Articles published on Security design
Authors
Select Authors
Journals
Select Journals
Duration
Select Duration
1774 Search results
Sort by Recency
- Research Article
- 10.1038/s41598-026-55476-y
- Jun 2, 2026
- Scientific reports
- Xuwen Zhang
The deep penetration of IoT terminals in water systems, healthcare, transportation, and other fields has exacerbated security threats such as cyber-physical attacks and traffic anomalies. However, traditional anomaly detection methods have limitations such as dependence on labeled data, weak generalization ability, high resource consumption, and prominent privacy risks. Although Vision Transformer (ViT) has the advantage of capturing global features, it is difficult to directly adapt to resource-constrained IoT terminals. In existing research, hybrid deep learning models have improved detection accuracy, but lightweight ViT fusion models lack terminal adaptability and multi-modal data fusion applications are scarce. The balance between dynamic scheduling and privacy protection in end-edge-cloud collaboration still needs to be broken through. To address the above issues, this paper proposes an IoT terminal AI security anomaly detection system based on the ViT-Transformer fusion model: adopting a three-level end-edge-cloud collaborative architecture, integrating multi-modal data such as network traffic, sensor timing, and side channel signals, and achieving cross-modal feature fusion through tokenization; combining pruning, distillation, and quantization optimization strategies to increase the model compression ratio to 70%; introducing Elliptic Curve Certificateless Encryption (CL-PKE) and Batch Listing Signature (BLS) batch authentication to ensure data security, and using federated learning to aggregate edge model updates and optimize global performance. Experiments were conducted on public datasets such as IoT-23 and UCI, as well as a self-made testbed. The results show that the model achieves an accuracy of 89.2% and an F1-score of 0.87 in multi-modal anomaly detection, with a terminal inference delay of 90ms and a memory footprint of 30MB, adapting to low-computing devices such as RPi4B and Arduino; CL-PKE resists brute force attacks for 5.2e6 seconds, and batch authentication for 100 terminals takes only 75ms; it exhibits excellent generalization across smart home, industrial IoT, and other scenarios, with a defense success rate of 85.3% against FGSM attacks. This study effectively addresses the resource bottleneck and security pain points of existing methods, providing an efficient and reliable technical solution for IoT terminal security.
- Research Article
- 10.3390/electronics15112389
- Jun 1, 2026
- Electronics
- Sahil Nayak + 2 more
Collaborative driving, in which autonomous vehicles cooperate with other vehicles and roadside infrastructure to improve safety, perception, and traffic efficiency, is emerging as a key paradigm for next-generation transportation systems. While such collaboration enhances situational awareness, it also introduces new security vulnerabilities across perception, communication, planning, decision-making, and control layers. In this survey, we present a unified taxonomy of security threats and defense mechanisms in collaborative driving systems, systematically organizing attacks and countermeasures across system layers. We further examine the integration of language models, including vision-based and multimodal reasoning models, into collaborative driving pipelines, highlighting the resulting security risks and design challenges. Finally, we identify key open research challenges, including cross-layer and end-to-end security, uncertainty-aware defenses, and real-world validation, outlining promising directions for future work toward secure and resilient collaborative autonomous mobility.
