitoring, and maintenance. This review was conducted through a two-stage systematic search of three databases (Scopus, IEEE Xplore, and ACM Digital Library; Web of Science was not accessible during the search period and was therefore excluded), which identified 54 primary studies meeting the full-text inclusion criteria, supplemented by 11 additional records located through hand-search, for a final corpus of 65 references. For each application domain (monitoring and inspection, energy distribution optimisation, fault detection and resilience, and cybersecurity and communication), we summarise the methodologies employed, the reported performance outcomes, and the evidence level of the available studies. We also analyse the scalability limits of current swarm approaches, communication constraints relevant to grid deployment, and the integration of swarm systems with existing SCADA and EMS infrastructure. The review identifies a significant gap between laboratory demonstrations and utility-scale deployment, and outlines priority directions for future research. Full article
36 pages, 639 KB  
Systematic Review
A Systematic Literature Review on Machine Learning for Intrusion Detection Systems
by Ali Ahmed, Ramy Mostafa, Mahmoud H. Qutqut and Noha Ragab
Future Internet 2026, 18(9), 470; https://doi.org/10.3390/fi18090470 - 7 Sep 2026
Viewed by 285
Abstract
The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite extensive research [...] Read more.
The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite extensive research on various ML and Deep Learning (DL) models for IDS, the current literature remains incomplete. It has many different datasets, methods, and evaluation standards. As cyber threats become more advanced, it is crucial to conduct a thorough analysis of ML techniques for intrusion detection. The goal of this Systematic Literature Review (SLR) is to provide a full picture of the most recent academic articles on ML-based IDS. The study addresses important research questions about the most widely used algorithms, the types of attacks and network environments covered, the methodological problems that remain unsolved, and the new trends that should shape future research. Following the PRISMA framework, we conducted a systematic review of peer-reviewed articles published between January 2022 and May 2025. We searched IEEE Xplore, ACM Digital Library, and SpringerLink, yielding 22,558 initial records. After carefully applying strict inclusion criteria, 125 papers were selected for the final analysis. We created a standardised data extraction form (i.e., using MS Excel) to gather bibliographic details, research emphasis, methodological strategies, datasets, evaluation criteria, and recognised constraints. We employed thematic analysis to develop a clear taxonomy. We identified five main research themes in our analysis: (1) ensemble and hybrid learning pipelines focused on performance optimisation (30 papers), (2) context-specific IDS designs for Internet of Things (IoT), cloud, and Software-Defined Networking (SDN) environments (34 papers), (3) data-centric engineering that deals with class imbalance and feature selection (20 papers), (4) deep neural architectures for representation learning (31 papers), and (5) trustworthiness concerns like adversarial robustness, zero-day detection, and Explainable AI (XAI) (10 papers). Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM), and Random Forests are the most commonly used algorithms, often combined. Nonetheless, significant deficiencies remain: about 2% of papers incorporate XAI, only 4% focus on adversarial robustness, and none validate their models in real-world production settings. Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks are the most common types in the literature, whereas Web attacks, ransomware, and advanced persistent threats remain poorly studied. The number of publications grows at an average of 30.2% annually, but the field still relies on legacy benchmark datasets rather than operational validation. Full article
(This article belongs to the Special Issue Privacy-Preserving and Secure Machine Learning)
Show Figures

