<?xml version="1.0" encoding="utf-8"?>
    <rss version="2.0">
      <channel xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <title>Frontiers in Computer Science | Computer Security section | New and Recent Articles</title>
        <link>https://www.frontiersin.org/journals/computer-science/sections/computer-security</link>
        <description>RSS Feed for Computer Security section in the Frontiers in Computer Science journal | New and Recent Articles</description>
        <language>en-us</language>
        <generator>Frontiers Feed Generator,version:1</generator>
        <pubDate>2026-07-21T15:52:32.162+00:00</pubDate>
        <ttl>60</ttl>
        <item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1867907</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1867907</link>
        <title><![CDATA[Fine-grained continuous user authentication via mouse grip pressure biometrics]]></title>
        <pubdate>2026-07-17T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Xiang Zou</author><author>Jingbo Wang</author><author>Yanqiu Liu</author><author>Jiali Wu</author><author>Guangjun Liu</author>
        <description><![CDATA[Computers have become indispensable tools in modern society and they often serve as repositories for large amounts of private and confidential information in public. User authentication is therefore a fundamental mechanism for protecting device security and user privacy. Traditional authentication methods such as passwords are not tightly bound to user identity and impose a significant memory burden, which has motivated the widespread adoption of biometric-based authentication approaches, such as fingerprint and facial recognition. However, fingerprint- and face-based authentication typically requires additional hardware support and can be vulnerable to interception by ultra-high-definition cameras, raising serious privacy concerns. To solve these problems, this paper proposes a fine-grained and continuous user authentication method based on mouse grip pressure biometrics. By deploying resistive pressure sensors on the surface of a mouse, we capture individualized pressure distribution patterns generated during natural mouse gripping. To further enhance discriminative capability, we refine the sensor contact layout to improve spatial feature resolution. Moreover, we introduce a layered representation for omnidirectional pressure signals to mitigate sensitivity to grip direction variations. Extensive experimental results demonstrate the effectiveness of the proposed system, achieving the FAR below 0.1% and the FRR below 0.4%. These results indicate that mouse grip pressure constitutes a highly discriminative and robust biometric modality for continuous user authentication.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1886719</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1886719</link>
        <title><![CDATA[Real-time saliency-guided deep watermarking on Kria KV260: a Vitis AI accelerated proxy architecture]]></title>
        <pubdate>2026-07-16T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Mehmet İrfan Gedik</author><author>Aysun Coşkun</author>
        <description><![CDATA[The rapid growth of Industrial Internet of Things (IIoT) ecosystems and autonomous surveillance networks has necessitated the shift of digital content security from central servers to the data-generating edge. In industrial security scenarios, operators must continuously monitor live video streams and optionally capture high-resolution, verifiable evidence snapshots. However, high computational costs and hardware-based precision losses prevent the real-time execution of deep learning-based watermarking models on resource-limited embedded devices. This study proposes a hardware-aware and semantically oriented real-time watermarking architecture running on the Xilinx Kria KV260 FPGA platform. The fundamental innovation of the proposed system is the asynchronous “Proxy Frame” software architecture, which allows heavy Convolutional Neural Networks (CNNs) to run in the background, isolated from the live video stream. Thus, highly secure watermarking can be performed at 1080p resolutions without compromising the fluidity of the 30 FPS live preview offered to the operator. Furthermore, a Noise-Assisted Dithering technique, inspired by stochastic resonance, was used to mitigate the “Signal Fading” problem arising from watermark signal loss during 8-bit integer (INT8) quantization on the Deep Learning Processing Unit (DPU). By injecting controlled Gaussian noise into the quantized inference pipeline, the detectability of subthreshold weak watermark signals was increased, reducing the hardware Bit Error Rate (BER) from 18.75% to 13.06%. MobileNetV2 and ResNet50-FCN based saliency models achieved an average PSNR visual quality of 39.86 dB by concealing the payload in perceptually insignificant regions. Under clean hardware conditions, the system achieved a baseline BER of 2.6% (with MobileNetV2). In attack tests, the BER remained below 15% for MobileNetV2 under most standard degradations, with the stated exceptions of severe JPEG compression and deliberate geometric cropping. This end-to-end hardware and software solution demonstrates that theoretical deep learning models can be integrated into industrial smart cameras without experiencing performance bottlenecks, particularly for static infrastructure monitoring.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1871563</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1871563</link>