- Research Article
- 10.1016/j.vehcom.2026.101023
- Jun 1, 2026
- Vehicular Communications
- Aymen Dia Eddine Berini + 8 more
• Provides an end-to-end review of UAV-NTN-based AV systems, emphasizing UAV-AV interactions within non-terrestrial networks for mission-critical services. • Analyzes key use cases (e.g., emergency response, disaster management, traffic control) and addresses operational challenges in UAV-NTN-AV integration. • Proposes a classification of security requirements (confidentiality, authentication, integrity, availability) tailored to heterogeneous NTN environments. • Critically assesses state-of-the-art security solutions-cryptographic protocols, key management, blockchain, and AI-driven intrusion detection under UAV-AV resource and mobility constraints. • Identifies open challenges and outlines future research directions, providing a roadmap for secure and resilient UAV-NTN-enabled AV systems. Non-terrestrial networks (NTNs), integrating satellites and unmanned aerial vehicles (UAVs), have become integral to next-generation communication systems, particularly in supporting mission-critical autonomous vehicle (AV) applications. UAV-assisted NTNs enhance AV operations by providing extended coverage, real-time responsiveness, and resilience in dynamic, infrastructure-limited environments. However, integrating UAVs, AVs, and NTNs introduces unique security challenges due to their heterogeneous, mobile and distributed nature. To the best of our knowledge, this paper provides the first comprehensive review of secure UAV-AV communication architectures within NTNs. First, it introduces a systematic taxonomy of security requirements and threat models specific to UAV-NTN-enabled AV ecosystems. This distinguishes our work from prior UAV-AV or NTN-only studies. Second, it consolidates and critically analyzes existing countermeasures including cryptographic techniques, blockchain mechanisms, and intrusion detection systems to assess their effectiveness, scalability, and limitations in resource-constrained, latency-sensitive contexts. Third, we propose a novel classification framework for security solutions that bridges architectural and operational perspectives. Furthermore, this work identifies unexplored challenges in resource management, network interoperability, and adaptive security in heterogeneous NTN infrastructures. It outlines future research directions involving quantum-safe cryptography, AI-enabled anomaly detection, and federated learning for privacy-preserving threat response. The finding and critical analysis provided in this paper serves as a foundational resource that guides the design of secure, scalable, and resilient UAV-NTN-AV communication architectures.
- Research Article
- 10.63503/j.ijaimd.2026.252
- May 20, 2026
- International Journal on Engineering Artificial Intelligence Management, Decision Support, and Policies
- Zinah Amer Al-Jazaeri + 1 more
Given the development of the Web of Things (WoT), cryptographic protocols are increasingly sought after that are both highly secure and utilize scarce resources. Thus, in this paper, we describe a new hybrid cryptographic algorithm, a SIMON-LEA cipher hybrid. The resulting scheme is a neutral security solution that can be applied in both software and hardware platforms. Additionally, data integrity and authentication have been achieved by the use of a secure message digest that is generated using the SHA- 256 hash algorithm. The other significant development in the structure is to feed the output of the SHA-256 into a 4D-NSJR chaotic system, which generates dynamical and nonlinear message-specific sub-keys. This is a nice way of eliminating flaws that accompany fixed key schedules and linear cryptanalysis. A rigorous test of the security of the proposed model was done using the NIST Statistical Test Suite; it passed all 15 tests at a higher P -value and avalanche effect of over 50%. It has been experimentally demonstrated that the hybrid scheme of the SIMON-LEA-SHA256 scheme achieves a 34% performance improvement and much lower memory footprint compared to the more conventional AES-128 scheme and Hybrid-SIMON-SPECKey scheme. This paper will offer a scalable and energy-saving security design for the transmission of sensitive real-time data in WoT networks by combining SHA256 integrity checking with the 4D-NSJR chaotic system to produce dynamically changing keys.
- Research Article
- 10.1186/s12913-026-14078-0
- May 16, 2026
- BMC health services research
- Hamideh Asad Allah Khan Vali + 3 more
Breast cancer is one of the leading causes of mortality among women worldwide. Telemedicine presents a promising pathway to improve cancer care delivery; however, structured approaches to systematically eliciting and integrating stakeholder requirements remain scarce. This study aimed to conduct a comprehensive needs assessment using requirements engineering principles to inform the design of a telemedicine-based follow-up system for breast cancer patients. An exploratory sequential mixed-methods design was employed, encompassing five stages: requirements elicitation, data collection, data analysis, requirements validation, and use-case development. Data were collected from 41 stakeholders-including healthcare professionals, administrative staff, patients, and caregivers-using semi-structured interviews and focus group discussions. Quantitative data were analyzed descriptively, while qualitative data underwent thematic analysis. The analysis identified three key domains of requirements-organizational, system, and stakeholder. Organizational requirements underscored the importance of leadership support, sustainable funding, and comprehensive training. System requirements emphasized security, scalability, interoperability, and user-centered design. Stakeholder needs highlighted privacy protection, accessibility, and effective communication channels. Applying a structured, stakeholder-driven requirements engineering approach enabled the identification of organizational, technical, and user needs essential for designing a telemedicine follow-up system for breast cancer. The developed framework provides a replicable model for implementing secure, scalable, and user-centered telemedicine solutions not only in oncology but also across other healthcare domains.
