Loading...

Table of Content

    23 May 2026, Volume 12 Issue 5
    LLMenhanced Static Analysis for Detecting Broken Object Level Authorization Vulnerabilities in Java Web Applications#br#
    #br#
    2026, 12(5):  394. 
    Asbtract ( )   PDF (1497KB) ( )  
    References | Related Articles | Metrics
    Broken object level authorization (BOLA) is currently one of the critical security threats to Web applications. As a typical unauthorized access vulnerability, BOLA arises when a system fails to properly validate a user’s access permissions to target objects. The key to static detection of BOLA vulnerabilities lies in: accurately identifying objectlevel sensitive operations and analyzing unprotected access behaviors during path traversal. Since BOLA is an application logiclevel vulnerability, its detection effectiveness directly depends on the precision of understanding the expected objectlevel authorization policies. However, existing detection methods predominantly rely on empirical heuristic rules to identify sensitive and protected operations, making them difficult to adapt to the actual business logic of different applications, resulting in high false positives and false negatives in detection results. To address this limitation, this paper innovatively proposes a large language model (LLM)enhanced static detection method for BOLA vulnerabilities in Web applications, LLM4BOLA. First, leveraging LLM’s advanced code comprehension and semantic reasoning capabilities to infer objectlevel sensitive operations and custom authorization policies in specific business scenarios. Then, identifying diverse permission protection mechanisms. Finally, comprehensively detecting missing objectlevel permission checks along the paths from request entry points to sensitive operations. Experimental results demonstrate that the proposed method not only effectively detects known vulnerabilities but also discovers unknown ones, significantly outperforming traditional rulebased approaches in detection accuracy.
    OSN Intrusion Detection Method Based on Residual Timeattention with Feature Selection#br#
    #br#
    2026, 12(5):  402. 
    Asbtract ( )   PDF (1781KB) ( )  
    References | Related Articles | Metrics
    Online social network (OSN), as core platform for information exchange, currently face serious intrusion threats. However, existing OSN intrusion detection techniques exhibit poor detection performance when dealing with issues such as high dimensionality, diverse datasets with different types of structures, significant semantic differences, and mismatched dynamic features. Therefore, an intrusion detection method based on residual timeattention with feature selection (RTAS) is proposed. The method utilizes the pretrained language model BERT for data preprocessing and designs a classifier based on residual timeattention. The model effectively captures contextual features in a wide range of text information through a bidirectional LSTM and attention mechanism. Meanwhile, an adaptive feature selection method based on deep reinforcement learning is proposed, which utilizes adaptive learning to obtain the optimal feature set. The experiment shows that the proposed method achieves accuracies of 98.53%, 98.68%, and 98.33% in detecting multiple threat patterns on datasets from Facebook, Google+, and Twitter, respectively. The average accuracy on the three datasets exceeds other mainstream methods.
    Research on Large Model Security Assessment Technology Based on Group Polarization Nested Jailbreak Templates#br#
    #br#
    2026, 12(5):  410. 
    Asbtract ( )   PDF (2619KB) ( )  
    References | Related Articles | Metrics
    As large model demonstrates excellent performance in natural language processing tasks, its security issues become increasingly prominent. Jailbreak attacks bypass model security mechanisms, weaken value alignment constraints, and induce models to generate harmful content. The risks of model abuse, hijacking, and information leakage caused by such attacks pose security threats to the large language model application ecosystem. To comprehensively evaluate large model security performance, a nested jailbreak template technique based on the group polarization psychological effect is proposed, which guides models to generate complex responses through progressively nested instructions. Based on this, the NesTHGA (nested templatehierarchical genetic algorithm) framework is constructed by integrating hierarchical genetic algorithms. Experimental results show that this method achieves an average attack success rate of over 80% across 8 mainstream large models, statistical tests confirm significant differences from existing methods, and ablation experiments verify component synergistic effects, effectively evaluating the security and robustness of large models against complex attacks.
    Research on Harmful Website Detection Based on Graph Neural Network and Multifeature Fusion
    2026, 12(5):  420. 
    Asbtract ( )   PDF (1884KB) ( )  
    References | Related Articles | Metrics
    To address the limitations of current harmful website detection methods in deep text semantic mining and multimodal feature coperception, this study proposes a multifeature fusion detection model based on graph attention networks (GAT) and ConvNeXt. The framework leverages GloVe word embeddings to construct semantic representations of website text, mapping it into a graph structure based on word cooccurrence relationships. The adaptive attention mechanism in GAT dynamically captures contextual dependencies between noncontiguous words, while ConvNeXt extracts both local details and global contextual features from website images. A crossattentionbased fusion module facilitates dynamic textimage feature alignment and interactive integration. Experimental results demonstrate that the proposed model achieves 99.10% accuracy in fourcategory website classification, significantly enhancing detection performance. This work offers valuable insights for identifying harmful online content and enhancing cybersecurity governance.