        <title><![CDATA[FBR-PAEKS: revocable public-key authenticated keyword search with forward privacy for dynamic cloud environments]]></title>
        <pubdate>2026-07-15T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Mishal Ismaeel</author><author>Ali Raza</author>
        <description><![CDATA[This study presents Forward-private and Binary-tree-Revocable PAEKS (FBR-PAEKS), a public-key authenticated encryption with keyword search scheme for secure multi-user cloud environments that integrates forward privacy and cryptographic revocation in a single construction. The proposed scheme supports expressive keyword search policies represented by linear secret-sharing schemes (LSSS), enabling flexible AND, OR, and threshold-based queries over encrypted indexes. FBR-PAEKS integrates a binary-tree-based revocation mechanism using the complete-subtree algorithm KUNode, an epoch-bound one-way state evolution chain for forward privacy, and a deletion-tag filter for logical document deletion. To resist insider keyword-guessing attacks by the cloud server, the construction introduces a sender–receiver shared element derived from the Diffie–Hellman value of their secret keys. Furthermore, the receiver's epoch secret is embedded into the trapdoor exponent to prevent current-state compromise from exposing past search information. We formalized the security of the scheme through ciphertext indistinguishability, resistance to insider keyword guessing, revocation unforgeability, forward privacy under state compromise, and trapdoor integrity. The security reductions are established under the CDH, mDLIN, PRF, one-wayness, and signature unforgeability assumptions in the random oracle model. Theoretical and practical evaluations show that FBR-PAEKS achieves strong security and expressive search functionality with competitive performance compared with existing PAEKS schemes.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1860652</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1860652</link>
        <title><![CDATA[IIDS: a light-weight interpretable intrusion detection system for network infrastructures]]></title>
        <pubdate>2026-07-14T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Asadullah Momand</author><author>Sana Ullah Jan</author><author>Naeem Ramzan</author>
        <description><![CDATA[Network security remains a critical challenge in today's interconnected world, where effective intrusion detection is essential for safeguarding sensitive infrastructure, including financial, medical, and governmental systems. Existing intrusion detection systems (IDS) often lack interpretability, preventing security personnel from gaining clear insights into detected anomalies and impeding timely, informed decision-making. Moreover, the growing complexity of networks demands an adaptable IDS capable of identifying diverse intrusion types, such as overflow, black hole, or diversion across varied environments, while minimizing false positives and computational overhead. To address these issues, this study proposes an interpretable intrusion detection system (IIDS) that leverages an ensemble learning approach integrating an attention-based convolutional neural network (CNN), long short-term memory (LSTM), and an interpretable random forest (RF) algorithm. The CNN and LSTM components extract spatial and temporal features from network traffic. At the same time, the RF enhances transparency by providing decision trees that elucidate the model's reasoning, enabling security teams to understand and trust the predictions. When evaluated against other methods, the proposed IIDS achieves optimal performance with an accuracy of 99.00% and an F1-score of 99.00%, outperforming other models on benchmark datasets.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1860123</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1860123</link>
        <title><![CDATA[Quantum-ready IoMT architecture for chest X-ray imaging with lightweight CNN and hybrid chaos-DNA encryption]]></title>
        <pubdate>2026-07-09T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Altahir Saad Ahmed</author><author>Ali Raza</author><author>Abed Saif Alghwali</author><author>Suzan Hassan Bakhit</author><author>Muhammad Farman</author>
        <description><![CDATA[This study presents a complete quantum-aware Internet of Medical Things (IoMT) framework for secure medical imaging that integrates lightweight edge diagnostics, quantum key distribution, and hybrid image encryption. At the edge layer, MicroRadNet, an ultra-compact convolutional neural network (CNN) with exactly 3,140 trainable parameters, is deployed on a Raspberry Pi Zero 2 W, achieving 98.24% accuracy on chest X-ray classification with INT8 quantization. This reduces the model size to 3.14 KB and yields inference latency that meets real-time constraints. At the communication layer, a gateway-mediated BB84 protocol executed on Amazon Braket generates session keys via Golay [24, 12, 8] reconciliation (correcting up to t = 3 errors per codeword) and privacy amplification, producing 256-bit keys with quantum bit error rate (QBER) < 0.02. At the image-protection layer, a hybrid cipher combines 5D hyperchaotic permutation (seeded from BB84 key material), fixed-rule DNA encoding, and quantum-keyed diffusion. Security evaluation demonstrates near-ideal entropy, strong NPCR and UACI values, uniform ciphertext histogram distribution, low directional adjacent-pixel correlations, low average absolute correlation, large key space, high plaintext sensitivity, high key sensitivity, and stable chaotic-sequence randomness. These results provide empirical statistical validation of resistance to common statistical, differential, brute-force, and key-sensitivity attacks. End-to-end latency remains below the 1.5 s system constraint, validating practical edge deployment. The framework replaces classical public-key dependency with simulation-validated quantum-aware foundations while maintaining clinical accuracy and real-time performance, establishing a path toward deployable, standards-aligned quantum-aware healthcare security.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1873568</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1873568</link>
