Document Type: Research Article

Access and Mobility Policy Control at the Network Edge

Volume 11, Issue 3, August 2019, Pages 105-111

https://doi.org/10.22042/isecure.2019.11.0.14

Evelina Pencheva, Ivaylo Atanasov, Ivaylo Asenov

Abstract The fifth generation (5G) system architecture is defined as service-based and the core network functions are described as sets of services accessible through application programming interfaces (API). One of the components of 5G is Multi-access Edge Computing (MEC) which provides the open access to radio network functions through API. Using the mobile edge API third party analytics applications may provide intelligence in the vicinity of end users which improves network performance and enhances user experience. In this paper, we propose new mobile edge API to access and control the mobility at the network edge. The application logic for provisioning access and mobility policies may be based on considerations like load level information per radio network slice instance, user location, accumulated usage, local policy, etc. We describe the basic API functionality by typical use cases and provide the respective data model, which represents the resource structure and data types. Some implementation aspects, related to modeling the resource states as seen by a mobile edge application and by the network, are discussed.

A Federated framework for unsupervised intrusion detection on the Modbus protocol in cyber-physical systems

Volume 18, Issue 3, July 2026, Pages 167-178

https://doi.org/10.22042/isecure.2026.242101

Hamid Reza Dashtabadi, Siavash Ahmadi

Abstract The increasing integration of modern network infrastructure into industrial control systems elevates the need for robust cyber intrusion detection for industrial protocols. Unsupervised anomaly detection is particularly effective for this task, as it identifies novel attacks by modeling normal behaviour rather than relying on limited attack data. While techniques like autoencoders, which use reconstruction error to flag deviations, can be effective, their application is often hindered by practical challenges, such as regulatory constraints and the large volumes of data that prohibit the centralised collection required for training. Federated learning offers a solution by distributing the training process to local clients and aggregating only the resulting model parameters, thus preserving data privacy and locality. This paper proposes an anomaly-based intrusion detection framework built on federated learning. Using the CIC-Modbus2023 dataset, which comprises raw Modbus traffic from a smart grid, we systematically extract and label network flows based on attack logs. We then train and evaluate several autoencoder variants—including standard, variational, and adversarial autoencoders—within this federated setting. Our results demonstrate strong performance in detecting malicious behaviour, highlighting the framework’s potential as a promising approach for mitigating threats against the Modbus protocol without centralised data access. The code is available at https://github.com/hamid-rd/FLBased-ICS-NIDS.

Shapley Value for Federated Learning: A Distributed and Fair Framework

Volume 17, Issue 2, July 2025, Pages 251-259

https://doi.org/10.22042/isecure.2025.219572

Mohammad Amin Sarzaeem, Seyed Reza Hoseini Najarkolaei, Mohammad Reza Aref

Abstract In a federated learning system, the objective is to train a global model over distributed datasets without centralizing all data on a single unit. This is accomplished by training a local model on the dataset of each data owner and then aggregating these local models to preserve the datasets’ privacy. To incentivize clients to actively engage in the learning process, fairness-aware federated learning techniques can be employed. One such approach involves quantifying the contribution of locally trained models in training the global model by Shapley value (SV) using an additional dataset and rewarding them according to their contributions. However, the calculation of the Shapley value presents a significant challenge due to its high computational complexity. To tackle this issue, our research presents a contribution-based federated learning method that efficiently computes the contribution of each locally trained model by distributing the additional dataset among processing nodes in a private manner and calculating the Shapley value over them.

Evaluating Multipath TCP Resilience against Link Failures

Volume 11, Issue 3, August 2019, Pages 113-122

https://doi.org/10.22042/isecure.2019.11.0.15

Mohammed J.F. Alenazi

Abstract Standard TCP is the de facto reliable transfer protocol for the Internet. It is designed to establish a reliable connection using only a single network interface. However, standard TCP with single interfacing performs poorly due to intermittent node connectivity. This requires the re-establishment of connections as the IP addresses change. Multi-path TCP (MPTCP) has emerged to utilize multiple network interfaces in order to deliver higher throughput. Resilience to link failures can be better supported in MPTCP as the segments’ communication are maintained via alternative interfaces. In this paper, the resilience of MPTCP to link failures against several challenges is evaluated. Several link failure scenarios are applied to examine all aspects of MPTCP including congestion algorithms, path management, and subflow scheduling. In each scenario, the behavior of MPTCP is studied by observing and analyzing the throughput and delay. The evaluation of the results indicates MPTCP resilience to a low number of failed links. However, as the number of failed links increases, MPTCP can only recover full throughput if the link failure occurs on the server side. In addition, in the presence of link failures, the lowestRTT MPTCP scheduler yields the shortest delivery time while providing the minimum application jitter.

