Loading...
Toggle navigation
Home
About
About Journal
Editorial Board
Author Center
Current Issue
Just Accepted
Archive
Most Read Articles
Most Download Articles
Most Cited Articles
E-mail Alert
RSS
Reader Center
Online Submission
Manuscript Tracking
Instruction
Download
Review Center
Peer Review
Office Work
Editor-in-Chief
Subscription
Contact Us
中文
Table of Content
23 May 2026, Volume 12 Issue 5
Previous Issue
LLMenhanced Static Analysis for Detecting Broken Object Level Authorization Vulnerabilities in Java Web Applications#br#
#br#
2026, 12(5): 394.
Asbtract
(
)
PDF
(1497KB) (
)
References
|
Related Articles
|
Metrics
Broken object level authorization (BOLA) is currently one of the critical security threats to Web applications. As a typical unauthorized access vulnerability, BOLA arises when a system fails to properly validate a user’s access permissions to target objects. The key to static detection of BOLA vulnerabilities lies in: accurately identifying objectlevel sensitive operations and analyzing unprotected access behaviors during path traversal. Since BOLA is an application logiclevel vulnerability, its detection effectiveness directly depends on the precision of understanding the expected objectlevel authorization policies. However, existing detection methods predominantly rely on empirical heuristic rules to identify sensitive and protected operations, making them difficult to adapt to the actual business logic of different applications, resulting in high false positives and false negatives in detection results. To address this limitation, this paper innovatively proposes a large language model (LLM)enhanced static detection method for BOLA vulnerabilities in Web applications, LLM4BOLA. First, leveraging LLM’s advanced code comprehension and semantic reasoning capabilities to infer objectlevel sensitive operations and custom authorization policies in specific business scenarios. Then, identifying diverse permission protection mechanisms. Finally, comprehensively detecting missing objectlevel permission checks along the paths from request entry points to sensitive operations. Experimental results demonstrate that the proposed method not only effectively detects known vulnerabilities but also discovers unknown ones, significantly outperforming traditional rulebased approaches in detection accuracy.
OSN Intrusion Detection Method Based on Residual Timeattention with Feature Selection#br#
#br#
2026, 12(5): 402.
Asbtract
(
)
PDF
(1781KB) (
)
References
|
Related Articles
|
Metrics
Online social network (OSN), as core platform for information exchange, currently face serious intrusion threats. However, existing OSN intrusion detection techniques exhibit poor detection performance when dealing with issues such as high dimensionality, diverse datasets with different types of structures, significant semantic differences, and mismatched dynamic features. Therefore, an intrusion detection method based on residual timeattention with feature selection (RTAS) is proposed. The method utilizes the pretrained language model BERT for data preprocessing and designs a classifier based on residual timeattention. The model effectively captures contextual features in a wide range of text information through a bidirectional LSTM and attention mechanism. Meanwhile, an adaptive feature selection method based on deep reinforcement learning is proposed, which utilizes adaptive learning to obtain the optimal feature set. The experiment shows that the proposed method achieves accuracies of 98.53%, 98.68%, and 98.33% in detecting multiple threat patterns on datasets from Facebook, Google+, and Twitter, respectively. The average accuracy on the three datasets exceeds other mainstream methods.
Research on Large Model Security Assessment Technology Based on Group Polarization Nested Jailbreak Templates#br#
#br#
2026, 12(5): 410.
Asbtract
(
)
PDF
(2619KB) (
)
References
|
Related Articles
|
Metrics
As large model demonstrates excellent performance in natural language processing tasks, its security issues become increasingly prominent. Jailbreak attacks bypass model security mechanisms, weaken value alignment constraints, and induce models to generate harmful content. The risks of model abuse, hijacking, and information leakage caused by such attacks pose security threats to the large language model application ecosystem. To comprehensively evaluate large model security performance, a nested jailbreak template technique based on the group polarization psychological effect is proposed, which guides models to generate complex responses through progressively nested instructions. Based on this, the NesTHGA (nested templatehierarchical genetic algorithm) framework is constructed by integrating hierarchical genetic algorithms. Experimental results show that this method achieves an average attack success rate of over 80% across 8 mainstream large models, statistical tests confirm significant differences from existing methods, and ablation experiments verify component synergistic effects, effectively evaluating the security and robustness of large models against complex attacks.
Research on Harmful Website Detection Based on Graph Neural Network and Multifeature Fusion
2026, 12(5): 420.