        <title><![CDATA[Adversarial attacks detection for network intrusion detection systems using outlier-filtered principal component analysis]]></title>
        <pubdate>2026-07-08T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>N. Dhinakaran</author><author>S. Anto</author>
        <description><![CDATA[Cybersecurity frameworks are increasingly incorporating machine learning-based Intrusion Detection Systems (IDS) into their security measures. Despite the effectiveness of these systems, they remain susceptible to different forms of attacks that take advantage of their operation; specifically, those that are designed to circumvent their protective mechanisms. For example, modifications made to network traffic can produce “adversarial samples,” which are designed to go undetected. To tackle this issue, two systems based on Principal Component Analysis (PCA) have been proposed for spotting adversarial samples: Standard Principal Component Analysis (SPCA) and Outlier Filtered Principal Component Analysis (OFPCA). SPCA identifies the basic structure of normal network traffic through principal components and detects adversarial attacks by looking at reconstruction errors. A sample is projected onto the principal components and then reconstructed in the original space. The difference between the original and reconstructed features is the reconstruction error. Larger errors can indicate manipulation. OFPCA, on the other hand, is trained only on normal samples after removing outlier data points from the training set. When testing SPCA method using the NSL-KDD dataset, it achieved an AUC-ROC score of 0.97 in detecting FGSM adversarial samples. OFPCA had a higher AUC-ROC score of 0.99 in identifying FGSM adversarial samples. OFPCA performed better than SPCA and other techniques, when tested under different adversarial attacks.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1865398</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1865398</link>
        <title><![CDATA[Network-aware communication-efficient fingerprint representation for resource-constrained IoT systems]]></title>
        <pubdate>2026-06-24T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Ibrahim Alameri</author><author>H. I. Wahhab</author><author>Tawfik Al-Hadhrami</author><author>Sultan Noman Qasem</author>
        <description><![CDATA[Biometric authentication with Internet of Things (IoT) systems is constrained by low data bandwidth, packet size, and energy capabilities. The transmission of raw biometric data exceeds the maximum transmission unit (MTU) size of traditional IoT standards (e.g., IEEE 802.15.4), resulting in large packet fragmentation and a high frame collision probability. We present a network-aware payload optimization method to minimize the application layer payload. thereby reducing airtime (channel occupation time) and improving spectrum efficiency. By using skeleton bitmaps and minutiae vectors, the size of the data is decreased by 70%–98% compared with raw images. A smaller payload reduces the protocol header overhead and ARQ for lost packets in lossy wireless environments. We introduce a distributed edge computing architecture for offloading data-intensive tasks from the core network to the network edge, thereby reducing backhaul traffic. Performance tests with a network simulator (NS-3) in Wi-Fi 6 (IEEE 802.11ax) and IEEE 802.15.4 scenarios reveal that transmission times are significantly reduced from 420–520 to 150–190 ms and energy consumption from 110–160 to 65–95 mJ by reducing the payload size from 120 to 35 kB or even further down to 2.4 kB. These results indicate that network-aware, communication-efficient biometric data representations enable scalable and energy-efficient IoT authentication. This strategy emphasizes the importance of minimizing transmitted data volume through network performance metrics in limited wireless scenarios. The results provide architectural guidelines for designing secure and low-latency biometric-based authentication systems in smart homes, healthcare monitoring, and industrial IoT applications, emphasizing network-centric optimization for resource-constrained IoT networks.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1837023</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1837023</link>
        <title><![CDATA[The human firewall effect training and awareness as drivers of phishing mitigation and reporting behavior]]></title>
        <pubdate>2026-06-19T00:00:00Z</pubdate>
        <category>Brief Research Report</category>
        <author>Omar Osman Haji Abdi</author><author>Ali Abdi Jama</author><author>Abdirahman Ibrahim Abdi</author>
