Opin vísindi
Opin vísindi er varðveislusafn vísindaefnis og doktorsritgerða í opnum aðgangi á vegum íslenskra háskóla og Landsbókasafns Íslands - Háskólabókasafns.
Opinn aðgangur að rannsóknaniðurstöðum er í samræmi við 10. gr. laga nr. 3/2003 um opinberan stuðning við vísindarannsóknir sem og kröfur innlendra og erlendra rannsóknasjóða. Markmiðið með opnum aðgangi er að niðurstöður rannsókna séu aðgengilegar sem flestum óhindrað og án endurgjalds á rafrænu formi. Vistun í varðveislusafninu er varanleg og ætlað að tryggja aðgang að vísindaefni íslenskra háskóla í opnum aðgangi um ókomna tíð. Varðveislusafnið Opin vísindi er tengt við rannsóknagáttina IRIS og rannsóknaniðurstöður í opnum aðgangi sem eru skráðar í IRIS eru um leið vistaðar og gerðar aðgengilegar til framtíðar í varðveislusafninu. Með því að safna þessu efni saman í eitt safn verður aðgangur að því einfaldur og þægilegur fyrir alla sem vilja kynna sér það og geta þannig notið þess öfluga vísindastarfs sem fram fer í háskólum landsins.
Varðveislusafnið er OpenAIRE / OpenAIREplus samhæft og samrýmist kröfum sem gerðar eru um birtingu rannsóknaniðurstaðna úr verkefnum sem styrkt eru úr evrópsku rannsóknaáætlununum FP7 og H2020.
Varðveislusafnið notar opna hugbúnaðinn DSpace.
Opinn aðgangur að rannsóknaniðurstöðum er í samræmi við 10. gr. laga nr. 3/2003 um opinberan stuðning við vísindarannsóknir sem og kröfur innlendra og erlendra rannsóknasjóða. Markmiðið með opnum aðgangi er að niðurstöður rannsókna séu aðgengilegar sem flestum óhindrað og án endurgjalds á rafrænu formi. Vistun í varðveislusafninu er varanleg og ætlað að tryggja aðgang að vísindaefni íslenskra háskóla í opnum aðgangi um ókomna tíð. Varðveislusafnið Opin vísindi er tengt við rannsóknagáttina IRIS og rannsóknaniðurstöður í opnum aðgangi sem eru skráðar í IRIS eru um leið vistaðar og gerðar aðgengilegar til framtíðar í varðveislusafninu. Með því að safna þessu efni saman í eitt safn verður aðgangur að því einfaldur og þægilegur fyrir alla sem vilja kynna sér það og geta þannig notið þess öfluga vísindastarfs sem fram fer í háskólum landsins.
Varðveislusafnið er OpenAIRE / OpenAIREplus samhæft og samrýmist kröfum sem gerðar eru um birtingu rannsóknaniðurstaðna úr verkefnum sem styrkt eru úr evrópsku rannsóknaáætlununum FP7 og H2020.
Varðveislusafnið notar opna hugbúnaðinn DSpace.
Nýlega bætt við
The Impact of Emerging Phishing Threats : Assessing Quishing and LLM-generated Phishing Emails against Organizations
(Association for Computing Machinery, 2025-08-24) Weinz, Marie; Zannone, Nicola; Allodi, Luca; Apruzzese, Giovanni; Department of Computer Science
Modern organizations are persistently targeted by phishing emails. Despite advances in detection systems and widespread employee training, attackers continue to innovate, posing ongoing threats. Two emerging vectors stand out in the current landscape: QR-code baits and LLM-enabled pretexting. Yet, little is known about the effectiveness of current defenses against these attacks, particularly when it comes to real-world impact on employees. This gap leaves uncertainty around to what extent related countermeasures are justified or needed. Our work addresses this issue. We conduct three phishing simulations across organizations of varying sizes - from small-medium businesses to a multinational enterprise. In total, we send over 71k emails targeting employees, including: a "traditional"phishing email with a click-through button; a nearly-identical "quishing"email with a QR code instead; and a phishing email written with the assistance of an LLM and open-source intelligence. Our results show that quishing emails have the same effectiveness as traditional phishing emails at luring users to the landing webpage - which is worrying, given that quishing emails are much harder to identify even by operational detectors. We also find that LLMs can be very good "social engineers": in one company, over 30% of the emails opened led to visiting the landing webpage - a rate exceeding some prior benchmarks. Finally, we complement our study by conducting a survey across the organizations' employees, measuring their "perceived"phishing awareness. Our findings suggest a correlation between higher self-reported awareness and organizational resilience to phishing attempts.
The Ephemeral Threat : Assessing the Security of Algorithmic Trading Systems powered by Deep Learning
(Association for Computing Machinery, Inc, 2025-06-04) Rizvani, Advije; Apruzzese, Giovanni; Laskov, Pavel; Department of Computer Science
We study the security of stock price forecasting using Deep Learning (DL) in computational finance. Despite abundant prior research on vulnerability of DL to adversarial perturbations, such work has hitherto hardly addressed practical adversarial threat models in the context of DL-powered algorithmic trading systems (ATS). Specifically, we investigate the vulnerability of ATS to adversarial perturbations launched by a realistically constrained attacker. We first show that existing literature has paid limited attention to DL security in the financial domain - -which is naturally attractive for adversaries. Then, we formalize the concept of ephemeral perturbations (EP), which can be used to stage a novel type of attack tailored for DL-based ATS. Finally, we carry out an end-to-end evaluation of our EP against a profitable ATS. Our results reveal that the introduction of small changes to the input stock-prices not only (i)∼induces the DL model to behave incorrectly but also (ii)∼leads to the whole ATS to make suboptimal buy/sell decisions, resulting in a worse financial performance of the targeted ATS.
