中文
相关论文

相关论文: The 23andMe Data Breach: Analyzing Credential Stuf…

200 篇论文

Sonatype's 2023 report found that 97% of developers and security leads integrate generative Artificial Intelligence (AI), particularly Large Language Models (LLMs), into their development process. Concerns about the security implications of…

软件工程 · 计算机科学 2025-07-24 Sivana Hamer , Marcelo d'Amorim , Laurie Williams

Managing and exchanging sensitive information securely is a paramount concern for the scientific and cybersecurity community. The increasing reliance on computing workflows and digital data transactions requires ensuring that sensitive…

密码学与安全 · 计算机科学 2023-11-23 Md Jobair Hossain Faruk , Bilash Saha , Jim Basney

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by…

密码学与安全 · 计算机科学 2022-05-18 Michal Kepkowski , Lucjan Hanzlik , Ian Wood , Mohamed Ali Kaafar

As Large Language Models (LLMs) become integral to scientific workflows, concerns over the confidentiality and ethical handling of confidential data have emerged. This paper explores data exposure risks through LLM-powered scientific tools,…

人机交互 · 计算机科学 2025-04-15 Yashothara Shanmugarasa , Shidong Pan , Ming Ding , Dehai Zhao , Thierry Rakotoarivelo

Retrieval-augmented generation (RAG) is a powerful technique to facilitate language model with proprietary and private data, where data privacy is a pivotal concern. Whereas extensive research has demonstrated the privacy risks of large…

密码学与安全 · 计算机科学 2024-03-03 Shenglai Zeng , Jiankun Zhang , Pengfei He , Yue Xing , Yiding Liu , Han Xu , Jie Ren , Shuaiqiang Wang , Dawei Yin , Yi Chang , Jiliang Tang

We conduct a large-scale measurement of developers' insecure practices leading to mini-app to super-app authentication bypass, among which hard-coding developer secrets for such authentication is a major contributor. We also analyze the…

密码学与安全 · 计算机科学 2023-07-19 Supraja Baskaran , Lianying Zhao , Mohammad Mannan , Amr Youssef

The increase in people's use of mobile messaging services has led to the spread of social engineering attacks like phishing, considering that spam text is one of the main factors in the dissemination of phishing attacks to steal sensitive…

计算与语言 · 计算机科学 2022-05-10 Mai A. Shaaban , Yasser F. Hassan , Shawkat K. Guirguis

Capturing the vast amount of meaningful information encoded in the human genome is a fascinating research problem. The outcome of these researches have significant influences in a number of health related fields --- personalized medicine,…

密码学与安全 · 计算机科学 2017-03-07 Mohammad Zahidul Hasan , Md Safiur Rahman Mahdi , Noman Mohammed

Security and privacy have been considered a corner stone in all electronic transactions nowadays. People are becoming very cautious when conducting electronic transactions over internet. One of the major issues that frightens them is…

密码学与安全 · 计算机科学 2019-10-23 Belal Amro , Ahmed Abu Sabha , Ammar Qunaibi , Ibraheem Najjar

Phishing is a well-known cybersecurity attack that has rapidly increased in recent years. It poses legitimate risks to businesses, government agencies, and all users due to sensitive data breaches, subsequent financial and productivity…

密码学与安全 · 计算机科学 2019-08-19 Sanchari Das , Andrew Kim , Zachary Tingle , Christena Nippert-Eng

Shuffle DP (Differential Privacy) protocols provide high accuracy and privacy by introducing a shuffler who randomly shuffles data in a distributed system. However, most shuffle DP protocols are vulnerable to two attacks: collusion attacks…

密码学与安全 · 计算机科学 2025-09-03 Takao Murakami , Yuichi Sei , Reo Eriguchi

Healthcare AI systems face major vulnerabilities to data poisoning that current defenses and regulations cannot adequately address. We analyzed eight attack scenarios in four categories: architectural attacks on convolutional neural…

密码学与安全 · 计算机科学 2026-01-26 Farhad Abtahi , Fernando Seoane , Iván Pau , Mario Vega-Barbas

In this paper we propose a new membership attack method called co-membership attacks against deep generative models including Variational Autoencoders (VAEs) and Generative Adversarial Networks (GANs). Specifically, membership attack aims…

机器学习 · 计算机科学 2019-09-23 Kin Sum Liu , Chaowei Xiao , Bo Li , Jie Gao

Website Fingerprinting (WFP) has traditionally focused on inferring which website a user visits from encrypted traffic metadata such as packet sizes and timing. In this paper, we identify and quantify a new privacy risk in modern web…

密码学与安全 · 计算机科学 2026-05-18 Chuxu Song , Hao Wang , Richard Martin

Encrypted cloud storage services are steadily increasing in popularity, with many commercial solutions currently available. In such solutions, the cloud storage is trusted for data availability, but not for confidentiality. Additionally,…

密码学与安全 · 计算机科学 2020-10-28 Anders Dalskov , Daniele Lain , Enis Ulqinaku , Kari Kostiainen , Srdjan Capkun

Directly releasing those data raises privacy and liability (e.g., due to unauthorized distribution of such datasets) concerns since location data contain users' sensitive information, e.g., regular moving patterns and favorite spots. To…

密码学与安全 · 计算机科学 2023-04-25 Yuzhou Jiang , Emre Yilmaz , Erman Ayday

When acting as a privacy-enhancing technology, synthetic data generation (SDG) aims to maintain a resemblance to the real data while excluding personally-identifiable information. Many SDG algorithms provide robust differential privacy (DP)…

密码学与安全 · 计算机科学 2025-04-02 Steven Golob , Sikha Pentyala , Anuar Maratkhan , Martine De Cock

Healthcare data contains some of the most sensitive information about an individual, yet sharing this data with healthcare practitioners can significantly enhance patient care and support research efforts. However, current systems for…

密码学与安全 · 计算机科学 2024-04-18 Ivan Costa , Ivone Amorim , Eva Maia , Pedro Barbosa , Isabel Praca

Nowadays, most online services offer different authentication methods that users can set up for multi-factor authentication but also as a recovery method. This configuration must be done thoroughly to prevent an adversary's access while…

密码学与安全 · 计算机科学 2024-03-25 Andre Büttner , Nils Gruschka

Hosting providers play a key role in fighting web compromise, but their ability to prevent abuse is constrained by the security practices of their own customers. {\em Shared} hosting, offers a unique perspective since customers operate…