        <description><![CDATA[Phishing attacks remain a major cybersecurity threat, particularly in environments where human factors play a critical role in system vulnerability. While organizations widely implement information security training and awareness programs, evidence on their effectiveness in promoting protective behavior remains inconsistent. This study examines the relationships among information security training, security awareness, phishing threat mitigation behavior, and reporting behavior within humanitarian organizations operating in Mogadishu, Somalia. A quantitative cross-sectional design was employed, and this study is presented as a Brief Research Report to provide concise and focused empirical evidence on these relationships. Data were collected from 121 employees using a structured questionnaire, and Partial Least Squares Structural Equation Modeling (PLS-SEM) was applied to analyze the proposed relationships. The results show that information security training significantly enhances security awareness and reporting behavior but does not directly influence phishing threat mitigation behavior. Security awareness emerged as the strongest predictor of both mitigation and reporting behaviors. Furthermore, mediation analysis revealed that security awareness fully mediates the relationship between training and mitigation behavior and partially mediates the relationship between training and reporting behavior. These findings highlight the importance of human-centered cybersecurity strategies, emphasizing continuous awareness-building rather than reliance on traditional training alone. The study contributes to theory by clarifying the role of awareness as a behavioral mechanism and provides practical implications for strengthening organizational resilience in fragile and resource-constrained contexts.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1818033</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1818033</link>
        <title><![CDATA[Using WCS-GNB for intrusion detection: improving Gaussian Naive Bayes with class-specific weights and validating against different machine learning models]]></title>
        <pubdate>2026-06-02T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Sudhindra B. Deshpande</author><author>P. Balachandra</author><author>Priyank Desai</author><author>Goh Kah Ong Michael</author><author>M. R. Chowdappa</author><author>Pratijnya Ajawan</author>
        <description><![CDATA[The increasing number of cyber threats demands a robust, real-time detection system that can accurately classify attacks while maintaining computational efficiency in real-time and within reasonable resource limits. Most real-time applications in cybersecurity still rely on traditional machine learning methods with arbitrary configurations due to the difficulty in resolving the trade-off between accuracy and speed within the system. This work proposes a modification to the standard Gaussian Naive Bayes (GNB) classifier, utilizing the Weighted Classification Strategy (WCS-GNB), to enhance the real-time detection of cyberattacks evaluated under simulated streaming conditions on commodity CPU hardware. It aims to address the limitations of traditional probabilistic classifiers as applied in cybersecurity. The WCS-GNB model seeks to preserve the detection accuracy of the model while incorporating class-dependent scaling and traditional Bayesian approaches through a formally derived log-posterior extension of the standard GNB framework. The methodology is evaluated on NSL-KDD and CICIDS2017, which consists of class-specific variance scaling and symmetric Bayesian inference on streaming network data with adaptive feature weighting systems. The proposed WCS-GNB model achieved a detection accuracy of 94.3% with a processing time of 2.9 ms, significantly outperforming the traditional GNB (85.2% accuracy) and competing with complex methods like Random Forest (91.7%), while maintaining a superior processing speed. The WCS-GNB model demonstrated robust performance across various attack types, including DDoS (96.2%), DoS (97.3%), Port Scanning (92.8%), Web Attacks (94.1%), and Botnet activities (89.5%). Throughput reaches ≈8.5 k records/s on commodity hardware. All performance improvements are confirmed statistically significant via paired t-tests (p < 0.05, Bonferroni-corrected) with large effect sizes (Cohen’s d ≥ 0.52). These results indicate WCS-GNB offers a practical, interpretable, and deployment-ready IDS core for high-throughput environments. The WCS-GNB approach successfully connects the gap between accuracy and efficiency in real-time cybersecurity apps. The integration of weighted features and class-specific scaling provides a practical solution for high-throughput network monitoring, while also maintaining the interpretability advantages of Bayesian methods.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1821417</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1821417</link>
        <title><![CDATA[Machine learning-based malicious URL detection using feature selection techniques and WHOIS features]]></title>
        <pubdate>2026-05-28T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Lokesh Khedekar</author><author>Suvarna Pawar</author>