5G Attacks: Realistic Scenarios and Simulations Using Open5GS

Volume 18, Issue 3, July 2026, Pages 179-189

https://doi.org/10.22042/isecure.2026.240534

Mahdi Jeyhoon, Maryam Rajabzadeh Assar

Abstract The evolution of fifth-generation cellular networks (5G) brings unprecedented improvements in speed, latency, and scalability, but also introduces significant new security challenges. While earlier studies have primarily focused on performance benchmarking or examined isolated vulnerabilities, there remains a lack of comprehensive, reproducible security evaluations of 5G core networks. This paper presents a scenario-based simulation study of three distinct denial-of-service (DoS) attacks targeting critical components of the 5G control plane. Using open-source tools such as Open5GS and UERANSIM, we demonstrate: (1) large-scale registration flooding that overloads both the next-generation NodeB (gNB) and the Access and Mobility Management Function (AMF); (2) AMF resource exhaustion through massive NGSetupRequest messages; and (3) tampering with a security-related parameter in the User Equipment (UE) registration process to disrupt authentication. The evaluation quantifies the impacts of Central Processing Unit (CPU) and Random Access Memory (RAM) under these attacks, showing that even commodity hardware testbeds can reveal critical vulnerabilities. Moreover, analysis of the logs collected during the attacks confirms the successful execution of each attack scenario. The findings highlight how scenario-based simulations effectively explore various 5G attack surfaces and underscore the necessity for targeted defense mechanisms to enhance the resilience of next-generation mobile networks.

A New Scheme Based on (t,n)-Secret Image Sharing With Steganography Based on Joseph’s Problem and HLR

Volume 17, Issue 2, July 2025, Pages 261-265

https://doi.org/10.22042/isecure.2025.219355

Zahra Saeidi, Samaneh Mashhadi

Abstract The paper presents a novel approach to Secret Image Sharing (SIS) that combines (t, n)-threshold schemes with steganography, utilizing Joseph’s problem and Homogeneous Linear Recursion (HLR) to enhance security. The methodology involves dividing a secret image into shadow images, embedding these shadows into cover images using a Least Significant Bit (LSB) method guided by Joseph’s problem. The study aims to increase the security of SIS while maintaining high visual quality in the stego images. The authors validate their approach through various experiments, demonstrating that the proposed method improves Peak Signal-to-Noise Ratio (PSNR) and Structural Similarity Index (SSIM) compared to existing methods.

A Fair Power Allocation for Non-Orthogonal Multiple Access in the Power Domain

Volume 11, Issue 3, August 2019, Pages 123-130

https://doi.org/10.22042/isecure.2019.11.0.16

Joel E. Cordeiro Junior, Marcelo S. Alencar, José V. dos Santos Filho, Karcius D. R. Assis

Abstract This paper presents an investigation on the performance of the Non-Orthogonal Multiple Access (NOMA) in the power domain scheme. A Power Allocation (PA) method is proposed from NOMA throughput expression analysis. This method aims to provide fair opportunities for users to improve their performance. Thus, NOMA users can achieve rates higher than, or equal to, the rates obtained with the conventional Orthogonal Multiple Access (OMA) in the frequency domain schemes. The proposed method is evaluated and compared with others PA techniques by computer system level simulations. The results obtained indicate that the proposed method increases the average cell spectral efficiency and
maintains a good fairness level with regard to the resource allocation among the users within a cell.

HashLearner: A Secure Decentralized Learning Framework Based on HashGraph

Volume 18, Issue 3, July 2026, Pages 191-205

https://doi.org/10.22042/isecure.2026.242015

Keyhan Mohammadi, Ehasan Kozegar, Reza Ebrahimi Atani

Abstract Federated learning enables collaborative model training without centralized data collection, but existing frameworks rely on a central server, introducing risks of single points of failure, adversarial manipulation, and privacy leakage. To address these challenges, we propose HashLearner, a secure decentralized learning framework that utilizes the HashGraph consensus protocol for model aggregation without trusted authorities. HashLearner introduces two key innovations: (i) a consensus-driven decentralized aggregation mechanism resilient to Byzantine adversaries, and (ii) a privacy-preserving shuffling strategy that mitigates gradient reconstruction and poisoning attacks. To handle heterogeneous data distributions, the framework further employs transfer learning–based personalization. The simulation results of HashLearner, tested on benchmark Kaggle datasets, demonstrate that the platform maintains high accuracy while significantly enhancing scalability, security, and privacy. These findings indicate that HashLearner provides a practical path toward scalable, privacy-preserving, and trustworthy decentralized federated learning.