The CASTLE 2024 Dataset : Advancing the Art of Multimodal Understanding
(Association for Computing Machinery, Inc, 2025-10-27) Rossetto, Luca; Bailer, Werner; Dang-Nguyen, Duc Tien; Healy, Graham; Jónsson, Björn Pór; Kongmeesub, Onanong; Le, Hoang Bao; Rudinac, Stevan; Schöffmann, Klaus; Spiess, Florian; Tran, Allie; Tran, Minh Triet; Tran, Quang Linh; Gurrin, Cathal; Department of Computer Science
Egocentric video has seen increased interest in recent years, as it is used in a range of areas. However, most existing datasets are limited to a single perspective. In this paper, we present the CASTLE 2024 dataset, a multimodal collection containing ego- and exo-centric (i.e., first- and third-person perspective) video and audio from 15 time-aligned sources, as well as other sensor streams and auxiliary data. The dataset was recorded by volunteer participants over four days in a common location and includes the point of view of 10 participants, with an additional 5 fixed cameras providing an exocentric perspective. The entire dataset contains over 600 hours of UHD video recorded at 50 frames per second. In contrast to other datasets, CASTLE 2024 does not contain any partial censoring, such as blurred faces or distorted audio. The dataset is available via https://castle-dataset.github.io/.
SpacePhish : The Evasion-space of Adversarial Attacks against Phishing Website Detectors using Machine Learning
(Association for Computing Machinery, 2022-12-05) Apruzzese, Giovanni; Conti, Mauro; Yuan, Ying; Department of Computer Science
Existing literature on adversarial Machine Learning (ML) focuses either on showing attacks that break every ML model, or defenses that withstand most attacks. Unfortunately, little consideration is given to the actual cost of the attack or the defense. Moreover, adversarial samples are often crafted in the "feature-space", making the corresponding evaluations of questionable value. Simply put, the current situation does not allow to estimate the actual threat posed by adversarial attacks, leading to a lack of secure ML systems. We aim to clarify such confusion in this paper. By considering the application of ML for Phishing Website Detection (PWD), we formalize the "evasion-space"in which an adversarial perturbation can be introduced to fool a ML-PWD-demonstrating that even perturbations in the "feature-space"are useful. Then, we propose a realistic threat model describing evasion attacks against ML-PWD that are cheap to stage, and hence intrinsically more attractive for real phishers. Finally, we perform the first statistically validated assessment of state-of-the-art ML-PWD against 12 evasion attacks. Our evaluation shows (i) the true efficacy of evasion attempts that are more likely to occur; and (ii) the impact of perturbations crafted in different evasion-spaces. Our realistic evasion attempts induce a statistically significant degradation (3-10% at p < 0.05), and their cheap cost makes them a subtle threat. Notably, however, some ML-PWD are immune to our most realistic attacks (p=0.22). Our contribution paves the way for a much needed re-assessment of adversarial attacks against ML systems for cybersecurity.
SoK : The Impact of Unlabelled Data in Cyberthreat Detection
(Institute of Electrical and Electronics Engineers Inc., 2022) Apruzzese, Giovanni; Laskov, Pavel; Tastemirova, Aliya; Department of Computer Science
Machine learning (ML) has become an important paradigm for cyberthreat detection (CTD) in the recent years. A substantial research effort has been invested in the development of specialized algorithms for CTD tasks. From the operational perspective, however, the progress of ML-based CTD is hindered by the difficulty in obtaining the large sets of labelled data to train ML detectors. A potential solution to this problem are semisupervised learning (SsL) methods, which combine small labelled datasets with large amounts of unlabelled data. This paper is aimed at systematization of existing work on SsL for CTD and, in particular, on understanding the utility of unlabelled data in such systems. To this end, we analyze the cost of labelling in various CTD tasks and develop a formal cost model for SsL in this context. Building on this foundation, we formalize a set of requirements for evaluation of SsL methods, which elucidates the contribution of unlabelled data. We review the state-of-the-art and observe that no previous work meets such requirements. To address this problem, we propose a framework for assessing the benefits of unlabelled data in SsL. We showcase an application of this framework by performing the first benchmark evaluation that highlights the tradeoffs of 9 existing SsL methods on 9 public datasets. Our findings verify that, in some cases, unlabelled data provides a small, but statistically significant, performance gain. This paper highlights that SsL in CTD has a lot of room for improvement, which should stimulate future research in this field.
Flokkar í Opnum vísindum
Veldu flokk til að skoða.
- University of Iceland
- University of Akureyri
- Bifröst University
- Hólar University College
- IRIS
- Agricultural University of Iceland
- National and University Library of Iceland
- Iceland University of the Arts