- Research Article
- 10.55041/ijsmt.v2i5.095
- May 5, 2026
- International Journal of Science, Strategic Management and Technology
- Sarthak Dubey + 5 more
Artificial Intelligence is transforming cybersecurity, as it is useful in detecting threats ahead of time, automated response to incidents and adaptive security designs that can handle complex cyber-attacks within the contemporary digital ecosystem. The chapter reviews new tendencies and the future perspectives of AI-based cybersecurity based on a systemic review of secondary information represented by scholarly literature on cybersecurity, industry-level cybersecurity reports, and policy frameworks. The results indicate that there is a major transformation between conventional reactive security paradigms and predictive, automated, and resilient oriented cybersecurity systems. Nevertheless, there are some major issues, such as the lack of explainability of black-box AI models, governance and ethics, adversarial AI threats, and the lack of validation in practice. The chapter suggests a conceptual framework that demonstrates how intelligence in the capabilities of artificial intelligence can be converted to intelligent cybersecurity functions and quantifiable results and ultimately lead to the resilience of digital security. The paper puts emphasis on explainable artificial intelligence, ethical governance structures, and human-in-the-loop decision-making in trust, transparency, and accountability in AI-assisted cybersecurity systems.
- Research Article
- 10.1080/07366981.2026.2660226
- May 2, 2026
- EDPACS
- Richa Vijay + 2 more
ABSTRACT The quick pace of cyber threat has revealed important vulnerabilities in conventional antivirus tools, especially because of their centralized designs, poor visibility of threats, and slow reaction to new and polymorphic malware strains. To overcome such difficulties, this paper will propose a hybrid Blockchain-Based SDN-Cloud-IoT Collaborative Antivirus Network (BCAN), which uses the decentralized and transparent nature of blockchain technology to improve security and scalability in contemporary data management network structures. Contrary to other current blockchain-based systems of cyber threat intelligence (CTI), the proposed system suggests a single cross-layer approach to deploy Software Defined Networking (SDN), IoT-edge aggregation, cloud-based analytics, and smart-contract-based implementation of trust enforcement. In the proposed model, malware signatures, threat knowledge, and response plans are distributed among the antivirus engines, security scientists, IoT apparatus, and distributed nodes in close real time. Smart contracts can be used to authenticate devices, manage trust, and access (and) blockchain can be used to guarantee integrity, immutability, and auditability of shared intelligence. To minimize the blockchain overhead and enhance the scalability, an edge level aggregation mechanism is presented allowing to optimally record the transactions without the loss of security guarantees. Extensive experimental benchmarking, detection accuracy, false-positive rate, transactions analysis and gas consumption profiling show that detection performance, response time, and blockchain overhead are better regarding centralized antivirus solutions. The findings identify the feasibility of blockchain-based collaborating security designs of the next generation of decentralized cybersecurity infrastructures.
- Research Article
- 10.3390/fintech5020038
- May 2, 2026
- FinTech
- Cristiano Wilson + 1 more
Background: Open banking (OB) is rapidly transforming financial ecosystems by enabling controlled data sharing among multiple actors through application programming interfaces (APIs). While this transformation promises innovation and competition, it also introduces complex security challenges that extend beyond purely technical considerations. Despite growing attention in academic and professional domains, existing reviews provide limited integration of security concerns with global adoption patterns and cross regional variation. Methods: This systematic review analyses empirical and conceptual research on security in OB published between 1999 and 2025, capturing early digital banking studies that later informed the development of OB. The literature is structured into three distinct phases: foundational digital banking developments, regulatory formalisation of OB frameworks, and post-implementation expansion of OB ecosystems. A comprehensive search was conducted across major academic databases and scholarly portals, complemented by relevant regulatory and policy sources. Following duplicate removal, title and abstract screening, full-text eligibility assessment, and methodological quality appraisal, 117 studies were retained for qualitative synthesis. Results: The findings reveal recurring security challenges arising from the interaction between technological infrastructures, regulatory frameworks, and user behaviour within OB ecosystems. Technical safeguards such as APIs, strong customer authentication, and encryption are necessary but insufficient when they are misaligned with regulatory implementation and user behaviour. Behavioural factors, including trust, consent understanding, and security-related decision making, play a central role in shaping ecosystem resilience. Based on this synthesis, the study develops a tri-dimensional security framework integrating technological, regulatory, and behavioural dimensions. The bibliometric analysis of 117 studies reveals that technological security dominates the literature (58%), followed by regulatory governance (44%) and behavioural dimensions (42%). However, only 17.9% of studies integrate all three dimensions simultaneously. APIs and authentication mechanisms represent the most frequent technological terms, while PSD2 and GDPR dominate regulatory discourse. Trust and decision-making are the most recurrent behavioural constructs. The relatively low proportion of fully integrated studies confirms a structural fragmentation within OB security research, thereby empirically justifying the proposed tri-dimensional framework. Chronologically, early studies (1999–2015) predominantly focused on technical security mechanisms and regulatory compliance, whereas more recent research (2020–2025) increasingly highlights the interplay between regulatory frameworks and user behaviour, suggesting a shift towards a more holistic understanding of security within OB adoption. Conclusions: This systematic review concludes that integrating technological, regulatory, and behavioural perspectives advances a more comprehensive understanding of security in OB ecosystems. The proposed tri-dimensional security framework provides a structured foundation for future research and supports policy-relevant and practice-oriented security design.
