IFIP Open Access Digital Library
Not a member yet
    22614 research outputs found

    Keep Your Memory Dump Shut: Unveiling Data Leaks in Password Managers

    No full text
    International audiencePassword management has long been a persistently challenging task. This led to the introduction of password management software, which has been around for at least 25 years in various forms, including desktop and browser-based applications. This work assesses the ability of two dozen password managers, 12 desktop applications, and 12 browser plugins, to effectively protect the confidentiality of secret credentials in six representative scenarios. Our analysis focuses on the period during which a Password Manager (PM) resides in the RAM. Despite the sensitive nature of these applications, our results show that across all scenarios, only three desktop PM applications and two browser plugins do not store plaintext passwords in the system memory. Oddly enough, at the time of writing, only two vendors recognized the exploit as a vulnerability, reserving CVE-2023-23349, while the rest chose to disregard or underrate the issue

    Xproofs: New Aggregatable and Maintainable Matrix Commitment with Optimal Proof Size

    No full text
    International audienceVector Commitment (VC) enables one to commit to a vector, and then the element at a specific position can be opened, with proof of consistency to the initial commitment. VC is a powerful primitive with various applications, including stateless cryptocurrencies. Recently, matrix commitment Matproofs (Liu and Zhang CCS 2022), as an extension of VC, has been proposed to reduce the communication and computation complexity of VC-based cryptocurrencies. However, Matproofs requires linear-sized public parameters, and the aggregated proof size may also increase linearly with the number of individual proofs aggregated. Additionally, the proof updating process involves a third party, known as Proof-Serving Nodes (PSNs), which leads to extra storage and communication overhead. In this paper, we first propose a multi-dimensional variant of matrix commitment and construct a new matrix commitment scheme for two-dimensional matrix, called 2D-Xproofs, which achieves optimal aggregated proof size without using PSNs. Furthermore, we present a highly maintainable three-dimensional scheme, 3D-Xproofs, which updates all proofs within sublinear time in the size of the committed matrix without PSNs’ assistance. More generally, we could further increase the matrix dimensionality to achieve more efficient proof updates. Finally, we demonstrate the security of our schemes, showing that both schemes are position binding. We also implement both schemes, and the results indicate that our schemes enjoy constant-sized aggregated proofs and sublinear-sized public parameters, and the proof update time in 3D-Xproofs is 2.5×\times × faster than Matproofs

    Human-In-The-Loop Based Success Rate Prediction for Medical Crowdfunding

    No full text
    Part 1: Biomedical/ClassificationInternational audienceMedical crowdfunding serves as a pivotal means of donor-driven funding to assist individuals unable to afford medical expenses. However, challenges such as a low success rate and suboptimal fundraising performances have garnered significant attention from medical crowdfunding platforms. This study employs a comprehensive framework combining neural network and tree models, augmented by Human-In-The-Loop (HITL), to predict the success rates of medical crowdfunding campaigns and identify the crucial determinants of fundraising effectiveness. Our approach enhances model interpretability, offering insights into the prediction and inference processes, and incorporates human feedback at various stages of model training and testing. We apply the method to a structured dataset from a leading medical crowdfunding platform. The findings indicate that our method achieves accuracy of 94.9%, AUC value of 98.2%, recall rate of 86.4%, and F1 score of 89.2% on the binary classification task. Further analysis reveals the primary factors influencing crowdfunding success to be the target amount and the duration of the fundraising campaign. These results prove the efficacy of incorporating HITL into the model development process, markedly enhancing performance and facilitating a deeper understanding of both the dataset and model prediction

    Ensemble Strategy Based Hyper-heuristic Evolutionary Algorithm for Many-Objective Optimization

    No full text
    Part 3: Neural and Evolutionary ComputingInternational audienceMany-objective Optimization problems (MaOPs), with four or more objectives are difficult to solve, is a kind of common optimization problems in actual industrial production. In recent years, a large number of many-objective optimization algorithms (MaOEAs) have been proposed to solve various types of MaOPs. However, in practical problems, it is usually hard to improve the existing optimization algorithms or make a lot of attempts for MaOEAs because the true Pareto surface is usually unknown in a new MaOPs, which is a time-consuming and uncertain task. In this paper, inspired by the selective hyper heuristic optimization algorithm, we propose an integrated hyper-heuristic many-objective optimization algorithm (MaOEA-EH), which can integrate the existing advanced MaOEAs by simulating the PBFT consensus mechanism in the blockchain, and select the best algorithm for the current problem through the voting-election method in the iterative process. Numerical results show that our algorithm performs well on various many-objective problems

    Genetic Algorithm Driven by Translational Mutation Operator for the Scheduling Optimization in the Steelmaking-Continuous Casting Production