        <description><![CDATA[In today's cybersecurity landscape, malicious Uniform Resource Locators (URLs) continue to pose a serious threat, as they can be used to deliver malware, phishing, and unauthorized data access, all of which can result in significant financial and reputational losses. Innovative, data-driven methods must be developed because traditional detection methods, such as blacklisting and rule-based detection, cannot detect newly created, obfuscated, and temporary URLs. We aimed to create a consistent method for detecting malicious URLs by analyzing both the characteristics of the URL and the information collected from the WHOIS database for that URL. We utilized five different feature selection methods to identify the best features from 5,000 URLs (malicious or benign) so we could test how they would classify using five different types of machine learning (ML) classifiers: random forest, logistic regression, support vector machine (SVM), naive bayes, and k-nearest neighbor (KNN). The classification methods were Random Forest Feature Importance, Chi-squared, mutual information (MI), L1-lasso, and recursive feature elimination (RFE). The feature selection method that produced the best results for KNN classification was RFE, achieving an F1 Score of 0.988, an accuracy rate of 0.988, and an area under the curve (AUC) of 0.996. We also examined how the inclusion of WHOIS attributes (i.e., domain age, registration date, and privacy) affected the classifiers' ability to perform correct classification. From the experimental results, we see a significant improvement in accuracy, precision, recall, and F1-measure when we include features extracted from WHOIS data. Therefore, WHOIS domain registration details are highly significant when distinguishing between legitimate and malicious websites. Furthermore, we did an extensive exploration of 25 distinct combinations of feature selection methods and ML models. The proposed methodology is a safe, efficient, and interpretable way of detecting malicious domains. Cybersecurity practitioners can design more effective prevention models by leveraging insights from our research (e.g., on model selection, feature importance, and the utility of WHOIS attributes), thereby setting the stage for future research in ML-based cybersecurity methodologies.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1800175</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1800175</link>
        <title><![CDATA[Distributed verification of security events in IIoT networks using low-latency blockchain consensus assisted by artificial intelligence]]></title>
        <pubdate>2026-05-19T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Iván Ortiz-Gárces</author><author>Pablo Palacios</author><author>Javier Guaña-Moya</author><author>William Villegas-Ch</author>
        <description><![CDATA[Security in Industrial Internet of Things (IIoT) networks faces structural limitations when threats are generated concurrently by distributed, heterogeneous nodes. Current systems, whether local or centralized, even when employing advanced artificial intelligence models, produce alerts whose overall validity cannot be verified. At the same time, existing blockchain solutions are primarily used as passive logging mechanisms, introducing latencies incompatible with industrial requirements. This work addresses this gap through a distributed security event verification architecture that integrates AI-based detection with a blockchain consensus mechanism explicitly optimized for low latency. The AI models generate events enriched with a continuous suspicion score, which are evaluated by a set of independent validators and resolved using Byzantine-fault-tolerant, permissioned consensus. The experimental evaluation is performed using widely adopted open IIoT datasets, supplemented by a dataset designed for model validation and consensus processes under controlled load and disagreement conditions. The results show that consensus maintains average latencies below 100 ms and within the 95th percentile range under operational loads, with validation rates exceeding 700 events per second before saturation. Additionally, the event acceptance rate remains stable despite increased workloads, demonstrating that consensus does not amplify detection errors.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1780315</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1780315</link>
        <title><![CDATA[Cybersecurity knowledge, perspectives, and challenges: insights from a diverse focus group]]></title>
        <pubdate>2026-05-19T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Kiranbir Kaur</author><author>Kuljit Kaur Chahal</author>
        <description><![CDATA[With the significant increase in demand for Internet-based resources, the number of threats to users’ security and privacy has also increased. Users face online money fraud, cyberbullying, cyberstalking, and online identity theft. Cybersecurity researchers are continually uncovering new threats and their mitigation strategies. In this paper, we present a qualitative study to identify technological challenges, their perspectives, and factors that act as barriers to cyberspace adoption by users of different age groups in India. Five focus group discussion sessions were held with children (senior secondary school students), graduates (university students), postgraduates (university students), senior citizens (older adults), and social activists (mixed-age group). Cybersecurity knowledge, awareness, and perceptions among diverse groups were discussed using a semi-structured question guide. Discussions were documented through a detailed manual note-taking process. Then, the notes were coded and analyzed thematically using an inductive coding process. Some key themes that emerged included diverse internet use, security and privacy concerns, dominance of social media, fear and avoidance, technology illiteracy, challenges with online transactions, and so on. After analyzing, it is clear that participants are not very aware of the cybersecurity and privacy consequences of their activities in cyberspace. Future initiators should focus on integrating cybersecurity education, awareness programs, and promoting a cyber-safe culture among diverse age groups of users. Thus, this research has implications for cybersecurity researchers, educationists, and policymakers.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1770179</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1770179</link>