Critical Success Factors for Data Virtualization: A Literature Review

Volume 11, Issue 3, August 2019, Pages 131-137

https://doi.org/10.22042/isecure.2019.11.0.17

Matthias Gottlieb, Marwin Shraideh, Isabel Fuhrmann, Markus Böhm, Helmut Krcmar

Abstract Data Virtualization (DV) has become an important method to store and handle data cost-efficiently. However, it is unclear what kind of data and when data should be virtualized or not. We applied a design science approach in the first stage to get a state of the art of DV regarding data integration and to present a concept matrix. We extend the knowledge base with a systematic literature review resulting in 15 critical success factors for DV. Practitioners can use these critical success factors to decide between DV and Extract, Transform, Load (ETL) as data integration approach.

EPT Benchmark: Evaluation of Persian Trustworthiness in Large Language Models

Volume 18, Issue 3, July 2026, Pages 207-231

https://doi.org/10.22042/isecure.2026.242935

Mohammad Reza Mirbagheri, Seyed Mohammad Mahdi Mirkamali, Zahra Arani, Ali Javeri, Amir Mahdi Sadeghzadeh Mesgar, Rasool Jalili

Abstract Large Language Models (LLMs), trained on extensive datasets using advanced deeplearning architectures, have demonstrated remarkable performance across a wide range of language tasks, becoming a cornerstone of modern AI technologies. However, ensuring their trustworthiness remains a critical challenge, asreliability is essential not only for accurate performance but also for upholding ethical, cultural, and social values. Careful alignment of training data and culturally grounded evaluation criteria is vital for developing responsible AI systems. In this study, we introduce the EPT (Evaluation of Persian Trustworthiness) metric, a culturally informed benchmark specifically designed to assess the trustworthiness of LLMs across six key aspects: Truthfulness, Safety, Fairness, Robustness, privacy, and ethical alignment. We curated a labelled dataset and evaluated the performance of several leading models—including ChatGPT, Claude, DeepSeek, Gemini, Grok, LLaMA, Mistral, and Qwen—using both automated LLM-based and human assessments. Our results reveal significant deficiencies in the safety dimension, underscoring the urgent need for focused attention on this critical aspect of model behaviour. Furthermore, our findings offer valuable insights into the alignment of these models with Persian ethical-cultural values and highlight critical gaps and opportunities for advancing trustworthy and culturally responsible AI. The dataset is publicly available at: https://github.com/Rezamirbagheri110/EPT-Benchmark.

Using Machine Learning ARIMA to Predict the Price of Cryptocurrencies

Volume 11, Issue 3, August 2019, Pages 139-144

https://doi.org/10.22042/isecure.2019.11.0.18

Saad Ali Alahmari

Abstract The increasing volatility in pricing and growing potential for profit in digital currency have made predicting the price of cryptocurrency a very attractive research topic. Several studies have already been conducted using various machine-learning models to predict crypto currency prices. This study presented in this paper applied a classic Autoregressive Integrated Moving Average(ARIMA) model to predict the prices of the three major cryptocurrencies âAT Bitcoin, XRP and Ethereum âAT using daily, weekly and monthly time series. The results demonstrated that ARIMA outperforms most other methods in predicting cryptocurrency prices on a daily time series basis in terms of mean absolute error (MAE), mean squared error (MSE) and root mean squared error(RMSE).