Figure 1

34 pages, 3640 KB  
Article
Trust Scoring for Edge–Fog–Cloud IIoT Networks Using Deep Learning
by André Daniel Neves Almeida, Tahmid Quazi, Sulaiman Saleem Patel and Mohamed Mostafa Hassan Mostafa
J. Sens. Actuator Netw. 2026, 15(4), 65; https://doi.org/10.3390/jsan15040065 - 11 Aug 2026
Viewed by 661
Abstract
Trust Management Systems (TMSs) have recently emerged as a behavioural complement to identity-based approaches in Industrial IoT (IIoT) cybersecurity by evaluating node trustworthiness. Deep Learning (DL)-based TMSs offer favourable detection over heuristic and Machine Learning (ML) models. The computational density of DL models [...] Read more.
Trust Management Systems (TMSs) have recently emerged as a behavioural complement to identity-based approaches in Industrial IoT (IIoT) cybersecurity by evaluating node trustworthiness. Deep Learning (DL)-based TMSs offer favourable detection over heuristic and Machine Learning (ML) models. The computational density of DL models introduces a trade-off between inference fidelity and deployment feasibility, particularly in Edge-Fog-Cloud (EFC) IIoT architectures where latency and resources are constrained. This work proposes an EFC architectural framework that relocates DL inference to the Fog layer, reducing Cloud communication latency and Edge resource exhaustion. A lightweight Long Short-Term Memory (LSTM)-based model derives continuous trust scores from header-derived, flow-aggregated features, with inference latency bounded through fixed-size sliding windows and stateless execution. The system is trained and evaluated on CIC-IoT-2023 across Denial-of-Service (DoS), Distributed DoS (DDoS), Mirai, and benign scenarios. System scalability is assessed through ns-3 network simulation under benign conditions, with full-system behaviour further evaluated under benign, DoS, and Mirai scenarios. Offline evaluation achieves F1-score 0.9996, accuracy 0.9997, ROC-AUC 0.9999, and PR-AUC 0.9997. Architectural evaluation yields a mean inference latency of 0.049 ms, a maximum enforcement latency of 0.120 ms, and a 302 kB deployment footprint. System simulation confirms a benign False Positive Rate (FPR) 0.07% and a maximum detection latency of 0.22 ms. DoS achieves recall 0.99999 and FPR 0.00186, and Mirai achieves recall 0.99997 with FPR 0. This demonstrates that DL-based trust inference is achievable on resource-constrained Fog nodes, establishing the work as a viable solution for trust evaluation in EFC IIoT deployments. Full article
(This article belongs to the Special Issue Advances in Intelligent Transportation Systems (ITS): 2nd Edition)
Show Figures

Figure 1

14 pages, 468 KB  
Article
Longitudinal Behavioural Analysis of Industrial IoT Network Traffic Using Passive Monitoring
by Henrique Santos and Pedro Magalhães
J. Sens. Actuator Netw. 2026, 15(4), 62; https://doi.org/10.3390/jsan15040062 - 2 Aug 2026
Viewed by 387
Abstract
Industrial Internet of Things (IIoT) production environments rely on automated communication between control systems and embedded devices while operating under strict availability constraints that limit the deployment of conventional IT security controls. Despite extensive research on intrusion detection systems, empirical studies based on [...] Read more.
Industrial Internet of Things (IIoT) production environments rely on automated communication between control systems and embedded devices while operating under strict availability constraints that limit the deployment of conventional IT security controls. Despite extensive research on intrusion detection systems, empirical studies based on long-term observations of real industrial networks remain scarce. This paper presents a longitudinal 92-day passive monitoring study of a production-line IIoT network comprising 22 monitored devices. A containerised instance of Zeek was deployed in promiscuous mode to collect flow-level and application-layer telemetry without interfering with operations. The resulting dataset contains more than 41.5 million network flows and 520.5 million packets, represented by 48.48 GB of structured Zeek logs. The results reveal highly deterministic communication patterns dominated by periodic HTTP polling between a central server and distributed devices. In particular, the hourly mean HTTP response size remained highly stable at 132.76 bytes, with a standard deviation of 1.37 bytes and a coefficient of variation of 1.0%. Although no confirmed malicious activity was observed, transient deviations were identified and attributed to planned production stoppages restart periods, which caused temporary traffic reductions and short-lived packet bursts. These findings demonstrate that production-line IIoT networks can exhibit predictable behaviour regimes suitable for statistical anomaly detection. The study contributes a longitudinal empirical characterisation of a real operational IIoT network, a reproducible methodology for behavioural baseline extraction using passive telemetry, and practical insights for safe monitoring deployment. Full article
Show Figures