        <title><![CDATA[Beyond data sharing: enhancing IoT intrusion detection with blockchain-enabled federated learning]]></title>
        <pubdate>2026-05-04T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Aditya Durgadas Naik</author><author>Raj Mani Shukla</author>
        <description><![CDATA[Federated learning (FL) is a decentralized machine learning (ML) approach that can be used for intrusion detection in Internet of Things (IoT) devices. It involves the local training of AI models and their aggregation at a central server. This methodology eliminates the need for data sharing between IoT devices while fostering collaborative model improvement. Nonetheless, concerns arise from the lack of transparency regarding the shared local models and the aggregation techniques employed. This lack of transparency can potentially lead to model poisoning attacks and hinder collaborators from using alternative aggregation methods that better align with their specific use cases. To address this issue, this study proposes a blockchain-based approach using FL to ensure transparent, immutable records of model updates, thereby bolstering security and trust for intrusion detection in IoT devices. In contrast to traditional synchronization- or periodic-update-based approaches, this study proposes a novel time-independent aggregation method for FL blockchain, enabling greater flexibility. Furthermore, the proposed blockchain allows various users to utilize their own aggregation methods, rather than a fixed one, based on their needs, resources, and availability. We also developed a user interface for the proposed blockchain system to visualize various aspects of the method, such as model aggregation. The proposed system is tested using traditional metrics, such as AI model performance, as well as extensive user testing.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1832170</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1832170</link>
        <title><![CDATA[Editorial: Reliable and secure system software in emerging cloud and distributed environments]]></title>
        <pubdate>2026-04-08T00:00:00Z</pubdate>
        <category>Editorial</category>
        <author>Xiaoguang Wang</author>
        <description></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1779065</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1779065</link>
        <title><![CDATA[From risk to resilience: addressing cybersecurity threats in Brazil’s government digital transformation]]></title>
        <pubdate>2026-03-26T00:00:00Z</pubdate>
        <category>Perspective</category>
        <author>Bruno Baranda Cardoso</author>
        <description><![CDATA[This chapter analyzes Brazil’s journey in consolidating a resilient digital ecosystem in the public sector, covering both the advances and challenges faced in implementing the National Digital Government Strategy (ENGD). It first addresses the varying degrees of digital maturity among government bodies and agencies, highlighting the inequalities and factors contributing to the fragmentation of the technological environment within the government. Next, it discusses the urgent need to shift from a predominantly reactive posture to a proactive approach in managing cyber risks, emphasizing the importance of a culture of prevention and continuous training of public agents. Finally, it underscores the strategic role of public technology companies, which act not only as facilitators of digital transformation but also as key players in threat identification, comprehensive risk assessments, and the consolidation of cyber protection mechanisms within the Brazilian State.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1762332</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1762332</link>
        <title><![CDATA[Explainable AI: enhancing decision-making in the detection of cyber threats]]></title>
        <pubdate>2026-03-20T00:00:00Z</pubdate>
        <category>Review</category>
        <author>P. W. C. Prasad</author><author>Md Shohel Sayeed</author><author>Duc-Man Nguyen</author><author>Daniel Patricko Hutabarat</author><author>Golam Md Mohiuddin</author>
