Physical Sciences › Computer Science › Information Systems
Information and Cyber Security
169 artículos indexados
Las investigaciones en seguridad informática y cibernética exploran los métodos para detectar, prevenir y responder a las vulnerabilidades de los sistemas digitales. Abarcan herramientas como los benchmarks para la identificación de fallos en el código, los entornos simulados (cyber ranges) para probar escenarios de ataques, o incluso los agentes de inteligencia artificial diseñados para automatizar operaciones de defensa. Estos trabajos abordan también la modelización de riesgos, la formación de equipos y la integración de grandes modelos de lenguaje en los centros de supervisión, al tiempo que analizan los límites y sesgos de las soluciones existentes.
Este asunto y su jerarquía proceden de la clasificación OpenAlex, el catálogo abierto de la investigación científica mundial.
Volumen mensual - últimos 12 meses
Países de los laboratorios
- Estados Unidos49 % · 45 artículos
- China26 % · 24 artículos
- Alemania7,6 % · 7 artículos
- Australia7,6 % · 7 artículos
- India5,4 % · 5 artículos
- Italia4,3 % · 4 artículos
- Vietnam4,3 % · 4 artículos
- Reino Unido4,3 % · 4 artículos
Sobre 92 artículos de este tema con al menos un laboratorio localizado. 27 países representados.
Se trata del país del laboratorio, nunca de la nacionalidad de las personas. Un artículo firmado desde varios países cuenta para cada uno de ellos, por lo que las partes suman más del 100 %. La cobertura es parcial y el vacío no es aleatorio: un investigador cuya institución se desconoce suele publicar poco, lo que sobrerrepresenta a los laboratorios consolidados.
Últimos artículos
- AuraForge: Scaling Security Supervision for Training Coding Agents
Danqing Wang, Songwen Zhao, Harsh Sharma, Jierui Wang, Andre Vicente Duarte, Ivan Bercovich, Lei Li · 2 de octubre de 2026
Coding agents are now proficient enough to generate complex software applications from a single prompt. As their capabilities have grown, human oversight has increasingly shifted from line-by-line code review toward hands-off evaluation of outcomes. However, recent studies have shown that such a tra…
- Dual-Fit Imperative in Security Leadership: A Grounded Theory Investigation of CISO Role Enactment in Modern Organisations
Mazino Benson Onibere · 30 de septiembre de 2026
The Chief Information Security Officer (CISO) has emerged as a strategically prominent executive role, confronting an adversarial environment, irreconcilable accountability tensions between security and business enablement, and a prevention paradox in which success remains invisible to resource allo…
- SecProbe: Adaptive Evaluation of Coding Agents on Cybersecurity Vulnerabilities
Xiaonan Luo, Yue Huang, Kehan Guo, Ping He, Chuan Zou, Chujie Gao, Lichi Li, Yuchen Ma, Zhangchen Xu, Zichen Chen, Yufei Han, Xiangliang Zhang · 29 de septiembre de 2026
Assessing cybersecurity vulnerability awareness in coding agents requires evaluations that reveal capability gaps and remain informative as models evolve. Static benchmarks offer fixed coverage and difficulty, while scarce vulnerable repositories and costly expert authoring limit their renewal at sc…
- CyberClear: A Benchmark for LLM Agent Systems on APT Attack Chain Provenance
Qi Chen, Fushuo Huo, Hangli Shen, Jingcai Guo, Shuhao Li, Guang Cheng · 29 de septiembre de 2026
Large language model agents have demonstrated promising capabilities in cybersecurity tasks, yet their ability to reconstruct complete Advanced Persistent Threat attack campaigns from complex security logs remains largely unexplored. Existing cybersecurity benchmarks for agents mainly focus on vulne…
- CyberWorld: World Models for Sample-Efficient Autonomous Cyber Defense
Ryozo Masukawa, Sanggeon Yun, Raheeb Hassan, Hyunwoo Oh, SungHeon Jeong, Mohsen Imani · 29 de septiembre de 2026
Deep reinforcement learning has become a prominent approach to autonomous cyber defense. Existing methods are predominantly model-free and consequently require extensive environment interaction. World models provide an alternative by learning predictive dynamics and optimizing policies through imagi…
- Typed Temporal Interaction Features for Simulation-Backed Forecasting of Open-Source Game Release Incidents
Shayma Alkobaisi, Anas Ali · 29 de septiembre de 2026
Open-source video-game quality depends on inter-actions among code, assets, configuration, tests, contributors, and issue workflows, yet conventional defect predictors usually flatten or omit these relations. We investigate release-level forecasting of a quality incident within thirty days using GAM…