    Dynamic Scheduling Algorithm for Heterogeneous Executor Based on CSI Features#br#
    #br#
    2026, 12(5):  428. 
    Asbtract ( )   PDF (3060KB) ( )  
    References | Related Articles | Metrics
    In the current mimetic authentication scenario based on channel state information (CSI), existing dynamic scheduling algorithms suffer from insufficient authentication performance due to inadequate consideration of the heterogeneity of execution entities. This paper proposes a CSI featuresbased heterogeneous executor dynamic scheduling algorithm (CFHEDA). The algorithm comprehensively quantifies the correlation between CSI features and the heterogeneity of execution entities to construct a featurebased heterogeneous execution entity matrix. Based on this, the algorithm integrates dynamic historical threat assessment with an iterative greedy strategy to prioritize maximizing feature coverage. It selects execution entities by integrating a comprehensive score that considers contributions from heterogeneity, historical risk, and failure indices. Through attack collision simulation experiments, this paper compares four algorithms, including the highorder heterogeneous scheduling algorithm (HFAWA). The experiments demonstrate that under different numbers of execution entities, CFHEDA consistently achieves the best performance, with average defense success rates and average attack interception rates improved compared to existing algorithms, and overall performance enhanced by approximately 5% to 12%.
    Memory and Noise Cooptimization Method for Fully Homomorphic Encryption CNN Inference
    2026, 12(5):  439. 
    Asbtract ( )   PDF (955KB) ( )  
    References | Related Articles | Metrics
    To address the challenges of high memory consumption, low computational efficiency, and homomorphic noise accumulation in fully homomorphic encryption (FHE) for privacypreserving inference in convolutional neural network (CNN), this paper proposes a collaborative optimization framework. The framework introduces a hierarchical memory scheduling strategy, which employs a dynamic key loading mechanism and an adaptive compression technique for polynomial ring slot numbers (reducing available slots exponentially based on network depth), thereby significantly decreasing memory usage. Additionally, a noise suppression residual module is developed, incorporating a noise propagation dynamics model to design a realtime noise monitoringbased ondemand bootstrapping trigger mechanism, which reduces bootstrapping frequency and enhances inference efficiency. Experimental results on the CIFAR10 dataset demonstrate that this framework enables homomorphic encrypted inference of ResNet20 in approximately 500s with only 20GB of memory, achieving a 3.5× improvement in inference efficiency and a 94% reduction in memory consumption compared to existing CKKSbased solutions (2271s384GB). This framework provides a novel technical paradigm for privacypreserving machine learning in resourceconstrained scenarios.
    Generative Logic and Coping Strategies of Personal Information Security Risks in Digital Platform
    2026, 12(5):  445. 
    Asbtract ( )   PDF (1235KB) ( )  
    References | Related Articles | Metrics
    While digital platform provides tremendous convenience for public production and daily life, security risks such as personal information leakage and misuse have simultaneously escalated. As a new tier in governance structures, guiding digital platform to strike a balance between information protection and data openness is crucial for advancing the modernization of cyberspace governance systems and enhancing governance capacity. Examining digital platform from the perspective of data controllers, this paper explores the generative logic of personal information security risks through a threetiered framework: unauthorized collection, unregulated processing and improper application. The paper proposes coping strategies including refining “informed consent” operational details to stabilize the privacy policy framework of platform, strengthening the application of data desensitization technologies to standardize the automated decisionmaking processes of platform, and improving the information provision and disclosure mechanisms to enhance the internal information management of platform, so as to achieve a balance between personal information protection and the release of the value of data elements.
    Highperformance Hardware Architecture Design and Implementation of the MLKEM Algorithm#br#
    2026, 12(5):  452. 
    Asbtract ( )   PDF (1290KB) ( )  
    References | Related Articles | Metrics
    The postquantum cryptographic algorithm MLKEM has emerged as a key standard for resisting quantum computing attacks, and its highspeed hardware implementation is crucial for future network security. This paper proposes a hardware architecture for MLKEM and optimizes several specific modules within the design. For the encoding and decoding operations, FIFObased processing is employed to reduce resource consumption. In addition, the compression operation is analyzed to eliminate division operations during the compression process, and division and rounding are combined through specific parameter selection. Furthermore, a compact operation schedule is adopted to increase parallelism while reducing the overall computation latency. The proposed design is implemented and synthesized on a Xilinx Artix7 platform. Experimental results show that the maximum operating frequency reaches 125MHz, with resource utilization of 19791 LUTs, 8364 FFs, 22 BRAMs, and 9 DSPs. Under three security levels, the latencies of key generation, encapsulation, and decapsulation are 354149576593 cycles, 404255047183 cycles, and 6822907211274 cycles, respectively. The proposed architecture achieves a favorable balance between resource overhead and computational performance.