        <description><![CDATA[The rapid growth of the Internet and the increasing reliance on digital systems have significantly expanded the global digital footprint, creating new challenges for cybersecurity. Artificial Intelligence (AI) technologies, particularly Machine Learning (ML) and Deep Learning (DL), have become central to addressing these challenges by enabling the automation of complex and data-intensive tasks across antivirus solutions, intrusion prevention systems, threat intelligence platforms, and email security tools. While these technologies provide high levels of accuracy in detecting anomalies, malware, and other forms of malicious activity, they are often criticized for operating as “black-box” systems. The lack of interpretability in their decision-making processes limits the ability of cybersecurity professionals to fully understand, validate, and trust the outcomes of AI-driven models, thereby restricting their practical adoption in high-stakes environments. To mitigate these limitations, Explainable Artificial Intelligence (XAI) has emerged as a promising paradigm that aims to make AI outputs transparent, interpretable, and actionable. By providing human-understandable explanations of automated decisions, XAI can bridge the gap between technical performance and practitioner usability, enabling analysts to make informed decisions, improve incident response, and strengthen organizational resilience against both known and emerging threats. This paper reviews recent state-of-the-art developments in XAI for cybersecurity, with a particular emphasis on anomaly detection a critical area for identifying insider threats, zero-day exploits, and atypical system behavior. The review follows a structured literature analysis of peer-reviewed studies published between 2018 and 2025, identified through systematic searches in major academic databases including IEEE Xplore, Scopus, Web of Science, and ACM Digital Library. After applying predefined inclusion and exclusion criteria focused on XAI applications in cybersecurity, 53 relevant studies were analysed to synthesize methodological trends, application domains, and evaluation practices. Drawing on these findings, the paper consolidates fragmented research contributions, identifies current gaps, and provides recommendations for advancing the design and adoption of explainable, trustworthy AI systems in cybersecurity. The analysis further highlights a critical deployment challenge: the integration of explainability mechanisms often introduces trade-offs between predictive accuracy, computational efficiency, and real-time scalability factors that are essential in operational cybersecurity environments.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1735253</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1735253</link>
        <title><![CDATA[RoLLMRec: a robust LLM-based recommender system for defending against shilling and prompt injection attacks]]></title>
        <pubdate>2026-03-12T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Sarama Shehmir</author><author>Rasha Kashef</author>
        <description><![CDATA[Large Language Models (LLMs) are increasingly being integrated into recommender systems, offering contextual reasoning, cross-domain adaptability, and natural language interaction. However, their adoption also introduces vulnerabilities such as prompt injection, semantic poisoning, and shilling attacks, which can distort recommendations and erode user trust. Addressing these risks is essential for the safe deployment of LLM-based recommenders. We propose RoLLMRec, a defense oriented architectural framework and evaluation methodology for LLM-based recommender systems that integrates prompt filtering, retrieval augmented grounding, trust aware scoring, and an auditing feedback loop. RoLLMRec improves robustness under the evaluated prompt level and semantic adversarial settings, while multimodal support is included at the architectural level only and is not empirically evaluated in the current experimental setup.RoLLMRec unifies five core components: (1) prompt shielding and input filtering to detect and block adversarial instructions; (2) retrieval-augmented generation to enrich factual grounding and reduce hallucination; (3) multimodal LLM encoding for text, metadata, and image inputs; (4) trust-aware scoring and Top-K ranking; and (5) adaptive feedback loops for continual learning. Evaluations on benchmark datasets such as Yelp, MovieLens, and Amazon Books show that RoLLMRec surpasses BERT4Rec, RecVAE, and LightGCN, improving NDCG@10 and HR@10 by up to 6% and 5%, respectively. Under a 10% prompt-injection attack, it maintains a Robust Hit Rate (RHR@10) above 0.63 and a Perturbation Sensitivity Index (PSI) below 0.135, achieving 15%–25% higher resilience. It also sustains a Semantic Stability Score (SSS) above 0.60 in zero-shot cross-domain transfer, confirming stable semantic intent.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1751284</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1751284</link>
        <title><![CDATA[Machine learning-based early incident detection system in a bakery plant’s industrial network: a cognitive model for counteracting hybrid threats]]></title>
        <pubdate>2026-03-02T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Gulshat Amanzholovna Amirkhanova</author><author>Dmytro Ihorovych Prokopovych-Tkachenko</author><author>Saltanat Almykhametovna Adilzhanova</author><author>Nazar Zubchenko</author><author>Liya Erbolkyzy Bektemir</author>
