Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection meth…
Differential privacy implementations rely on precise sampling from noise distributions to provide formal privacy guarantees. We report the discovery of systematic artifacts in OpenDP's discrete Laplace sampler that manifest as periodic distortions in the output distribution. Through systematic testing, we trace these artifacts to a faulty implementation in the rational arithmetic library used by the bernoulli_exp1 f…
While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate bloc…
Quantum key distribution (QKD) links are provisioned from security analyses of stationary channels, whereas the devices that determine the channel drift between recalibrations. Whether an eavesdropper who cannot alter the channel's own noise gains by following that drift has not been quantified. Adaptive eavesdropping is posed here as a constrained Markov decision process in which the attacker selects one circuit pe…
With the increasing capabilities of Large-Language-Models (LLMs) and LLM-based agents, users are increasingly using them to solve everyday problems, such as answering e-mails or providing programming support. Existing work has extensively investigated security and privacy risks, such as prompt injections and the disclosure of sensitive data to chatbot providers. While various solutions were developed to address thes…
Open source software (OSS) ecosystems face growing threats from sophisticated supply chain attacks including typosquatting, dependency confusion, Trojan Source obfuscation, malicious build injection, and CI/CD pipeline poisoning. Existing detection approaches rely on signature-based tools and rule-based systems that struggle to generalize across attack variants and emerging threat patterns. In this paper we propose…
System calls (syscalls) record key interactions between running programs and the operating system kernel, providing fine-grained and minimally intrusive data for host-based intrusion detection systems (HIDS) deployed in cloud and other modern computing environments. However, existing methods often model syscalls in their original execution order, where sequences from different processes are interleaved, making infor…
Machine-learning Network Intrusion Detection Systems (IDS) depend on substantial labeled datasets and task-specific training, whereas Large Language Models (LLMs) detection can analyze flow records directly but incurs higher inference cost and latency, with less constrained outputs. This paper presents JEV-IDS, an open experimental general NIDS based on the Jev System One Model (SOM) to detect zero day intrusions Un…
Owing to its uniqueness, stability, and high accuracy, iris recognition has been widely applied in fields such as financial payments and public security. However, driven by continuous technological advancements, attackers increasingly forge iris features to bypass identity-verification systems. Iris presentation attack detection (IPAD) aims to distinguish bona fide iris samples from various attack iris images. Exist…
A client-agnostic reliability and security proxy for the Model Context Protocol (MCP). It provides self-healing connections with automatic reconnection, runtime tool-security (tool-definition pinning / rug-pull detection, poisoning inspection, and shadowing detection), and a compliance-mapped audit trail crosswalked to the NIST AI RMF and the OWASP Top 10 for LLM Applications.
Background: Cyberattacks continue to grow in volume and sophistication, and small-to-medium-sized organizations are increasingly exposed because of limited budgets and security personnel. Open-source Security Information and Event Management (SIEM) platforms such as Wazuh offer a low-cost alternative to commercial solutions; however, their reliance on static, rule-based correlation logic limits their ability to dete…
The rapid development of the Internet of Vehicles (IoV) has made cyberattacks targeting vehicular time-series data a critical security issue. Existing reconstruction-based detection methods mainly rely on global sequence modeling, which limits their effectiveness in highly dynamic vehicular environments and often results in missed detections of stealthy, localized attacks caused by subtle temporal variations. To add…
The adoption of Internet of Things (IoT) and Machine Learning (ML) in agriculture presents a revolutionary step toward efficient agricultural practices using data to address global issues surrounding food security. This review conducted a systematic search of the Scopus, IEEE Xplore, ScienceDirect, and SpringerLink databases for articles published between January 2023 and January 2026. It used keyword combinations l…
Modern cybersecurity controls, including endpoint detection and response platforms, malware sandboxes, CI/CD pipelines, and network-monitoring systems, already generate telemetry used in detection engineering, threat hunting, incident response, and security operations. Established approaches, including MITRE's Cyber Analytics Repository, already connect adversary behavior, required data, sensors, and detection analy…
It has become necessary to design efficient, robust, and effective Intrusion Detection Systems (IDS) amid the rising complexity of cyberattacks and the exponential growth in network traffic. In this work, we present an advanced IDS framework using comparative deep learning (in short, DL) models for precise classification and detection of all types of network intrusions. The proposed system consists of five DL models…