Figure 1

33 pages, 613 KB  
Review
Distributed Artificial Intelligence for IoT Security: A Structured Review
by Sabina Szymoniak and Mariusz Kubanek
Sensors 2026, 26(15), 4802; https://doi.org/10.3390/s26154802 - 28 Jul 2026
Viewed by 662
Abstract
The expansion of the Internet of Things (IoT) has increased the complexity of securing distributed systems against growing threats to data security, privacy, and reliability. Conventional centralised cybersecurity methods are often insufficient for environments characterised by scale, heterogeneity, and dynamic behaviour. This paper [...] Read more.
The expansion of the Internet of Things (IoT) has increased the complexity of securing distributed systems against growing threats to data security, privacy, and reliability. Conventional centralised cybersecurity methods are often insufficient for environments characterised by scale, heterogeneity, and dynamic behaviour. This paper presents a structured review of Distributed Artificial Intelligence (DAI) for IoT security, focusing on how local, cooperative intelligence can support intrusion detection, anomaly recognition, secure data processing, and collaborative defence. We synthesise the current literature on Federated Learning (FL), Multi-Agent Systems, and related approaches, highlighting their benefits, limitations, and practical deployment constraints. Particular attention is given to critical infrastructure contexts, where resilience is essential for operational continuity and public safety. The review concludes by outlining key gaps and future research directions for DAI-enabled IoT security. Full article
(This article belongs to the Special Issue Architecting Security for the Next-Generation Internet of Things)
Show Figures

Figure 1

27 pages, 8669 KB  
Article
Heterogeneous Feature Integration for Class-Imbalanced Intrusion Detection in Grid Systems
by Kai Cheng, Dongkun Li, Weidong Tang, Lin Liu and Xueyu Zhang
Symmetry 2026, 18(7), 1241; https://doi.org/10.3390/sym18071241 - 22 Jul 2026
Viewed by 635
Abstract
Modern grid digitalization connects communication networks, monitoring terminals, service platforms, security devices, and operational data sources. Intrusion detection in this setting requires correlating heterogeneous security data with grid-side contextual evidence. To address class imbalance and cross-domain heterogeneity, this study proposes a heterogeneous feature [...] Read more.
Modern grid digitalization connects communication networks, monitoring terminals, service platforms, security devices, and operational data sources. Intrusion detection in this setting requires correlating heterogeneous security data with grid-side contextual evidence. To address class imbalance and cross-domain heterogeneity, this study proposes a heterogeneous feature group integration framework for intrusion detection with grid cybersecurity data. Four semantic feature subspaces are constructed symmetrically: network behaviour, power operation context, zone-derived communication/event topology, and system operation state, ensuring equal structural footing for subsequent modality-specific encoding. Transformer-based encoders model temporal dependencies in network, physical, and system state modalities, while a graph neural network encodes topology-related structural information. The resulting embeddings are integrated by a late fusion classifier for multiclass attack identification; the fusion process treats each feature group symmetrically at the decision level, without imposing a priori dominance among modalities. In the main run, the full model achieves an accuracy of 0.944, a macro F1 score of 0.891, a weighted F1 score of 0.937, a macro precision of 0.929, and a macro recall of 0.878. The corresponding balanced accuracy is 0.878, and the multiclass MCC is 0.924. Class-wise results show reliable performance on Benign, Scan, WebAtk, DDoS, DoS, and Backdoor classes, while Ransomware remains difficult and is frequently confused with WebAtk. Specifically, the Ransomware recall is 0.27, with most errors assigned to WebAtk. Modality analysis further indicates that modality contribution is class dependent: some feature groups have limited standalone discriminative power but provide complementary evidence after fusion. This finding highlights an inherent asymmetry in class-wise utility, which we counterbalance by employing both macro and weighted metrics, offering a symmetric evaluation lens that accounts for both minority and majority classes. These results show that grid-oriented intrusion detection benefits from decision-level integration of heterogeneous feature groups and imbalance-aware evaluation, where symmetric treatment of feature subspaces and evaluation perspectives jointly enhances robustness. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