    A Compressionrobust Video Watermarking Method Based on Multiscale Convolutional Attention and Dualbranch Adversarial Training#br#
    #br#
    2026, 12(5):  463. 
    Asbtract ( )   PDF (2987KB) ( )  
    References | Related Articles | Metrics
    To overcome the limitations of current deep learningbased video watermarking methods, such as reliance on singlescale feature extraction, limited adversarial training mechanisms, and insufficient robustness against compression, this paper proposes a robust video watermarking model called MSCAGAN (multiscale convolutional attention generative adversarial network), which integrates a multiscale convolutional attention mechanism and a dualbranch adversarial training framework. The model employs a lightweight multiscale attention module to extract key features form video frames at both local and global perspectives. Combined with depthwise separable convolution, it reduces computational complexity while achieving precise localization and strength control of watermark embedding, thereby enhancing invisibility. This paper innovatively designs a dualbranch adversarial training structure, in which a learnable adversary network is introduced to simulate realworld attacks, enhancing the model’s robustness against common threats such as compression, cropping, and scaling. Experimental results demonstrate that the watermarked videos generated by MSCAGAN achieve an average PSNR of 44.61dB and a SSIM of 0.964, significantly outperforming existing methods. Under H.264 compression, the average decoding accuracy reaches 94.01%. Moreover, the model maintains strong robustness even under severe cropping and scaling attacks. In summary, MSCAGAN provides an efficient and reliable solution for multimedia content copyright protection. It has the potential to be extended to emerging coding standards such as H.265, further enhancing its robustness in complex application scenarios.
    Research on the Institutional Framework and Rule Characteristics of Chinese Network Information Security Policies
    2026, 12(5):  474. 
    Asbtract ( )   PDF (1709KB) ( )  
    References | Related Articles | Metrics
    Network information security policy is an important institutional guarantee for maintaining national security and development, and analyzing the institutional framework and rule characteristics of Chinese network information security policies is of great significance for enhancing its implementation effect of network information security policies. Coding statistics of 39 network information security policies, based on the components of institutional grammar tool (IGT), this paper highlights the complex orientation of the institutional framework of Chinese network information security policies from five dimensions: actors, action constraints, action scenarios, action goals, and evaluation results. Based on the framework of the system,focusing on the function definition rules, exit access rules, decisionmaking guidance rules, information transfer rules, and rewards and punishments incentives rules in the institutional analysis and development (IAD) framework, it is found that the current Chinese network information security policies are characterized by the rules of ambiguous definition of departmental rights and responsibilities, missing access conditions of the main body, weakening of the statement of the regulatory strength, poor reverse feedback channels, and unequal distribution of the rewards and punishments. In view of existing problems, in the future, the effectiveness of regulation can be improved by clarifying the rights and responsibilities of departments, adding access conditions, adding rulebased statements, optimizing feedback channels, and improving incentive and punishment measures.
    Research on the Implementation Path of Zero Trust Strategy
    2026, 12(5):  483. 
    Asbtract ( )   PDF (3588KB) ( )  
    References | Related Articles | Metrics
    Amid the wave of digital transformation, the traditional boundarybased network security model is increasingly ineffective in dynamic and border less environments. The United States has taken the lead in restructuring its cybersquatting system through a systematic zerotrust strategy, and its trinity practice path of “policytechnologyecology” is of reference significance for China to build a digital security barrier. This paper uses case analysis and policy comparison methods to deeply analyze the toplevel design logic, core technological breakthrough points, and ecological coordination mechanisms of the U.S. zerotrust strategy, revealing its essence of transitioning from “passive protection” to “active immunity”. Based on a deep diagnosis of the complexity of China’s ultralargescale network ecosystem, the shortcomings in the autonomy of core technologies, and the challenges of data sovereignty governance, this paper proposes a Chinesestyle “fourdimensional integrated” implementation path: breaking the fragmented dilemma with systematic toplevel design; breaking through technological bottlenecks with the integration of national cryptography and AIdriven technologies; building a security ecosystem with costsharing and standard leadership through governmententerprise collaboration; and addressing implementation limitations with scenario classification and privacy enhancement. The study emphasizes that China needs to innovate on the basis of reference, take zero trust as an important engine for building a digital security barrier, and balance the needs of security protection with the development of the digital economy.