- Reward Hacking and Agent Containment Failure: A Monte Carlo Study Based on the 2026 Hugging Face Incident
Murat Ozer, Bulent Erenay, Ibrahim Berber · 29 de septiembre de 2026
The July 2026 intrusion into Hugging Face production infrastructure showed how reward hacking can become an external cybersecurity incident when a capable agent encounters weak containment boundaries. This study develops a probabilistic risk model linking five stages: reward hacking, containment esc…
- XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security
Sangshin Park, Jainta Paul, Lawrence Ponce, Md Raihan Ahmed, Mu Zhang, Luis Garcia · 28 de septiembre de 2026
Industrial control system (ICS) threats documented for one plant can express cyber-physical effects relevant to another, but semantic similarity alone does not establish whether those effects are structurally admissible or evaluable on a target. We present XPhysICS, a provenance-aware, target-condit…
- Coding Agents Aren't Enough! Evaluating an Enterprise Security Brain for Agentic Cloud Investigations
Leon Goldberg, Gal Engelberg, Eden Yavin, Elad Elouz, Ariel Zadok, Konstantin Koutsyi · 28 de septiembre de 2026
Cloud-security investigation is dominated by population tasks: which identities can read a data store, how many resources fail a control, which assets are reachable from another account. These resolve against a complete inventory, not a named object. A partial answer to one is not a partial result. …
- Detecting Data Poisoning in Code Generation LLMs via Black-Box, Vulnerability-Oriented Scanning
Shenao Yan, Shan Jin, Shimaa Ahmed, Sunpreet Singh Arora, Yiwei Cai, Yizhen Wang, Yuan Hong · 25 de septiembre de 2026
Code generation large language models (LLMs) are increasingly integrated into modern software development workflows. Recent work has shown that these models are vulnerable to backdoor and poisoning attacks that induce the generation of insecure code, yet effective defenses remain limited. Existing s…
- TraceVIC: Causal Reasoning over Code Evolution for Identifying Vulnerability-Inducing Commits
Fnu Tanish, Samiha Shimmi, Samikshya Chapagain, Hamed Okhravi, Mona Rahimi, Lei Zhang · 23 de septiembre de 2026
Software vulnerabilities are often discovered long after they are introduced, making it difficult to identify the vulnerability-inducing commit (VIC) responsible for introducing the underlying vulnerable condition. Existing VIC identification techniques largely rely on git blame to trace vulnerable …
- Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration
Mustafa S. Aljumaily, Hayder Kareem Abed, Nawar S. Alseelawi · 23 de septiembre de 2026
Cybersecurity literature has extensively documented the operational benefits of artificial intelligence (AI) for threat detection, incident response, and prevention, while raising qualitative concerns about over-automation, algorithmic bias, and analyst-skill erosion. What remains largely absent is …
- License Compliance in Open Source Cybersecurity Projects
Ahmed Shah, Selman Selman, Ibrahim Abualhaol · 21 de septiembre de 2026
Developers of cybersecurity software often include and rely upon open source software packages in their commercial software products. Before open source code is absorbed into a proprietary product, developers must check the package license to see if the project is permissively licensed, thereby allo…
- MiST: Mid-Training LLMs for Cybersecurity
Oded Ovadia, Elad Ben Zaken, Elad Guttman, Orly Moreno Kadosh · 17 de septiembre de 2026
Cybersecurity combines high-stakes analysis with complex technical language, making it an impactful and challenging domain for LLMs. We present MiST (Mid-trained Security Transformer), a suite of 8B and 32B models that achieve strong performance on public cybersecurity benchmarks. We use mid-trainin…
- Automating Attack Graph Construction for Agentic Pentesting. Towards Neuro-Symbolic Vulnerability Hunting
Oliver Stevanovic, Jasmin Wachter · 16 de septiembre de 2026
Logic attack graphs grounded in scanner output provide explicit and auditable attack path reasoning LLM-based agents lack. Integrating symbolic frameworks such as MulVAL to contemporary security workflows or agentic pipelines, however, requires translating scanner evidence to initial facts, and crea…
- A Graph-Based Approach for Mapping Kernel-Level Telemetry to MITRE ATT&CK
Matteo Lupinacci, Luigi Arena, Francesco Blefari, Angelo Furfaro · 14 de septiembre de 2026