23 pages, 477 KB  
Article
From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence
by János Kálmán
Account. Audit. 2026, 2(3), 12; https://doi.org/10.3390/accountaudit2030012 - 15 Jul 2026
Viewed by 1151
Abstract
Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built [...] Read more.
Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring. The Act is not an auditing standard and does not directly regulate every tool used by audit firms. Nevertheless, its governance logic is relevant where audit firms develop, procure, or rely on AI-enabled systems that process sensitive client data, influence professional judgement, or become part of audit-relevant client systems. This conceptual study uses doctrinal requirements-to-controls mapping and design-oriented analysis to translate selected AI Act governance objectives into firm-level and engagement-level quality-management controls and into criteria for evaluating AI-enabled audit evidence. The paper specifies three modes of AI Act relevance: direct legal relevance where a regulated AI Act role is engaged; indirect relevance where AI compliance documentation becomes audit-relevant information; and benchmark relevance where the Act supplies governance objectives for quality management without creating an audit-law duty. The resulting artefacts are a traceable AI Act/IAASB standards crosswalk, an evidence-risk typology, a quality-management integration model, a documentation and review checklist, and a proportional maturity model. The framework clarifies when AI outputs remain triage or risk-assessment tools, when they provide directional or corroborative evidence, and the narrower conditions under which they may contribute to substantive evidence. It links reliance to data completeness, reconciliation, versioning, validation, false-positive and false-negative behaviour, explainability, logging, source-document corroboration, and reviewer challenge. The contribution is a scalable governance-to-controls framework that supports defensible reliance and inspection readiness without overstating the AI Act’s direct legal applicability. Empirical validation in audit firms remains a priority for future research. It further explains how quantitative risk features and anomaly-detection outputs feed into qualitative audit judgement: models can route attention to unusual transactions or documents, but evidential weight still depends on base-rate-aware error analysis, source-document corroboration, and reviewer challenge. Full article
Show Figures

Figure 1

32 pages, 7931 KB  
Article
Addressing Extreme Baseline Imbalances in Quasi-Experimental Evaluation of AI-Driven Adaptive Cybersecurity Training: A Multi-Method Approach
by Mohammed M. Al-Gawda, Majdi Abdellatief and Ibrahim Al-Baltah
Information 2026, 17(7), 682; https://doi.org/10.3390/info17070682 - 14 Jul 2026
Viewed by 544
Abstract
Despite widespread adoption of cybersecurity awareness training (CSAT), a persistent knowledge–behaviour gap continues to undermine organisational security posture, particularly in resource-constrained and developing-country contexts. This 12-week quasi-experimental field study evaluated an AI-adaptive CSAT platform against traditional instructor-led training (ILT) across three Yemeni organisations [...] Read more.
Despite widespread adoption of cybersecurity awareness training (CSAT), a persistent knowledge–behaviour gap continues to undermine organisational security posture, particularly in resource-constrained and developing-country contexts. This 12-week quasi-experimental field study evaluated an AI-adaptive CSAT platform against traditional instructor-led training (ILT) across three Yemeni organisations (total N = 187; AI-Adaptive: n = 94; Control: n = 93). The system used a 4-parameter Bayesian Knowledge Tracing (BKT) engine—with interpretable guess and slip signals—as an auditable pedagogical decision layer that triggered Protection Motivation Theory (PMT) and Theory of Planned Behavior (TPB)-aligned interventions. Extreme baseline imbalances (Cohen’s d > 2.0), at which standard ANCOVA residual adjustment alone is known to be biased and which necessitated advanced causal-inference triangulation, were addressed via a four-method protocol (ANCOVA, Propensity Score Matching, Difference-in-Differences, mixed-effects). All four methods converged on consensus effect sizes of d = 0.66–0.89. IT-verified Tier 2–3 incidents declined by 48.9% (incidence-rate ratio [IRR] = 0.51, 95% CI [0.38, 0.68]); blinded phishing click-rates fell from 8.8% to 2.1% (χ2(1) = 8.74, p = 0.003). Bootstrapped mediation analysis (PROCESS Model 4; 5000 draws) indicated that coping self-efficacy and perceived behavioural control—but not threat appraisal—were jointly associated with 66.4% of the total compliance effect. Rosenbaum bounds Γ = 2.1; E-values ≥ 3.4. The findings are consistent with the hypothesis that AI-adaptive cybersecurity training produces robust, theoretically explicable benefits and that the coping-appraisal pathway, not threat salience, is the active psychological mechanism. The four-method triangulation framework offers a replicable standard for field evaluations with non-random assignment. the consensus envelope d = 0.66–0.89 is the observed range of point estimates across the four estimators; per-method 95% CIs are reported below indirect effect via coping self-efficacy = 0.843 [0.52, 1.19], via PBC = 0.524 [0.28, 0.81], via threat appraisal = 0.059 [−0.07, 0.21] (ns); direct effect c’ = 0.63 (p = 0.026); total effect c = 2.06 [1.58, 2.54]. Full article
(This article belongs to the Special Issue AI-Driven Information Analytics for Cybersecurity and Privacy)
Show Figures