Asbtract
(
)
PDF
(1884KB) (
)
References
|
Related Articles
|
Metrics
To address the limitations of current harmful website detection methods in deep text semantic mining and multimodal feature coperception, this study proposes a multifeature fusion detection model based on graph attention networks (GAT) and ConvNeXt. The framework leverages GloVe word embeddings to construct semantic representations of website text, mapping it into a graph structure based on word cooccurrence relationships. The adaptive attention mechanism in GAT dynamically captures contextual dependencies between noncontiguous words, while ConvNeXt extracts both local details and global contextual features from website images. A crossattentionbased fusion module facilitates dynamic textimage feature alignment and interactive integration. Experimental results demonstrate that the proposed model achieves 99.10% accuracy in fourcategory website classification, significantly enhancing detection performance. This work offers valuable insights for identifying harmful online content and enhancing cybersecurity governance.
Dynamic Scheduling Algorithm for Heterogeneous Executor Based on CSI Features#br#
#br#
2026, 12(5): 428.
Asbtract
(
)
PDF
(3060KB) (
)
References
|
Related Articles
|
Metrics
In the current mimetic authentication scenario based on channel state information (CSI), existing dynamic scheduling algorithms suffer from insufficient authentication performance due to inadequate consideration of the heterogeneity of execution entities. This paper proposes a CSI featuresbased heterogeneous executor dynamic scheduling algorithm (CFHEDA). The algorithm comprehensively quantifies the correlation between CSI features and the heterogeneity of execution entities to construct a featurebased heterogeneous execution entity matrix. Based on this, the algorithm integrates dynamic historical threat assessment with an iterative greedy strategy to prioritize maximizing feature coverage. It selects execution entities by integrating a comprehensive score that considers contributions from heterogeneity, historical risk, and failure indices. Through attack collision simulation experiments, this paper compares four algorithms, including the highorder heterogeneous scheduling algorithm (HFAWA). The experiments demonstrate that under different numbers of execution entities, CFHEDA consistently achieves the best performance, with average defense success rates and average attack interception rates improved compared to existing algorithms, and overall performance enhanced by approximately 5% to 12%.
Memory and Noise Cooptimization Method for Fully Homomorphic Encryption CNN Inference
2026, 12(5): 439.
Asbtract
(
)
PDF
(955KB) (
)
References
|
Related Articles
|
Metrics
To address the challenges of high memory consumption, low computational efficiency, and homomorphic noise accumulation in fully homomorphic encryption (FHE) for privacypreserving inference in convolutional neural network (CNN), this paper proposes a collaborative optimization framework. The framework introduces a hierarchical memory scheduling strategy, which employs a dynamic key loading mechanism and an adaptive compression technique for polynomial ring slot numbers (reducing available slots exponentially based on network depth), thereby significantly decreasing memory usage. Additionally, a noise suppression residual module is developed, incorporating a noise propagation dynamics model to design a realtime noise monitoringbased ondemand bootstrapping trigger mechanism, which reduces bootstrapping frequency and enhances inference efficiency. Experimental results on the CIFAR10 dataset demonstrate that this framework enables homomorphic encrypted inference of ResNet20 in approximately 500s with only 20GB of memory, achieving a 3.5× improvement in inference efficiency and a 94% reduction in memory consumption compared to existing CKKSbased solutions (2271s384GB). This framework provides a novel technical paradigm for privacypreserving machine learning in resourceconstrained scenarios.
Generative Logic and Coping Strategies of Personal Information Security Risks in Digital Platform
2026, 12(5): 445.
Asbtract
(
)
PDF
(1235KB) (
)
References
|
Related Articles
|
Metrics
While digital platform provides tremendous convenience for public production and daily life, security risks such as personal information leakage and misuse have simultaneously escalated. As a new tier in governance structures, guiding digital platform to strike a balance between information protection and data openness is crucial for advancing the modernization of cyberspace governance systems and enhancing governance capacity. Examining digital platform from the perspective of data controllers, this paper explores the generative logic of personal information security risks through a threetiered framework: unauthorized collection, unregulated processing and improper application. The paper proposes coping strategies including refining “informed consent” operational details to stabilize the privacy policy framework of platform, strengthening the application of data desensitization technologies to standardize the automated decisionmaking processes of platform, and improving the information provision and disclosure mechanisms to enhance the internal information management of platform, so as to achieve a balance between personal information protection and the release of the value of data elements.
Highperformance Hardware Architecture Design and Implementation of the MLKEM Algorithm#br#
2026, 12(5): 452.
Asbtract
(
)
PDF
(1290KB) (
)
References
|
Related Articles
|
Metrics
The postquantum cryptographic algorithm MLKEM has emerged as a key standard for resisting quantum computing attacks, and its highspeed hardware implementation is crucial for future network security. This paper proposes a hardware architecture for MLKEM and optimizes several specific modules within the design. For the encoding and decoding operations, FIFObased processing is employed to reduce resource consumption. In addition, the compression operation is analyzed to eliminate division operations during the compression process, and division and rounding are combined through specific parameter selection. Furthermore, a compact operation schedule is adopted to increase parallelism while reducing the overall computation latency. The proposed design is implemented and synthesized on a Xilinx Artix7 platform. Experimental results show that the maximum operating frequency reaches 125MHz, with resource utilization of 19791 LUTs, 8364 FFs, 22 BRAMs, and 9 DSPs. Under three security levels, the latencies of key generation, encapsulation, and decapsulation are 354149576593 cycles, 404255047183 cycles, and 6822907211274 cycles, respectively. The proposed architecture achieves a favorable balance between resource overhead and computational performance.
