English
Related papers

Related papers: Risky Business: Assessing Security with External M…

200 papers

Cyber risk assessment is a fundamental activity for enhancing the protection of an organization, identifying and evaluating the exposure to cyber threats. Currently, this activity is carried out mainly manually and the identification and…

Cryptography and Security · Computer Science 2022-07-08 Marco Angelini , Silvia Bonomi , Alessandro Palma

In safety-critical deep learning applications, robustness measures the ability of neural models that handle imperceptible perturbations in input data, which may lead to potential safety hazards. Existing pre-deployment robustness assessment…

Machine Learning · Computer Science 2025-08-27 Wenchuan Mu , Kwan Hui Lim

The lack of high-quality public cyber incident data limits empirical research and predictive modeling for cyber risk assessment. This challenge persists due to the reluctance of companies to disclose incidents that could damage their…

Risk Management · Quantitative Finance 2026-03-20 Jiayi Guo , Zhiyu Quan , Linfeng Zhang

Recent work~\cite{Liu2016} has shown that dependencies between items in a dataset can lead to privacy leaks. We extend this concept to privacy-preserving transformations, considering a broader set of dependencies captured by correlation…

Cryptography and Security · Computer Science 2025-06-17 Kenneth Odoh

Open source software (OSS) generates trillions of dollars in economic value and has become essential to the technical infrastructures that power organizations worldwide. As these systems increasingly depend on OSS, understanding the…

Software Engineering · Computer Science 2026-01-06 Elijah Kayode Adejumo , Mariam Guizani , Brittany Johnson

Following the AI Seoul Summit in 2024, twelve AI companies published frontier AI safety frameworks (Frameworks) outlining their approaches to managing catastrophic risks from advanced AI systems. Emerging legislation increasingly treats…

Computers and Society · Computer Science 2026-05-01 Lily Stelling , Malcolm Murray , Bruno Galizzi , Max Schaffelder , Siméon Campos , Henry Papadatos

There is an increase in global malware threats. To address this, an encryption-type ransomware has been introduced on the Android operating system. The challenges associated with malicious threats in phone use have become a pressing issue…

Cryptography and Security · Computer Science 2025-10-30 Parick Ozoh , John K Omoniyi , Bukola Ibitoye

Conditional forecasts of risk measures play an important role in internal risk management of financial institutions as well as in regulatory capital calculations. In order to assess forecasting performance of a risk measurement procedure,…

Risk Management · Quantitative Finance 2017-02-22 Natalia Nolde , Johanna F. Ziegel

A wide variety of privacy metrics have been proposed in the literature to evaluate the level of protection offered by privacy enhancing-technologies. Most of these metrics are specific to concrete systems and adversarial models, and are…

Information Theory · Computer Science 2012-11-14 David Rebollo-Monedero , Javier Parra-Arnau , Claudia Diaz , Jordi Forné

Owing to recorded incidents of Information technology inclined organisations failing to respond effectively to threat incidents, this project outlines the benefits of conducting a comprehensive risk assessment which would aid proficiency in…

Computers and Society · Computer Science 2018-12-13 Samuel Cris Ayo , Bonaventure Ngala , Olasunkanmi Amzat , Robin Lal Khoshi , Samarappulige Isuru Madusanka

Centrality metrics have been used in various networks, such as communication, social, biological, geographic, or contact networks. In particular, they have been used in order to study and analyze targeted attack behaviors and investigated…

Social and Information Networks · Computer Science 2021-07-23 Zelin Wan , Yash Mahajan , Beom Woo Kang , Terrence J. Moore , Jin-Hee Cho

Many cyberattacks succeed because they exploit flaws at the human level. To address this problem, organizations rely on security awareness programs, which aim to make employees more resilient against social engineering. While some works…

Cryptography and Security · Computer Science 2025-12-01 Matthias Pfister , Giovanni Apruzzese , Irdin Pekaric

This study presents a critical review of disclosed, documented, and malicious cybersecurity incidents in the water sector to inform safeguarding efforts against cybersecurity threats. The review is presented within a technical context of…

Cryptography and Security · Computer Science 2020-07-28 Amin Hassanzadeh , Amin Rasekh , Stefano Galelli , Mohsen Aghashahi , Riccardo Taormina , Avi Ostfeld , Katherine Banks

My main worry, and the core of my research, is that our cybersecurity ecosystem is slowly but surely aging and getting old and that aging is becoming an operational risk. This is happening not only because of growing complexity, but more…

Cryptography and Security · Computer Science 2026-01-05 Martijn Dekker

Metrics and frameworks to quantifiably assess security measures have arisen from needs of three distinct research communities - statistical measures from the intrusion detection and prevention literature, evaluation of cyber exercises,…

Cryptography and Security · Computer Science 2019-10-28 Michael D. Iannacone , Robert A. Bridges

Compared to organizations in other sectors, civil society organizations (CSOs) are particularly vulnerable to security and privacy threats, as they lack adequate resources and expertise to defend themselves. At the same time, their security…

Computers and Society · Computer Science 2020-07-15 Nikita Samarin , Alisa Frik , Sean Brooks , Coye Cheshire , Serge Egelman

In modern internet-scale computing, interaction between a large number of parties that are not known a-priori is predominant, with each party functioning both as a provider and consumer of services and information. In such an environment,…

Cryptography and Security · Computer Science 2021-09-06 Christos-Minas Mathas , Costas Vassilakis , Nicholas Kolokotronis

Modern autonomous systems with machine learning components often use uncertainty quantification to help produce assurances about system operation. However, there is a lack of consensus in the community on what uncertainty is and how to…

Systems and Control · Electrical Eng. & Systems 2026-01-27 Sampada Deglurkar , Haotian Shen , Anish Muthali , Marco Pavone , Dragos Margineantu , Peter Karkus , Boris Ivanovic , Claire J. Tomlin

Firms in inter-organizational networks such as supply chains or strategic alliances are exposed to interdependent risks. These are risks that are transferable across partner firms. They can be decomposed into intrinsic risks a firm faces…

Computer Science and Game Theory · Computer Science 2023-05-09 Sanjith Gopalakrishnan , Sriram Sankaranarayanan

As a new type of cyber attacks, advanced persistent threats (APTs) pose a severe threat to modern society. This paper focuses on the assessment of the risk of APTs. Based on a dynamic model characterizing the time evolution of the state of…

Cryptography and Security · Computer Science 2017-12-29 Xiaofan Yang , Tianrui Zhang , Lu-Xing Yang , Luosheng Wen , Yuan Yan Tang