    No full text
    Part 3: Neural and Evolutionary ComputingInternational audienceThe scheduling optimization of industrial processes is crucial for enhancing production capacity and minimizing energy consumption. In the realm of continuous casting, the expansion of the scheduling scale and the increasing number of scheduling objects pose challenges for genetic algorithms in swiftly generating optimal solutions that adhere to constraints. Prolonged scheduling decision times and difficulties in ensuring constant pouring constraints are critical issues that require urgent resolution in the continuous casting scheduling problem within steelmaking. This paper proposes a genetic algorithm driven by translational mutation operator for the scheduling optimization in the steelmaking-continuous casting production named TMGA. Incorporating continuous pouring information in the encoding process guarantees uninterrupted pouring during the casting stage. Furthermore, applying the translational mutation operator is instrumental in elevating the search efficiency for the global optimal solution, consequently diminishing scheduling decision times. To validate the effectiveness of the proposed approach, this study conducts a rigorous examination involving a numerical simulation case and two ablation experiments. The experimental results demonstrate the superior performance of TMGA compared to other methods

    A BERT-Based Model for Legal Document Proofreading

    No full text
    Part 2: Natural Language ProcessingInternational audienceLegal documents require high precision and accuracy in language use, leaving no room for grammatical and spelling errors. To address the issue, this paper proposes a novel application of the BERT pre-trained language model for legal document proofreading. The BERT-based model is trained to detect and correct legal texts’ grammatical and spelling errors. On a dataset of annotated legal documents, we experimentally show that our BERT-based model significantly outperforms state-of-the-art proofreading models in precision, recall, and F1 score, showing its potential as a valuable tool in legal document preparation and revision processes. The application of such advanced deep learning techniques could revolutionise the field of legal document proofreading, enhancing accuracy and efficiency

    Question Answering Systems Based on Pre-trained Language Models: Recent Progress

    No full text
    Part 2: Natural Language ProcessingInternational audienceAlthough Pre-trained Language Model (PLM) ChatGPT as a Question-Answering System (QAS) is so successful, it is still necessary to study further the QASs based on PLMs. In this paper, we survey state-of-the-art systems of this kind, identify the issues that current researchers are concerned about, explore various PLM-based methods for addressing them, and compare their pros and cons. We also discuss the datasets used for fine-tuning the corresponding PLMs and evaluating these PLM-based methods. Moreover, we summarise the criteria for evaluating these methods and compare their performance against these criteria. Finally, based on our analysis of the state-of-the-art PLM-based methods for QA, we identify some challenges for future research

    Credit Default of P2P Online Loans Based on Logistic Regression Model Under Factor Space Theory Risk Prediction Research

    No full text
    Part 5: Business Intelligence and Risk ControlInternational audienceP2P, as the most representative online lending platform with a long history of personal credit development, can provide powerful data support for exploring the problem of personal credit default risk, and Logistic Regression plays an important role in machine learning, and the current research on Logistic Regression mainly stays at the application level. Therefore, based on the Factor Space theory to further deepen the interpretation of Logistic Regression, explore the obvious and hidden relationship of the factors behind it, and give a reasonable expression of Logistic Regression from the perspective of the obvious and hidden factors, take the U.S. lending club as an example, choose the lender information data of the whole year of 2019, and establish the P2P online credit default Logistic Regression prediction model. Considering that the conditional factors contain multiple value states, the One-Hot idea is introduced to improve the precision of the algorithm. The accuracy, recall and other evaluation indexes are chosen to compare and analyse the prediction effect of the model. The results of the model show that Logistic Regression can effectively predict the credit default risk of personal credit, and also provide a more in-depth explanation for the generation of personal credit default risk in the context of new personal loans

    Secure and Negotiate Scheme for Vehicle-to-Vehicle Communications in an IoV

    No full text
    Part 4: Recommendation and Social ComputingInternational audienceThe exchange of real-time data between vehicle-to-vehicle communications is crucial in the Internet of Vehicles (IoV) for vehicle-intelligent decisions. However, malicious and false communication data may cause serious personal safety accidents. Confirming the authenticity of the identities of both parties and encrypting communication content before communication is the first line of defense to ensure system security. Therefore, to secure the vehicle-to-vehicle communications, this paper proposes a secure and efficient authentication and key agreement scheme with lightweight operation. Our scheme achieves vehicle-to-vehicle authentication and establishes a session key to encrypt subsequent communication content with only lightweight operations such as symmetric encryption algorithms and hash functions. Furthermore, our scheme provides many ideal attributes, such as forward secrecy, which ensures that the final compromised of the system will not affect the previous communication content. Besides, we prove the security of the proposed scheme through heuristic analysis and BAN logic analysis and analyze the performance of the proposed scheme via comparing the computational cost and communication cost with three state-of-the-art related schemes. The results show that the proposed scheme has high communication efficiency

    0

    full texts

    22,614

    metadata records
    Updated in last 30 days.
    IFIP Open Access Digital Library
    Access Repository Dashboard
    Do you manage Open Research Online? Become a CORE Member to access insider analytics, issue reports and manage access to outputs from your repository in the CORE Repository Dashboard! 👇