Figure 1

28 pages, 799 KB  
Article
A Quantitative Evaluation of Cyber4Me: A Holistic Framework for Enhancing Individual Cybersecurity Awareness
by Md. Arafatur Rahman, Mohamad Ibrahim, Bashir Ahmed, Nadia Refat, Tan Sze Wei and Prashant Pillai
Computers 2026, 15(7), 418; https://doi.org/10.3390/computers15070418 - 29 Jun 2026
Viewed by 469
Abstract
Human factors remain the dominant contributor to cybersecurity incidents, yet awareness training produces only moderate and often non-durable behaviour change, and most evaluated programs are either purely digital or evaluated only at the framework level. This study addresses two gaps: the scarcity of [...] Read more.
Human factors remain the dominant contributor to cybersecurity incidents, yet awareness training produces only moderate and often non-durable behaviour change, and most evaluated programs are either purely digital or evaluated only at the framework level. This study addresses two gaps: the scarcity of empirical and demographically stratified evidence for multi-modal community-facing awareness programs, and the lack of an explicit account of how artificial intelligence (AI) should be integrated into such programs rather than treated as an optional add-on. We evaluate Cyber4Me, a four-stage individual-awareness intervention (community roadshows, structured training, a hackathon, and a physical–digital escape room) that is wrapped in a cross-cutting AI adaptive layer built entirely on structured performance and behaviour data baseline competency tiering, awareness–behaviour gap detection, predictive early-warning, and personalised recommendation, with no reliance on free text. Using a single-group pre–post design with 130 participants in the UK Black Country region and a multi-dimensional Likert instrument, all four competency domains (confidence, familiarity, GDPR knowledge, incident-response preparedness) improved significantly (paired-t, all p<0.001; large within-participant effects, Cohen’s d1.0). Improvement was strongly moderated by demographics: older adults gained most in familiarity, undergraduates in confidence, and lower-education participants in regulatory knowledge. The contributions are as follows: transparent and demographically stratified pre–post evidence for a multi-modal awareness program with effect sizes reported; a fitness-for-purpose comparison against contemporary analogs (KnowBe4, Proofpoint, CyberPatriot, iCAT, CAT-RWE, GPT-CSAT, escape-room studies) that treats AI as a first-class design dimension; and an articulated AI integration architecture for the framework, demonstrated offline on the cohort using only structured performance and behaviour data (no free text). In this architecture, a gradient-boosted classifier assigns participants to three baseline competency tiers at 93.1% cross-validated accuracy; these tiers differ sharply in measured improvement (ANOVA F=68.8, p<0.001; Foundational +1.79 vs. Applied +0.30 scale points), an awareness–behaviour gap segment is detected and predicted from intake signals alone (AUC =0.73), and a recommender routes participants to personalised follow-on tracks. As the design is single-group and self-reported, results are reported as evidence of within-participant change associated with the intervention rather than as a causal efficacy estimate, and the AI layer is demonstrated for feasibility rather than being evaluated as a separate trial arm; the scope is explicitly individual security awareness and behaviour, not technical network, IIoT, or cloud security. Full article
(This article belongs to the Special Issue Using New Technologies in Cyber Security Solutions (3rd Edition))
Show Figures