- Research Article
- 10.1109/jiot.2026.3669231
- May 1, 2026
- IEEE Internet of Things Journal
- Gaofeng Pan + 6 more
This paper investigates the internal secrecy and external covertness of a mixed-trust autonomous aerial vehicle (AAV) communication system assisted by rate-splitting multiple access (RSMA). In this setting, a semi-trusted user with partial decoding capability poses an internal eavesdropping threat, while multiple distributed wardens attempt to detect the transmission from the AAV to the semi-trusted user, creating an external covertness challenge. To characterize these security aspects, a unified analytical framework is developed. First, the internal eavesdropping capability of the semi-trusted user is quantified by deriving a closed-form expression for its eavesdropping success probability. Based on the outcome of the eavesdropping attempt, tractable expressions for the secrecy outage probability of the legitimate user are obtained. Furthermore, the external covertness performance is analyzed by deriving closed-form false alarm probability, missed detection probability, and detection error probability (DEP) for an individual warden, together with the optimal detection threshold and the corresponding minimum DEP. The cooperative global detection performance with multiple wardens is further characterized under conservative fusion rules. Extensive Monte Carlo simulations validate the analytical results and, through a joint evaluation of secrecy, reliability, and covertness metrics, illustrate the feasible operating regions enabled by RSMA power allocation in comparison with a NOMA baseline. The results provide a comprehensive theoretical basis for the design of secure and covert AAV communication strategies in mixed-trust environments.
- Research Article
- 10.64751/ajaccm.2026.v6.n2(1).489
- Apr 23, 2026
- American Journal of AI Cyber Computing Management
- Ch Jyothi + 4 more
The rapid growth of web-based applications has made secure authentication a critical requirement to protect user data from cyber threats such as Structured Query Language injection (SQLi) attacks. With the increasing reliance on digital platforms, ensuring data integrity, confidentiality, and controlled access has become essential. A major challenge arises from weak authentication implementations where improper input handling allows attackers to manipulate SQL queries and gain unauthorized access. In traditional systems, authentication is often implemented using dynamic query construction with minimal input validation, prioritizing functionality over security. Such systems fail to recognize malicious input patSterns and remain highly vulnerable to injection attacks. The limitations of these systems include unsafe query construction, weak validation techniques, lack of effective attack detection mechanisms, and insufficient focus on secure design principles, leading to risks such as data breaches and compromised system integrity. These issues highlight the need for a more secure and reliable authentication approach that balances protection with usability. To address these challenges, the proposed system introduces a Django-based application integrated with a MySQL (Structured Query Language-based relational database management system) backend, consisting of two modules: a vulnerable login module to demonstrate SQLi risks and a secured login module that applies input validation and detects suspicious patterns in user inputs. This dual-module design enables clear comparison between insecure and secure approaches. The significance of this research lies in enhancing awareness of web application security, promoting secure coding practices, improving authentication reliability, and providing a practical foundation for developing systems resistant to common cyber threats.