Learning to Locate: GNN-Powered Vulnerability Path Discovery in Open Source Code

Volume 18, Issue 3, July 2026, Pages 233-241

https://doi.org/10.22042/isecure.2026.242017

Nima Atashin, Behrouz Tork Ladani, Mohammadreza Sharbaf

Abstract Detecting security vulnerabilities in open-source software is a critical task that is highly regarded in the related research communities. Several approaches have been proposed in the literature for detecting vulnerable code and identifying classes of vulnerabilities. However, there is still room to improve the explanation of the root causes of detected vulnerabilities by locating vulnerable statements and discovering the paths that lead to the activation of the vulnerability. While frameworks like SliceLocator offer explanations by identifying vulnerable paths, they rely on rule-based sink identification that limits their generalisation. In this paper, we introduce VulPathFinder, an explainable vulnerability path discovery framework that enhances SliceLocator’s methodology by utilising a novel Graph Neural Network (GNN) model for detecting sink statements, rather than relying on predefined rules. The proposed GNN captures semantic and syntactic dependencies to find potential sink points (PSPs), which are candidate statements where vulnerable paths end. After detecting PSPs, program slicing can be used to extract potentially vulnerable paths, which are then ranked by feeding them back into the target graph-based detector. Ultimately, the most probable path is returned, explaining the root cause of the detected vulnerability. We demonstrate the effectiveness of the proposed approach by performing evaluations on a benchmark of the buffer overflow CWEs from the SARD dataset, providing explanations for the corresponding detected vulnerabilities. The results show that VulPathFinder outperforms both the original SliceLocator and GNNExplainer (as a general GNN explainability tool) in discovering vulnerability paths to identified PSPs.

An Optimal Utilization of Cloud Resources using Adaptive Back Propagation Neural Network and Multi-Level Priority Queue Scheduling

Volume 11, Issue 3, August 2019, Pages 145-151

https://doi.org/10.22042/isecure.2019.11.0.19

Anwar Saeed, Muhammad Yousif, Areej Fatima, Sagheer Abbas, Muhammad Adnan Khan, Leena Anum, Ali Akram

Abstract With the innovation of cloud computing industry lots of services were provided based on different deployment criteria. Nowadays everyone tries to remain connected and demand maximum utilization of resources with minimum time
and effort. Thus, making it an important challenge in cloud computing for optimum utilization of resources. To overcome this issue, many techniques have been proposed shill no comprehensive results have been achieved. Cloud Computing offers elastic and scalable resource sharing services by using resource management. In this article, a hybrid approach has been proposed with an objective to achieve the maximum resource utilization. In this proposed method, adaptive back propagation neural network and multi-level priority-based scheduling are being carried out for optimum resource utilization. This hybrid technique will improve the utilization of resources in cloud computing. This shows result in simulation-based on the form of MSE and Regression with job dataset, on behalf of the comparison of three algorithms like Scaled Conjugate Gradient (SCG), Levenberg Marquardt (LM) and Bayesian Regularization (BR). BR gives a better result with 60 hidden layers Neurons to other algorithms. BR gives 2.05 MSE and 95.8 regressions in Validation, LM gives 2.91 MSE and 94.06 regressions with this and SCG gives 3.92 MSE and 91.85 regressions.

Decentralised Plagiarism Detection System for Open Textual Educational Resources based on Blockchain Technology

Volume 18, Issue 3, July 2026, Pages 243-254

https://doi.org/10.22042/isecure.2026.242098

Sina Fattahi Ardakani, Maedeh Mosharraf

Abstract Open Educational Resources (OER) have become a valuable tool for expanding access to quality education. However, managing intellectual property rights in OER environments remains a challenge, particularly in verifying content authenticity and protecting creators’ rights. To address this challenge, the study proposes a decentralised approach to copyright management for OER. Our solution processes OER textual content using defined windows and the Locality Sensitive Hashing (LSH) algorithm to detect exact and partial similarities efficiently. By integrating blockchain technology and the InterPlanetary File System (IPFS), we establish a transparent, decentralised platform for storing and managing resources. To assess its effectiveness, the proposed system was implemented and tested on a dataset of 2,600 OER articles. The evaluation demonstrated perfect performance, with 100 per cent precision and recall across both direct and paraphrased plagiarism detection test sets. The results indicate that this technological integration can serve as a robust foundation for enhancing transparency and protecting authors’ rights within the OER ecosystem.