Figure 1

42 pages, 4791 KB  
Article
Unpacking Internet-Based Social Engineering Victimisation on Social Networking Sites: An Interdisciplinary Qualitative Framework of Individual, Social, and Platform Factors
by Saad Saleh Alshammari, Ben Soh and Alice Li
Future Internet 2026, 18(7), 336; https://doi.org/10.3390/fi18070336 - 25 Jun 2026
Viewed by 530
Abstract
Despite extensive research on social engineering victimisation on social networking sites (SNSs) across the Internet, user susceptibility continues to increase, indicating that existing explanatory models remain incomplete. Previous studies have predominantly examined susceptibility through isolated factors, including individual traits, message characteristics, or source [...] Read more.
Despite extensive research on social engineering victimisation on social networking sites (SNSs) across the Internet, user susceptibility continues to increase, indicating that existing explanatory models remain incomplete. Previous studies have predominantly examined susceptibility through isolated factors, including individual traits, message characteristics, or source attributes, while often overlooking how evolving Internet-based SNS environments interact with human and social factors. To address this gap, this study presents an interdisciplinary qualitative investigation into emerging determinants of user susceptibility to social engineering cyberattacks (SECAs) on Internet-enabled SNS platforms. Drawing on in-depth interviews with 18 experts from cybersecurity, psychology, sociology, criminology, and linguistics, the study captures perspectives that are rarely integrated within a single analytical framework. Using NVivo 14 and inductive thematic analysis, six core themes and seven sub-themes were identified, revealing previously underexplored cognitive-emotional, social-relational, and platform-mediated mechanisms of victimisation. The key contribution of this research is not the identification of entirely new susceptibility factors, but the development of an interdisciplinary framework that integrates these previously disconnected dimensions. By foregrounding the role of SNS design affordances within the broader Internet ecosystem and their interaction with human cognition and social dynamics, this study advances current understanding beyond fragmented models of user vulnerability. The findings provide a novel conceptual foundation for future empirical research and inform the design of more effective, context-aware mitigation and awareness strategies for SECAs on Internet-based SNSs. Full article
(This article belongs to the Special Issue Adversarial Attacks and Cyber Security)
Show Figures

Figure 1

29 pages, 3168 KB  
Article
Human Behaviour as a Predictor of Insider Threat: A PRISMA Systematic Literature Review and a Novel Ensemble-Based Detection Model
by Christian Bowie, Hadi Larijani and Ayyaz Qureshi
Information 2026, 17(7), 627; https://doi.org/10.3390/info17070627 - 25 Jun 2026
Viewed by 877
Abstract
Cybersecurity insider threats remain a significant challenge for modern organisations due to their potential to cause substantial financial and reputational damage. This paper presents a systematic review of insider-threat research (2019–2026) using the PRISMA methodology and introduces an empirically validated ensemble framework for [...] Read more.
Cybersecurity insider threats remain a significant challenge for modern organisations due to their potential to cause substantial financial and reputational damage. This paper presents a systematic review of insider-threat research (2019–2026) using the PRISMA methodology and introduces an empirically validated ensemble framework for insider-threat detection. The proposed approach combines User-Based Sequences (UBS), a self-supervised Transformer trained on next-token prediction and time-gap modelling, and an unsupervised anomaly detection ensemble operating on model-derived behavioural features. An answers directory is incorporated to provide grounded truth for insider entities and episodes within the CERT r6.2 dataset, enabling direct validation of detection outcomes. The framework integrates behavioural theory with machine-learning techniques to improve understanding of insider-threat precursors. Evaluation was performed using a seven-stage Isolation Forest ensemble incorporating multimodal behavioural and technical data streams. The approach successfully identified all insider users, achieving 100% recall and an AUROC of 0.93. Comparative analysis against a previously reported model showed comparable AUROC and perfect recall despite differences in evaluation methodology. While precision remained low (0.004) due to the extreme class imbalance in the full CERT r6.2 population (5 insiders among 4000 users), the results highlight the operational challenges of insider-threat detection in realistic enterprise environments. This research contributes a novel, reproducible framework that combines behavioural theory and advanced machine learning to support the detection and analysis of insider threats. Full article
(This article belongs to the Section Information Security and Privacy)
Show Figures