- Research Article
- 10.3390/info17040387
- Apr 20, 2026
- Information
- Unarine Madzivhandila + 1 more
The security of financial messaging systems is critical to maintaining trust in digital financial platforms. Despite advances in cryptography, many contemporary systems remain vulnerable to channel-based and cryptographic threats, including eavesdropping, interception, tampering, and unauthorized access. Hybrid cryptographic models that combine asymmetric encryption for secure key exchange with symmetric encryption for efficient data protection have emerged as effective approaches for strengthening confidentiality, integrity, and authenticity in financial message communications. This study presents a scoping review of literature published between 2015 and 2025, mapping research on user vulnerabilities in financial messaging systems and examining the role of hybrid cryptographic models in mitigating these risks. Guided by the PRISMA-ScR reporting standards, 615 articles were identified across nine scholarly databases. Forty-four studies met the inclusion criteria after systematic screening. The findings reveal a growing emphasis on hybrid encryption strategies, particularly RSA–AES and ECC–AES combinations, due to their balance of security strength and computational efficiency. However, significant gaps persist in empirical validation, real-world deployment, and user-centred security design, especially in mobile-first and resource-constrained environments. Existing research largely prioritizes theoretical performance and algorithmic efficiency, with limited attention to practical integration, usability, and operational constraints. This review highlights the need for holistic security frameworks that integrate cryptographic robustness with usability, regulatory compliance, and contextual deployment considerations. It provides a structured foundation for future research focused on developing scalable, user-centric, and resilient security solutions for financial messaging systems.
- Research Article
- 10.3390/e28040457
- Apr 16, 2026
- Entropy (Basel, Switzerland)
- Ruikai Miao + 6 more
Reconfigurable intelligent surface (RIS) emerges as a promising paradigm and offers a new perspective for physical layer security. In practice, imperfect eavesdropper channel state information (CSI) represents a critical challenge for RIS-aided physical layer security design. To tackle this issue, this paper investigates RIS-aided physical layer security enhancement under imperfect eavesdropper CSI and formulates a robust weighted sum secrecy rate maximization problem. To efficiently solve this problem, a model-driven deep learning approach is proposed. We begin by introducing the gradient descent-ascent algorithm to solve the optimization problem. Then we unfold this algorithm into a gated recurrent unit (GRU)-aided deep unfold network with trainable parameters. The proposed GRU-aided deep unfold network leverages GRU to adaptively generate gradient ascent-descent step sizes. Different from the existing deep unfold network that commonly has a fixed number of iteration, the proposed deep unfold network integrates the sequential learning capability of GRU and enables adaptive iteration adjustment. The simulation results demonstrate that compared to existing non-robust optimization algorithm and traditional deep unfold network with fixed number of iteration, the proposed method exhibits robustness against imperfect CSI and achieves higher weighted sum secrecy rate.
- Research Article
- 10.55041/ijsrem60150
- Apr 14, 2026
- INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
- Mr Adesh V Patil + 4 more
ABSTRACT Campus Connect is a full-stack campus social networking platform that unifies students, faculty, alumni, and administrators through a role-based digital ecosystem for communication, notice dissemination, and professional networking. Recent research on alumni portals and alumni–student interaction platforms underscores the growing need for centralized, secure, and engaging web-based systems that support mentorship, career guidance, and institutional collaboration. This paper presents the design and implementation of Campus Connect—built with React 18, TypeScript, Node.js/Express, Prisma ORM, and SQLite—and situates it within contemporary alumni and campus interaction platforms. A structured literature review of ten post-2021 works on alumni portals and interaction platforms is provided, followed by a detailed discussion of system architecture, security design, core features, and research applications. The paper demonstrates how Campus Connect operationalizes best practices identified in the literature while extending scope beyond alumni to serve the entire campus community. Keywords: Campus Social Network; Alumni Portal; Role-Based Access Control; Educational Technology; Web Application; React; Node.Js; Prisma; Sqlite.