Cloud and IoT based Smart Car Parking System by using Mamdani Fuzzy Inference System (MFIS)

Volume 11, Issue 3, August 2019, Pages 153-160

https://doi.org/10.22042/isecure.2019.11.0.20

Tahir Alyas, Gulzar Ahmad, Yousaf Saeed, Muhammad Asif, Umer Farooq, Asma Kanwal

Abstract Internet of Things (IoT) and cloud computing technologies have connected the infrastructure of the city to make the context-aware and more intelligent city for utility its major resources. These technologies have much potential to solve the
challenges of urban areas around the globe to facilitate the citizens. A framework model that enables the integration of sensor’s data and analysis of the data in the context of smart parking is proposed. These technologies use sensors and
devices deployed around the city parking areas sending real time data through the edge computers to the main cloud servers. Mobil-Apps are developed that used real time data, set from servers of the parking facilities in the city. Fuzzification is shown to be a capable mathematical approach for modeling city parking issues. To solve the city parking problems in cities a detailed analysis of fuzzy logic proposed systems is developed. This paper presents the results
achieved using Mamdani Fuzzy Inference System to model complex smart parking system. These results are verified using MATLAB simulation.

Backdoor Defense via Aggregation of Outsourced Models using Multi-Stage Knowledge Distillation

Volume 18, Issue 3, July 2026, Pages 255-266

https://doi.org/10.22042/isecure.2026.240527

Amirhossein Heydari, Azadeh Mansouri, Ahmad Mahmoudi-Aznaveh

Abstract Backdoor attacks pose a significant threat to deep learning systems by injecting hidden malicious behavior to the model while preserving high accuracy on clean data. Such attacks are particularly dangerous in scenarios where users rely on pre-trained models or outsource training to untrusted parties. In this work, we propose a practical defense strategy that assumes no knowledge of the backdoor trigger or the training process, relying on a small trusted clean dataset. Our method introduces a two-stage pipeline: First, we aggregate predictions from multiple potentially compromised models to train an intermediate Teacher-Aggregation (TA) model; then, we distill this knowledge into a compact light-weight student model. This multi-stage approach effectively alleviates backdoor effects while preserving clean accuracy. Experimental results on MNIST and CIFAR-10 demonstrate that our method significantly reduces the Attack Success Rate (ASR)—to approximately 0.1% on MNIST and 2.6% on CIFAR-10—outperforming baseline ensemble defenses. Furthermore, our lightweight student model is suitable for edge deployment, providing a generic and scalable defense that remains robust under minimal assumptions, making it well-suited for real-world applications in adversarial environments. Our code is available at: https://github.com/mr-pylin/backdoor-toolbox

Towards Measuring the Project Management Process During Large Scale Software System Implementation Phase

Volume 11, Issue 3, August 2019, Pages 161-172

https://doi.org/10.22042/isecure.2019.11.0.21

Wajdi Aljedaibi, Sufian Khamis

Abstract Project management is an important factor to accomplish the decision to implement large-scale software systems (LSS) in a successful manner. The effective project management comes into play to plan, coordinate and control such a complex project. Project management factor has been argued as one of the important Critical Success Factor (CSF), which need to be measured and monitored carefully during the implementation of Enterprise Resource Planning(ERP) systems. The goal of this article is to develop âAœCSF-Live!âAI which is a method for measuring, monitoring, and controlling critical success factors of large-scale software systems. To achieve such goal, we apply CSF-Live for the project management CSF. The CSF-Live uses the Goal/Question/Metric paradigm (GQM) to yield a flexible framework containing several metrics that we used it to develop a formulation to enable the measurement of the project management CSF. The formulation that we developed for the project management CSF implies that the significance of having proper project management when conducting an ERP system implementation, since it is positively associated with the success of the ERP.

An LSTM-DBSCAN Approach for Interpretable Insider Threat Detection via Behavioural Anomaly Analysis

Volume 18, Issue 3, July 2026, Pages 267-276

https://doi.org/10.22042/isecure.2026.241277

Mohammad Mohammadi, Moein Bannaye Zahmati, Morteza Noferesti

Abstract Insider threats pose a significant cybersecurity risk, as authorised users can exploit legitimate access to compromise sensitive systems and data. This paper proposes an integrated behavioural anomaly detection approach to address three critical challenges in AI-driven insider threat detection: lack of interpretability, misleading evaluation metrics, and misalignment with operational taxonomies. Our approach employs a three-stage pipeline: (1) an LSTM autoencoder to detect temporal anomalies in login patterns, (2) DBSCAN clustering to identify suspicious file access and device usage during anomalous sessions, and (3) DBSCAN-based URL analysis to uncover exfiltration patterns. By analysing behaviour across time, location, and web activity, this framework builds actionable threat chains mapped to MITRE ATT&CK techniques including T1078, T1005, T1204.002, T1567.002. It bridges the gap between theoretical models and the daily work of a Security Operations Center (SOC). In the data exfiltration scenario on the CERT R6.2 insider threat dataset, the proposed approach achieved a recall of 83.3% and an accuracy of 91.7% in classifying malicious days. The framework also provides interpretable alerts and maintains operational efficiency.