Figure 1

34 pages, 4546 KB  
Review
A Comprehensive Review of Event-Triggered Consensus Schemes in DC Microgrids
by Zaid Hamid Abdulabbas Al-Tameemi, Rasool Peykarporsan, Tek Tjing Lie, Ramon Zamora and Frede Blaabjerg
Energies 2026, 19(13), 2958; https://doi.org/10.3390/en19132958 - 23 Jun 2026
Viewed by 407
Abstract
This paper provides a comprehensive review of recent studies on event-triggered control schemes for DC microgrids. Several event-triggered mechanisms (ETMs) are thoroughly discussed, including static, dynamic, self-triggered, and edge-based algorithms. Considering the strengths and weaknesses of these algorithms, it is found that although [...] Read more.
This paper provides a comprehensive review of recent studies on event-triggered control schemes for DC microgrids. Several event-triggered mechanisms (ETMs) are thoroughly discussed, including static, dynamic, self-triggered, and edge-based algorithms. Considering the strengths and weaknesses of these algorithms, it is found that although such ETMs can decrease communication burden in the system, they are also susceptible to communication delays, Zeno behaviour, sensitivity to control parameter changes in triggering conditions, and inability to adapt to the fluctuating nature of renewable energy sources (RESs). Furthermore, this article examines implementation challenges, including data packet loss, quantisation effects, actuator faults, and a lack of cybersecurity measures, to provide readers with a clear vision of future trends in this field. Based on the main findings of the investigation, this review paper proposes possible areas for future research, highlighting the need for event-triggered control schemes that operate in discrete time, handle delays, and adapt to varying operating conditions. Other concepts, including adaptive control parameters for triggering conditions based on machine learning, the adoption of advanced cybersecurity measures, and data-aware transmission approaches that consider both communication frequency and total data volume, are also discussed. To conduct a comprehensive review of all the above-mentioned ETMs, several databases, including IEEE Xplore, Elsevier, and MDPI, were searched using the main keywords in this field, such as event-triggered, self-triggered, and edge-based ETMs, in conjunction with DC microgrids. This facilitated an in-depth analysis of such control schemes, including their strengths and weaknesses, providing readers with a strong basis for selecting a proper control scheme suited to their future research. Full article
Show Figures

Figure 1

46 pages, 9235 KB  
Article
Behavioural Biometrics and Session-Level Risk Monitoring for Insider Threat Detection in Enterprise Networks
by Nursultan Kuldeyev, Orken Mamyrbayev, Ainur Akhmediyarova and Assel Yerzhan
Electronics 2026, 15(11), 2400; https://doi.org/10.3390/electronics15112400 - 1 Jun 2026
Viewed by 646
Abstract
Identifying insider threats in modern enterprise environments presents a unique cybersecurity challenge. Although malicious activity may often appear to be legitimate user activity, it is difficult to recognize the distinction. This study presents an innovative approach to insider threat detection by analyzing enterprise [...] Read more.
Identifying insider threats in modern enterprise environments presents a unique cybersecurity challenge. Although malicious activity may often appear to be legitimate user activity, it is difficult to recognize the distinction. This study presents an innovative approach to insider threat detection by analyzing enterprise activity logs for session-level behavioural risk monitoring with behavioural biometrics. Behavioural patterns are modelled as temporal sequences across consecutive monitoring windows to capture both short-term behavioural intensity and long-term behavioural drift. The proposed system utilizes a hybrid deep learning architecture that includes a Long Short-Term Memory (LSTM) network and an autoencoder model to model temporal dependence of a user’s behaviour and to identify anomalies through reconstruction error analysis. The LSTM network captures user’s sequential activity and autoencoder determines variance from the user’s typical behavioural profile. The outputs of both models are aggregated using a unified behavioural risk scoring mechanism for session-level risk monitoring and ongoing insider threat assessment. The experimental results from Insider Threat Dataset for Corporate Environments demonstrate that proposed approach is effective in classifying normal versus malicious behaviours of users. The proposed framework achieves an accuracy of 97.65%, a precision of 96.35%, a recall of 99.05%, an F1-score of 97.68%, and a ROC-AUC of 99.20% on a near-balanced benchmark split. Under realistic class imbalance conditions, the framework achieves a PR-AUC of 0.842 and MCC of 0.781, representing the more operationally conservative performance estimate. These findings confirm that the proposed framework constitutes a viable solution for integrating behavioural modelling and anomaly detection within continuous enterprise authentication systems. Full article
Show Figures

