https://journals.riverpublishers.com/index.php/JCSANDM/issue/feed Journal of Cyber Security and Mobility 2026-10-02T18:46:31+02:00 JCSM jcsm@riverpublishers.com Open Journal Systems <div class="JL3"> <div class="journalboxline"> <p><strong>Journal of Cyber Security and Mobility</strong></p> <p>Journal of Cyber Security and Mobility&nbsp;is an international, open-access, peer reviewed journal publishing original research, review/survey, and tutorial papers on all cyber security fields including information, computer &amp; network security, cryptography, digital forensics etc. but also interdisciplinary articles that cover privacy, ethical, legal, economical aspects of cyber security or emerging solutions drawn from other branches of science, for example, nature-inspired.<br><br><br></p> </div> </div> https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32988 A Privacy-Aware Multi-Scale Feature Fusion and Adaptive Class Optimization Method for Network Intrusion Detection Based on the SOR Model 2026-05-13T10:31:15+02:00 Jing Bai JingBai2026@outlook.com <p>As a critical educational carrier, university cyberspace bears the important mission of educating students. Network intrusion – unauthorized and improper activities such as penetration, theft, surveillance, and destruction targeting university networks – not only threatens campus cybersecurity but also constitutes illegal technical conduct that erodes the outcomes of higher education. As attack techniques grow increasingly sophisticated, university intrusion detection systems urgently need to accurately identify increasingly complex attack behaviors from massive, rapidly evolving campus network traffic. Integrating the SOR (Stimulus-Organism-Response) theoretical model, this study conceptualizes network attack events and abnormal traffic as external environmental stimuli (S). The system performs privacy-aware feature processing on raw network traffic data, reducing unnecessary collection of personal information of faculty and students from the technical source, and minimizing the model’s reliance on sensitive or directly identifiable traffic attributes. Parallel convolutional branches with different kernel sizes (3<span id="MathJax-Element-1-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m1&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#xD7;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m1" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.451em, 1000.64em, 2.297em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-2" class="mrow"><span id="MathJax-Span-3" class="mo" style="font-family: MathJax_Main;">×</span></span></span></span></span></span>3, 5<span id="MathJax-Element-2-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m2&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#xD7;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m2" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.451em, 1000.64em, 2.297em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-5" class="mrow"><span id="MathJax-Span-6" class="mo" style="font-family: MathJax_Main;">×</span></span></span></span></span></span>5, 7<span id="MathJax-Element-3-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m3&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#xD7;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m3" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.451em, 1000.64em, 2.297em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-8" class="mrow"><span id="MathJax-Span-9" class="mo" style="font-family: MathJax_Main;">×</span></span></span></span></span></span>7) are employed to extract local, medium-range, and global campus network traffic patterns from multiple receptive fields. The extracted multi-scale features are fused and then fed into a BiLSTM module (O). The optimized adaptive class balancing, precise intrusion recognition, and classification decisions are conceptualized as behavioral responses (R). To address the class imbalance problem, an adaptive class optimization strategy is incorporated into the training objective, assigning greater learning weights to minority classes and hard-to-classify attack categories at the loss function level, thereby constructing an intelligent intrusion detection theoretical-practical model for university network security. Experiments are evaluated on three benchmark datasets – CIC-IDS2017, UNSW-NB15, and CSE-CIC-IDS2018 – achieving 98.84% accuracy on CIC-IDS2017 and 99.98% accuracy on CSE-CIC-IDS2018, while robustness experiments under feature missing and noise perturbation conditions further validate its security and stability. In conclusion, the proposed SOR theory-driven privacy-aware multi-scale feature fusion and adaptive class optimization practical model provides an effective and practical technical solution for complex university network security scenarios, and can offer solid technical support for the construction of smart campus networks and ideological and political education platforms in universities.