- Research Article
- 10.1080/23249935.2026.2633638
- Mar 27, 2026
- Transportmetrica A: Transport Science
- Farahnaz Javidi-Niroumand + 3 more
Cooperative adaptive cruise control (CACC) is one of the main features of connected and autonomous vehicles (CAVs), improving safety and traffic efficiency by enabling vehicles to communicate and maintain optimal spacing. However, CACC systems are vulnerable to false data injection (FDI) attacks, which can disrupt vehicle behaviour and compromise safety. To address this vulnerability, a Lyapunov-based controller, an observer, and an attack estimator are designed to improve system performance under FDI attacks. Unlike existing secure control designs, we provided a stability analysis showing that the estimated FDI attack error is semi-globally uniformly ultimately bounded. As tuning these controller parameters is challenging yet critical, we present a testing and verification framework for tuning CACC control parameters to mitigate the impact of FDI attacks. The framework employs gradient descent (GD) optimisation to refine control parameters, minimising tracking errors and improving FDI attack estimation. Simulation results demonstrate that the proposed approach significantly enhances safe following distances and attack estimation accuracy across diverse scenarios.
- Research Article
- 10.1145/3804452
- Mar 23, 2026
- ACM Transactions on Design Automation of Electronic Systems
- Tanvir Hossain + 4 more
The shift towards decentralized microelectronics manufacturing creates significant security vulnerabilities. Untrusted partners, foundries, and testing facilities gain full design access, enabling them to inspect, reverse engineer, and compromise critical security features. Sophisticated design-for-security (DfS) primitives have been developed to counter these threats; however, this paper demonstrates that these primitives can be systematically dismantled by hardware Trojans (HT), which represent the ultimate insider threat within untrusted ecosystems. We introduce the concept of Trojan-assisted meta-attacks; a new attack paradigm in which Trojans structurally neutralize protections rather than algorithmically bypassing them. Adversaries leverage comprehensive design knowledge from supply chain access, employing advanced netlist analysis and data-flow examination to precisely identify and subvert security infrastructure. We present a unified meta-attack framework that generalizes across DfS primitives, supported by case studies on Physically Unclonable Functions (PUFs) and Dynamically Obfuscated Scan Chains (DOSC). Our systematic methodology achieves highly accurate security primitive identification through heuristic algorithms and machine learning approaches. Case studies demonstrate a complete authentication bypass through the extraction of PUF challenge–response pairs and an attack that disables DOSC protections by exploiting its deterministic structure. Together, these results show that meta-attacks constitute a broader paradigm shift in hardware security, exposing vulnerabilities across diverse DfS primitives. To address this challenge, we evaluate countermeasures that provide significant security improvements with reasonable overhead. By framing both the attacks and defenses within a unified meta-attack/defense framework, this work establishes a foundation for future research on Trojan-aware security architectures and underscores the urgent need to design protections that remain effective even under structural compromise.
- Research Article
- 10.1007/s44443-026-00658-x
- Mar 23, 2026
- Journal of King Saud University Computer and Information Sciences
- Badiea Abdulkarem Mohammed + 9 more
Security challenges and solutions in Internet of Medical Things (IoMT) communication: A review
- Research Article
- 10.58257/ijprems51527
- Mar 16, 2026
- International Journal of Progressive Research in Engineering Management and Science
This paper analyzes the interaction among a facility's Physical Protection System (PPS), response forces, and a potential adversary using a performance-based perspective.The study introduces a heuristic method to identify the most vulnerable adversary path to a target and applies a related heuristic to estimate response force movement for both onsite and offsite teams.The onsite team is modeled primarily as the interruption element, while the offsite team is treated as reinforcement with a dominant neutralization role.The approach is anchored in the detection-delayresponse logic widely used in PPS evaluation and aligns with established single-path interruption models such as Estimate of Adversary Sequence Interruption (EASI).A simulation on a hypothetical facility layout demonstrates how detector placement, delay distribution, alarm assessment reliability, and response timing jointly influence interruption outcomes.Results show that heuristic path selection enables focused resource allocation to highest-risk corridors and that response time variability materially affects interruption probability.The study concludes that integrating pathbased vulnerability identification with response optimization improves the efficiency of PPS upgrades and supports risk-informed security design.