A Compressionrobust Video Watermarking Method Based on Multiscale Convolutional Attention and Dualbranch Adversarial Training#br#
#br#
2026, 12(5): 463.
Asbtract
(
)
PDF
(2987KB) (
)
References
|
Related Articles
|
Metrics
To overcome the limitations of current deep learningbased video watermarking methods, such as reliance on singlescale feature extraction, limited adversarial training mechanisms, and insufficient robustness against compression, this paper proposes a robust video watermarking model called MSCAGAN (multiscale convolutional attention generative adversarial network), which integrates a multiscale convolutional attention mechanism and a dualbranch adversarial training framework. The model employs a lightweight multiscale attention module to extract key features form video frames at both local and global perspectives. Combined with depthwise separable convolution, it reduces computational complexity while achieving precise localization and strength control of watermark embedding, thereby enhancing invisibility. This paper innovatively designs a dualbranch adversarial training structure, in which a learnable adversary network is introduced to simulate realworld attacks, enhancing the model’s robustness against common threats such as compression, cropping, and scaling. Experimental results demonstrate that the watermarked videos generated by MSCAGAN achieve an average PSNR of 44.61dB and a SSIM of 0.964, significantly outperforming existing methods. Under H.264 compression, the average decoding accuracy reaches 94.01%. Moreover, the model maintains strong robustness even under severe cropping and scaling attacks. In summary, MSCAGAN provides an efficient and reliable solution for multimedia content copyright protection. It has the potential to be extended to emerging coding standards such as H.265, further enhancing its robustness in complex application scenarios.
Research on the Institutional Framework and Rule Characteristics of Chinese Network Information Security Policies
2026, 12(5): 474.
Asbtract
(
)
PDF
(1709KB) (
)
References
|
Related Articles
|
Metrics
Network information security policy is an important institutional guarantee for maintaining national security and development, and analyzing the institutional framework and rule characteristics of Chinese network information security policies is of great significance for enhancing its implementation effect of network information security policies. Coding statistics of 39 network information security policies, based on the components of institutional grammar tool (IGT), this paper highlights the complex orientation of the institutional framework of Chinese network information security policies from five dimensions: actors, action constraints, action scenarios, action goals, and evaluation results. Based on the framework of the system,focusing on the function definition rules, exit access rules, decisionmaking guidance rules, information transfer rules, and rewards and punishments incentives rules in the institutional analysis and development (IAD) framework, it is found that the current Chinese network information security policies are characterized by the rules of ambiguous definition of departmental rights and responsibilities, missing access conditions of the main body, weakening of the statement of the regulatory strength, poor reverse feedback channels, and unequal distribution of the rewards and punishments. In view of existing problems, in the future, the effectiveness of regulation can be improved by clarifying the rights and responsibilities of departments, adding access conditions, adding rulebased statements, optimizing feedback channels, and improving incentive and punishment measures.
Research on the Implementation Path of Zero Trust Strategy
2026, 12(5): 483.
Asbtract
(
)
PDF
(3588KB) (
)
References
|
Related Articles
|
Metrics
Amid the wave of digital transformation, the traditional boundarybased network security model is increasingly ineffective in dynamic and border less environments. The United States has taken the lead in restructuring its cybersquatting system through a systematic zerotrust strategy, and its trinity practice path of “policytechnologyecology” is of reference significance for China to build a digital security barrier. This paper uses case analysis and policy comparison methods to deeply analyze the toplevel design logic, core technological breakthrough points, and ecological coordination mechanisms of the U.S. zerotrust strategy, revealing its essence of transitioning from “passive protection” to “active immunity”. Based on a deep diagnosis of the complexity of China’s ultralargescale network ecosystem, the shortcomings in the autonomy of core technologies, and the challenges of data sovereignty governance, this paper proposes a Chinesestyle “fourdimensional integrated” implementation path: breaking the fragmented dilemma with systematic toplevel design; breaking through technological bottlenecks with the integration of national cryptography and AIdriven technologies; building a security ecosystem with costsharing and standard leadership through governmententerprise collaboration; and addressing implementation limitations with scenario classification and privacy enhancement. The study emphasizes that China needs to innovate on the basis of reference, take zero trust as an important engine for building a digital security barrier, and balance the needs of security protection with the development of the digital economy.
Author Center
Online Submission
Instruction
Template
Copyright Agreement
Review Center
Peer Review
Editor Work
Editor-in-Chief
Office Work