IoT Protocols Based Fog/Cloud over High Traffic

Volume 11, Issue 3, August 2019, Pages 173-180

https://doi.org/10.22042/isecure.2019.11.3.23

Istabraq M. Al-Joboury, Emad H. Al-Hemiary

Abstract The Internet of Things (IoT) becomes the future of a global data field in which the embedded devices communicate with each other, exchange data and making decisions through the Internet. IoT could improve the quality of life in smart cities, but a massive amount of data from different smart devices could slow down or crash database systems. In addition, IoT data transfer to Cloud for monitoring information and generating feedback that will lead to high delay in infrastructure level. Fog Computing can help by offering services closer to edge devices. In this paper, we propose an efficient system architecture to mitigate the problem of delay. We provide performance analysis like response time, throughput and packet loss for MQTT (Message Queue Telemetry Transport) and HTTP (Hyper Text Transfer Protocol) protocols based on Cloud or Fog servers with large volume of data from emulated traffic generator working alongside one real sensor . We implement both protocols in the same architecture, with low cost embedded devices to local and Cloud servers with different platforms. The results show that HTTP response time is 12.1 and 4.76 times higher than MQTT Fog and Cloud based located in the same geographical area of the sensors respectively. The worst case in performance is observed when the Cloud is public and outside the country region. The results obtained for throughput shows that MQTT has the capability to carry the data with available bandwidth and lowest percentage of packet loss. We also prove that the proposed Fog architecture is an efficient way to reduce latency and enhance performance in Cloud based IoT.

Genetic Algorithms in Action: Adversarial Attacks on Machine Learning-Based XSS Detection Systems

Volume 18, Issue 3, July 2026, Pages 277-286

https://doi.org/10.22042/isecure.2026.248360

Mohammadreza Safi, Mohammad Ali Hadavi

Abstract Cross-Site Scripting (XSS) remains a critical web application vulnerability, consistently ranking among the OWASP Top 10 security risks. Although machine learning and deep learning techniques have improved XSS detection, these models are susceptible to adversarial attacks — carefully crafted inputs designed to evade detection. This paper proposes a novel adversarial attack framework that leverages a Genetic Algorithm to generate adversarial XSS payloads targeting machine learning-based detection systems automatically. Our framework is designed to achieve high transferability, enabling adversarial samples to bypass a wide range of detection models, even those with different architectures. By employing genetic operators such as selection, crossover, and mutation, the framework systematically optimizes payloads to maximize their ability to evade detection while preserving syntactic validity. Experimental results demonstrate that the generated adversarial samples consistently evade multiple state-of-the-art detection models, revealing significant vulnerabilities in current XSS defences. This work underscores the urgent need for more robust machine learning-based security solutions and provides a foundation for developing improved defences against adaptive adversarial threats.

Virtualized Network Management Laboratory for Educational Purposes

Volume 11, Issue 3, August 2019, Pages 181-186

https://doi.org/10.22042/isecure.2019.11.3.24

Oula L. Abdulsattar, Emad H. Al-Hemiary

Abstract In this paper, we implement a Virtualized Network Management Laboratory named (VNML) linked to college campus network for educational purposes. This laboratory is created using Virtualbox virtualizer and GNS3 on Linux UBUNTU single HP DL380 G7 server platform. A total of 35 virtual devices (Routers, Switches and Virtual Machines) are created and distributed over virtualized campus network with seven network management tools configured and run. The proposed laboratory is aimed to overcome the limitations of network hardware existence in any educational facility teach network management subject in their curriculum. The other advantages include ease of managing the laboratory and overrides physical location setup within the same geographical area.