        <description><![CDATA[IntroductionIn the context of growing cyber risks to critical industries, including bakery complexes, this paper proposes a cognitive architecture for early incident detection in the operational technology (OT) network.MethodsThe architecture integrates User and Entity Behavior Analytics (UEBA), a Security Information and Event Management (SIEM) system, and Zero Trust principles, focusing on hybrid threats: from external attacks on industrial controllers, such as programmable logic controllers (PLCs) to internal operator errors. At the analytics layer, two complementary deep learning pipelines are used: a convolutional neural network (CNN) + long short-term memory (LSTM) (CNN + LSTM) model for detecting low-level network patterns (Byte2Image) and an autoencoder (AE) combined with LSTM (AE + LSTM model) for predicting time-series data and identifying anomalies in equipment telemetry. An adaptive threshold decision procedure is introduced for the first time, optimizing both accuracy and computational resources on edge nodes. The architecture complies with the IEC 62443 and ISO/IEC 27019 standards.Results and discussionHigh performance metrics, specifically Precision, were demonstrated in the bakery plant’s digital twin scenarios.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1669659</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1669659</link>
        <title><![CDATA[A secure authentication scheme for smart home environments: a biometric-driven approach]]></title>
        <pubdate>2026-02-27T00:00:00Z</pubdate>
        <category>Original Research</category>
        <author>Zahra M. Rajeh</author><author>Sharaf A. Alhomdy</author><author>Fursan Thabit</author><author>Khawla A. Maodah</author>
        <description><![CDATA[A smart home represents an emerging technological revolution. Devices such as smart TVs, smart refrigerators, and smart locks are connected to the Internet to enhance convenience in daily life. However, users contact these smart home devices via public channels, which makes the data being transferred vulnerable to attacks. Ensuring the privacy and data security of home users becomes a significant challenge. As smart home systems become increasingly integrated into our daily routines, securing them is crucial. This study presents a lightweight authentication scheme for smart homes. It combines biometric data (OTIC) with cryptographic techniques. The goal is to achieve robust security while maintaining minimal computational overhead. The scheme allows mutual authentication among users, gateways, and devices. A formal security analysis is conducted using the Real-or-Random (RoR) model. The results demonstrate the scheme’s resilience against polynomial-time adversaries. The scheme is efficient, robust, and resistant to common attacks, making it a practical solution for securing smart home networks. In the informal analysis, the proposed scheme was compared to other smart home authentication schemes. The comparison addressed various security features, including eavesdropping attacks, fault analysis attacks, and other security aspects. Finally, the performance analysis shows that the scheme performs well in terms of computation cost (memory = 332.2916 bits, CPU = 6.8299%, and Time = 1.5341 ms), as well as communication cost of 2,400 bits. These results demonstrate that the scheme offers lightweight performance with enhanced security.]]></description>
      </item><item>
        <guid isPermaLink="true">https://www.frontiersin.org/articles/10.3389/fcomp.2026.1764808</guid>
        <link>https://www.frontiersin.org/articles/10.3389/fcomp.2026.1764808</link>
        <title><![CDATA[Annoyed by cybersecurity? Human-centric perspectives on cybersecurity]]></title>
        <pubdate>2026-02-26T00:00:00Z</pubdate>
        <category>Review</category>
        <author>Ravdeep Kour</author><author>Ramin Karim</author><author>Annika Wägenbauer</author>
        <description><![CDATA[Humans play a vital role in designing, developing, implementing, and using technical systems. For this reason, it is crucial to keep humans in the loop at each phase of these systems to make them more secure and user-friendly. There needs to be a balance between using these systems securely and making them easy to use. Today, under pressure to secure our systems from cyberattacks, we primarily focus on making them secure but often overlook making them easy to use. Thus, the objective of this paper is to provide a human-centric perspective on cybersecurity and to introduce a human-centric framework that enables Industry 5.0, where humans have direct interaction with systems and solutions that are more customer-oriented. To carry out this research, the authors have applied the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines to investigate human-centric research over a 10-year period, from 2015 to 2025. The literature shows that most human-centric research contributions are well-balanced, with conceptual, experimental, and survey approaches each accounting for approximately 64% of the total, indicating a mature blend of theoretical and applied research. These studies are focused on developing structured, strategic approaches that integrate human factors into cybersecurity practices across sectors such as education, government, health, software, smart home networks, and others. To conduct this research, the authors have prepared an anonymous questionnaire with fundamental questions about secure system’s design, which can be easily used. The evaluation results show that frequent password resets (33.3%) and frequent authentication (26.7%) are the most “annoying” cybersecurity measures. Additionally, most respondents consider biometric login the most user-friendly security feature, followed by single sign-on and automatic security patch updates. What is missing in existing literature and studies is a holistic perspective on human-centrism, beyond mere ease of use. We aim to cover that blind spot by introducing our independently developed framework in this paper.]]></description>
      </item>
      </channel>
    </rss>