Mapping observed system behavior to standardized frameworks like MITRE ATT&CK is essential for threat-informed defense, but remains largely manual. Existing automated methods depend on Cyber Threat Intelligence reports, which offer only retrospective accounts of attacks. Low-level telemetry, i.e. ke…
- Evaluating Context Segmentation in Locally Deployable SLMs for Cybersecurity CTF Tasks
Sebastiano Nordio, Michele Lotto · 14 de septiembre de 2026
The proliferation of highly capable open-weight Small Language Models (SLMs) democratizes access to advanced cybersecurity capabilities, posing a escalating risk as these models can bypass proprietary API guardrails when deployed locally. However, SLMs deployed as autonomous agents often struggle wi…
- AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring
Tsafac Nkombong Regine Cyrille, Hasan Dag, Reiner Creutzburg, Knut Haufe · 11 de septiembre de 2026
Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obl…
- X-amine509: Predicting the Practical Risk Level of Enterprise X.509 Certificates
Cameron Keith, Shubh Patel, JD Kilgallin, Caleb Shorter · 10 de septiembre de 2026
Enterprises managing large X.509 certificate inventories face a prioritization problem: deterministic analysis tools that precisely identify standards violations are indispensable for remediation, but applying them exhaustively across millions of certificates is operationally impractical. We present…
- Compute-Bounded Security Assurance - Coverage, Verification, and Response under Resource Constraints
Jithin VG, Ditto PS · 10 de septiembre de 2026
Additional inference compute can increase the number of correctly resolved security-assurance tasks, but repeated success, unique coverage, accepted evidence, and operational protection are different quantities. We develop a resource-constrained framework that separates them. For repeated conditiona…
- Cyber-Financial Contagion: Modeling the Propagation of an AI Vendor Compromise Through the Banking System
Alex Leytes · 10 de septiembre de 2026
The banking system now depends on a small set of shared artificial intelligence vendors for fraud screening, credit decisioning, anti-money-laundering triage, customer analytics, and internal decision support. This paper studies how a compromise inside one of those vendors can propagate along a chai…
- Feyospace-v1: How the Cyber Mercury Seven Trained Frontier Cyber Models
Zongjie Li, Alan Z. W, John Nicolas J, Walter H. F, Scott Donald L, Gordon Y. P, Deke X Jr · 9 de septiembre de 2026
Training capable cyber agents is often treated primarily as a problem of model scale, yet open-weight post-training is constrained more directly by the cost of executable environments, reliable multi-turn supervision, and access to strong teachers. We present a data-centric framework that addresses …
- A Translational Note on AI Safety Evaluation
Madhava Gaikwad · 9 de septiembre de 2026
Recent studies report that automated red-teaming finds more vulnerabilities, at lower cost, than human red-teaming on standard AI safety benchmarks, and some read this as evidence that human evaluators are becoming dispensable. The comparison measures one thing and the conclusion claims another. A b…
- The History Is the Detector: Executing CVE Patch History, End-to-End
Qiushi Wu, Kevin Eykholt, Youngja Park, Xiaokui Shu, Dhilung Kirat, Douglas Lee Schales, Ian Molloy · 7 de septiembre de 2026
Public vulnerability databases collect rich information about known software flaws, including their weakness types, affected components, and related patches. Fixing commits provide the exact code changes that removed these flaws. While these records capture why the original code was unsafe, they are…
- PatchBench: Evaluating AI Agents for Vulnerability Patching
Chihao Shen, Jiacheng Li, Aastha Mahajan, Jeffery Siyuan Tian, Yonghwi Kwon, Yizheng Chen · 4 de septiembre de 2026
AI agents have recently demonstrated strong performance in automated vulnerability patching. However, existing evaluations often validate a patch only by testing whether the provided Proof-of-Concept (PoC) input still triggers a crash. This leaves two key threats to validity: agents may reproduce me…
Otros asuntos del tema Sistemas de información
Los asuntos que la clasificación OpenAlex vincula al mismo tema, los más activos primero.
- Software Engineering Research853 artículos / 12 meses+218 %
- Information Retrieval and Search Behavior727 artículos / 12 meses+506 %
- Recommender Systems and Techniques600 artículos / 12 meses+154 %
- Expert finding and Q&A systems205 artículos / 12 meses+1175 %
- Blockchain Technology Applications and Security146 artículos / 12 meses+650 %
- Big Data and Digital Economy127 artículos / 12 meses+14 %