Dual-Layered Quantum-Secure Concealing: Steganography over Quantum Key Distribution

Volume 18, Issue 3, July 2026, Pages 287-296

https://doi.org/10.22042/isecure.2026.240529

Donya Sadat Rezaeishad, Hossein Bahramgiri

Abstract In the quantum computing era, classical encryption faces unprecedented vulnerabilities, while Quantum Key Distribution (QKD) alone remains insufficient for top-secret data transmission due to practical hardware flaws. In this paper, a novel dual-layered framework that integrates steganography with QKD is proposed to enhance security and concealment. The proposed protocol embeds encrypted messages within QKD keys during post-processing, leveraging existing infrastructure without requiring hardware modifications. The message is first compressed, encoded, and encrypted using a pre-shared QKD key via one-time-pad encryption. A block-based search mechanism then hides message bits within the sifted key while preserving statistical randomness. Crucially, this approach provides two-layer security: information-theoretic encryption via QKD and undetectable message existence. Evaluations confirm ultra-low failure probabilities of embedding (below 10−12 for 1000-bit messages) and minimal deviations in sifted key length (under 1% for typical blocks). The solution enables eavesdropper detection, maintaining full compatibility with standard QKD post-processing. By unifying steganographic stealth with QKD’s theoretical security, this work establishes a practical solution for transmitting top-secret data against evolving quantum threats.

A Secure and Verifiable Secret Sharing Scheme Using Neural Steganography and Hash-Based Authentication

Volume 18, Issue 3, July 2026, Pages 297-305

https://doi.org/10.22042/isecure.2026.242016

Majid Farhadi Sangdehi, Zohre Karimi, Mohammad Amin khorzani

Abstract This study presents a resilient and efficient architecture for securely distributing secrets to the public across untrusted networks. The proposed method integrates Shamir’s Verifiable Secret Sharing with AES-GCM encryption to provide strong confidentiality and authentication guarantees. Each share is reinforced with cryptographic hash-based signatures and imperceptibly embedded within cover images using a neural steganographic framework based on an Attention U-Net enhanced with transformer mechanisms and Squeeze-and-Excitation blocks, allowing the system to place data in visually insensitive regions adaptively. The training process leverages a joint perceptual and structural loss function, ensuring high visual fidelity while preserving critical image features for robust message recovery. Experimental evaluations demonstrate superior performance in Peak Signal-to-Noise Ratio and Structural Similarity Index Measure, and a minimal Bit Error Rate across various distortions, including noise, blurring, and JPEG compression. Compared to existing methods, the framework provides enhanced protection against fraudulent participants or dealers, eliminates reliance on secure private channels, and enables the reuse of system components, offering a comprehensive solution for safe, verifiable secret sharing.

Time-Based Steganography in Text

Volume 18, Issue 3, July 2026, Pages 307-312

https://doi.org/10.22042/isecure.2026.242053

Zahra Ghoraeian, Mohammad Reza Sadeghi, Samaneh Mashhadi

Abstract Preserving data confidentiality is crucial in today’s digital world where data exchange is increasingly becoming digital. This paper presents a novel text steganography algorithm. Initially, the secret message is converted into a bit stream. This bit stream is then shuffled using a random sequence to enhance security. Finally, the data is converted into a specific ”time” (including date and hour), and this generated time is embedded within a suitable cover text. The results demonstrate that the proposed algorithm is robust against a variety of attacks, including retyping, OCR, printing and photocopying, compression, document feature modification, non-Unicode environment conversion, and semantic paraphrasing. The algorithm is language-independent and applicable to all languages. The scheme exhibits high transparency against visual and machine attacks and has a capacity of 18 bits per time. The embedding of information bits using a random sequence enhances the scheme’s resistance against detection attacks.

Architected Graph-Enhanced Neural Network Framework for Image Integrity and Tamper Precision

Volume 18, Issue 3, July 2026, Pages 313-322

https://doi.org/10.22042/isecure.2026.242096

Khashayar Jafarizade, Mohammad Hassan Majidi, Hossein Gholamalinejad

Abstract Image authenticity is a perennial issue with the evolution of advanced tampering techniques, particularly grid-aligned manipulations and spatial vulnerability-exploiting post-processing attacks. The paper presents a novel architecture for a neural network fusing Graph Neural Networks (GNNs), Convolutional Neural Networks (CNNs), and digital watermarking to detect tampering successfully and localise it. CNNs are trained on learning local spatial features, and an invisible low-dropout convolutional encoder places watermarks to ensure authenticity. GNNs address the inherent problem of modelling long-range structural relations for blind tampering pattern detection that is accurate. With a graph-based representation of image blocks, the framework learns complex spatial relations, which alleviates the rigid receptive field limitation. Extensive experiments on benchmark datasets confirm the framework’s superiority, achieving an F1-Score of 0.94 in tampering localisation, which significantly outperforms the 0.88 F1-Score of leading state-of-the-art methods. This approach creates a new standard for image integrity verification, offering an interpretable and scalable solution with far-reaching applications in digital content protection.