Figure 1

8 pages, 2836 KB  
Proceeding Paper
Satellite Navigation in Safety-Critical Decision Making
by Wili Helenius, Hanna Kajander and Janne Lahtinen
Eng. Proc. 2026, 126(1), 48; https://doi.org/10.3390/engproc2026126048 - 13 Apr 2026
Viewed by 643
Abstract
GPS GNSS position signal manipulation in shipping can lead to significant navigational challenges. Such disruptions may result from various factors, including atmospheric conditions, satellite malfunctions, or intentional positioning satellite signal disturbance. Impacts on shipping operations include delays, increased operational costs, and safety risks [...] Read more.
GPS GNSS position signal manipulation in shipping can lead to significant navigational challenges. Such disruptions may result from various factors, including atmospheric conditions, satellite malfunctions, or intentional positioning satellite signal disturbance. Impacts on shipping operations include delays, increased operational costs, and safety risks for crews and vessels. Understanding these disturbances and their implications is crucial for enhancing maritime safety and efficiency. Common causes of GNSS disturbances in shipping include atmospheric effects such as ionospheric and tropospheric delays, satellite signal obstructions due to terrain or buildings, satellite malfunctions or failures, and intentional interference like jamming. These factors can lead to inaccuracies in positioning, affecting navigation and safety. GPS signals are vulnerable to various cyber threats, including spoofing, jamming, and signal interference. Spoofing involves sending counterfeit GPS signals to mislead receivers, while jamming disrupts the legitimate signals. Ensuring the integrity and security of GPSs is crucial for applications like navigation, timing, and critical infrastructure. Advanced encryption and authentication methods can help safeguard the security of GPS signals. These vulnerabilities can have profound implications for navigation systems and critical infrastructure. Enhancing GPS security requires a combination of advanced technologies and policies to improve signal integrity and authentication processes. The Global Positioning System (GPS) is the most widely used GNSS positioning method in commercial shipping. Moreover, deliberate disturbance technical birth mechanisms are similar across the field of GNSS systems. Therefore, this study focuses on the deliberate disturbance of the GPS, recognising the ability to upscale the research results to other commonly used GNSSs such as Beidou, Galileo, and Glonass. This paper introduces a behavioural approach to enhancing cybersecurity and preparedness to external threats in commercial shipping through European collaboration in the CyberSEA project. Full article
(This article belongs to the Proceedings of European Navigation Conference 2025)
Show Figures

Figure 1

28 pages, 1445 KB  
Article
Cost-Aware Lightweight Deep Learning for Intrusion Detection: A Comparative Study on UNSW-NB15 and CIC-IDS2017
by Marija Gombar, Amir Topalović and Mirjana Pejić Bach
Electronics 2026, 15(8), 1603; https://doi.org/10.3390/electronics15081603 - 12 Apr 2026
Cited by 3 | Viewed by 1142
Abstract
Lightweight intrusion detection systems (IDSs) are increasingly integrated into applied data science workflows for cybersecurity and process monitoring, where limited computational resources and asymmetric error costs constrain model design. This paper presents a comparative study of two lightweight deep learning IDS architectures: ForNet [...] Read more.
Lightweight intrusion detection systems (IDSs) are increasingly integrated into applied data science workflows for cybersecurity and process monitoring, where limited computational resources and asymmetric error costs constrain model design. This paper presents a comparative study of two lightweight deep learning IDS architectures: ForNet, a convolutional model optimized for feature-centric detection, and SigNet, a gated recurrent model designed for sequence-oriented modeling of ordered flow-feature representations. Both models are trained with Cost-Robust Focal Loss (CRF-Loss), a cost-aware objective that penalizes false positives and false negatives according to deployment-specific risk preferences. We evaluate the models on the UNSW-NB15 and CIC-IDS2017 benchmarks using six standard metrics (accuracy, precision, recall, F1-score, Matthews correlation coefficient (MCC), and the area under the receiver operating characteristic curve (AUROC)), complemented by an analysis of false-positive behavior. On CIC-IDS2017, ForNet achieves precision up to 0.95 and MCC up to 0.93 with AUROC above 0.94, while SigNet shows a stronger recall-oriented profile on UNSW-NB15. In an ablation study, replacing Binary Cross-Entropy with CRF-Loss reduces the false-positive rate by approximately 15–20% and improves robustness-oriented metrics such as MCC by up to 12% on CIC-IDS2017. Rather than claiming universal state-of-the-art performance, the study focuses on performance–risk trade-offs under realistic operational constraints. The results highlight how architectural bias and cost-aware optimisation jointly shape IDS behaviour and offer benchmark-based guidance for interpreting performance–risk trade-offs in lightweight intrusion detection. Full article
Show Figures

Graphical abstract

Back to TopTop