- Research Article
- 10.3390/s26051720
- Mar 9, 2026
- Sensors (Basel, Switzerland)
- Jiayong Chai + 4 more
Cross-domain data collaboration is a core requirement for the intelligent development of critical areas such as the Internet of Vehicles and intelligent transportation systems. In this scenario, vehicles and various sensors deployed roadside continuously generate massive amounts of time-series data, yet this data often forms "data silos" due to privacy regulations and a lack of trust between collaborating entities. Existing integrated schemes combining "Federated Learning + Blockchain" have achieved a certain degree of process traceability and automated payments, but risks of gradient-level privacy leakage persist, and inflexible and delayed incentive mechanisms result in low participation quality. To systematically address these bottlenecks, this paper proposes the Federated Learning with Assured Privacy and Reputation-Driven Incentives (FLARE) architecture, whose core innovation lies in the native integration of cryptographic security and mechanism design theory. It includes the Secure and Faithfully Executed Gradient aggregation (SafeGrad) protocol, which integrates partial homomorphic encryption and zero-knowledge proofs to provide verifiable privacy guarantees for gradient contributions while enabling efficient secure aggregation, defending against inversion attacks at the source; alongside this, it includes the Economy-on-Chain incentive (EconChain) mechanism, which designs an on-chain economic system based on blockchain, achieving precise measurement and sustainable incentivization of training process contributions through fine-grained instant micro-rewards and a dynamic reputation model. Experiments show that, compared to baseline schemes, FLARE can effectively enhance node participation enthusiasm and contribution quality without compromising model accuracy, providing a new paradigm with both strong security and high vitality for the trusted and efficient circulation of data.
- Research Article
- 10.1142/s1793351x26410059
- Mar 1, 2026
- International Journal of Semantic Computing
- Julia Gomez-Rangel + 4 more
The rapid rise of large language models (LLMs) has driven their widespread adoption, especially as the core component of open-source applications, which we refer to as LLM-Powered Apps (LPAs). Despite the rapid growth of this ecosystem, little is known about how these applications are built in the open-source world, especially in terms of their architectural and design decisions, deployment strategies, and security practices, which remain poorly understood. In this paper, we conduct a comprehensive empirical study of 89 popular open-source LPAs on GitHub, with the goal of characterizing their design choices and identifying common security and safety concerns. We systematically collect a set of architectural and operational attributes, classify each LPA by its primary purpose and analyze how functionality influences architectural and security design. Our findings reveal dominant design patterns as well as recurring risks, such as inadequate access control, lack of telemetry transparency, and design assumptions that break down in complex runtime environment. We also conducted an in-depth study of 376 GitHub issues from two popular LPAs and two LIFs developed in open-source communities. We summarize the root causes of the GitHub issues by creating a taxonomy of three themes based on the software development life-cycle. By surfacing these trends and vulnerabilities, our study provides a foundational understanding of how LPAs are currently built and deployed in the open-source ecosystem as well as the recurring issues and pitfalls for developing and maintaining LPAs. The results offer practical insights for developers, researchers, and platform maintainers seeking to build more robust and secure LLM-integrated software systems. Furthermore, we propose a set of guideline for the secure use of API keys, encapsulated within a pre-commit hook and a GitHub Action workflow for easy integration into new and existing GitHub projects using API keys.
- Research Article
1
- 10.1016/j.cose.2025.104762
- Mar 1, 2026
- Computers & Security
- Wanling Cai + 5 more
• This review provides an overview of current human-centered studies on smart home security, helping researchers and practitioners to better navigate this field. • We present a conceptual framework that outlines key challenges in ensuring smart home security together with a synthesis of insights on contributing human factors. • The paper provides a summary of general security design principles and existing user-centered security approaches in smart homes, and highlights research directions for future investigation. Smart home technologies, like cameras, door locks, and speakers, are increasingly used in our everyday lives. However, their continuous data collection and internet connectivity pose various security risks. While research on smart home security has mainly focused on technological aspects, human experience and societal factors also play a crucial role. Various human and social factors, such as user experience with smart home devices, security design processes, and government regulations, are intertwined and influence each other, affecting smart home security. It is therefore important to understand and consider these interconnected factors in technology design to secure homes that contain increasingly connected devices. This scoping review provides an overview of current human-centered studies (N=102) on smart home security, which aims to help researchers and practitioners better navigate this field. We present a conceptual framework that outlines key challenges in ensuring smart home security with a synthesis of insights on contributing human factors. We then summarize general security design principles and map existing user-centred security approaches in smart homes, and highlight research directions for future investigation. Beyond mapping existing studies, the review reveals a growing emphasis on engaging multiple stakeholders, especially smart home users, in shaping human-centered security.