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32969 Optimized LSTM-Informer Model for Accurate Detection of Network Threats in Hospital Environments 2026-05-29T10:54:54+02:00 Hanteng Liu HantengLiu@outlook.com Zonggeng Chen oryouforme_m@163.com Yishun Xia yal0858@gmail.com Siqi Qiao cheesebrat@163.com Jiayu Ou 13929563330@139.com <p>In view of the complex hospital network environment, massive redundancy of security alarms, and lag in identification of real threats, this study proposes a hospital network security alarm model based on optimized Long Short-Term Memory (LSTM)-Informer. First, an attention-enhanced multi-dimensional alarm feature fusion module is constructed to integrate device logs, traffic data, and threat intelligence unique to hospital networks. Second, a hybrid bidirectional LSTM (BiLSTM) and improved Informer structure is designed to enhance long-range correlation mining and short-term burst alarm detection. The sparse attention mechanism is optimized with hospital threat-level priors to improve detection accuracy and reduce false alarms. The results show that among long-term correlation alarm types, the recall rate of port scanning, intranet lateral movement, and ransomware behavior are all <span id="MathJax-Element-1-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m1&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#x2265;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m1" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.306em, 1000.71em, 2.444em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-2" class="mrow"><span id="MathJax-Span-3" class="mo" style="font-family: MathJax_Main;">≥</span></span></span></span></span></span>94.5%, and the false alarm rate is <span id="MathJax-Element-2-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m2&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#x2264;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m2" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.306em, 1000.71em, 2.444em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-5" class="mrow"><span id="MathJax-Span-6" class="mo" style="font-family: MathJax_Main;">≤</span></span></span></span></span></span>2.8%, proving that the model effectively filters redundant alarms in long-term sequences. Among the short-term burst alarm types, the F1 score of malicious traffic injection and data leakage attempts is <span id="MathJax-Element-3-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m3&quot; display=&quot;inline&quot;&gt;&lt;mo&gt;&amp;#x2265;&lt;/mo&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m3" class="math" style="width: 0.853em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.789em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.306em, 1000.71em, 2.444em, -1000em); top: -2.124em; left: 0em;"><span id="MathJax-Span-8" class="mrow"><span id="MathJax-Span-9" class="mo" style="font-family: MathJax_Main;">≥</span></span></span></span></span></span>93.8%. Since the characteristics of phishing emails are more subtle, the false positive rate is slightly higher (4.0%), but it is still far lower than the traditional LSTM model (10.8%). The performance of the optimized model is significantly improved compared with the traditional model, and it can effectively alleviate the alarm fatigue of security operation personnel. This study provides an efficient alarm research and judgment solution for hospital network security intelligent operation and maintenance, helping to achieve active defense.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32995 Vulnerable Function Detection Using Lexical and Structural Features: An Empirical Study on PrimeVul and DiverseVul 2026-05-13T11:01:44+02:00 Jing Wang JingWang202611@outlook.com <p>A persistent challenge in software vulnerability detection is the failure of many existing approaches to handle highly imbalanced datasets reliably. In practical vulnerability datasets, vulnerable functions usually account for only a small proportion of all samples, which makes model evaluation highly sensitive to feature representation, threshold selection, and class distribution. To address this issue, this study proposes a lightweight feature-based detection pipeline for function-level vulnerability detection. The implemented method combines TF-IDF lexical features with numerical code-statistical features and evaluates several conventional machine-learning classifiers under a unified experimental protocol. PrimeVul is used as the primary dataset, while DiverseVul is introduced for external cross-dataset validation. The experiments include baseline comparison, feature ablation, threshold selection, sensitivity analysis, random-seed stability testing, imbalance-handling evaluation, and cross-dataset assessment. The results show that the proposed feature-based pipeline achieves stable performance under highly imbalanced settings. On the PrimeVul test set, the best configuration achieves an accuracy of approximately 0.9697, an F1-score in the range of 0.26–0.27, and a ROC-AUC above 0.83. The external evaluation on DiverseVul further indicates that the learned feature representation retains a certain degree of cross-dataset generalization. These findings suggest that carefully designed lightweight feature representations, combined with systematic multi-metric evaluation, can provide a reproducible and interpretable baseline for practical software vulnerability detection.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32996 Deepfake Image Detection Using Squeeze-and-Excitation Attention and Adaptive Threshold Optimization 2026-05-22T09:40:13+02:00 Chaoran Li ChaoranLi2026@outlook.com <p>Artificial intelligence-generated content (AIGC) has significantly improved the realism of manipulated facial images and videos, creating serious risks for social-network misinformation, content security, and digital trust. This study focuses on visual deepfake image detection rather than multimodal misinformation detection. Existing convolutional neural network (CNN)-based deepfake detectors commonly rely on a fixed decision threshold of 0.5, which may be unstable when facial images are affected by compression, cropping, noise, and distribution shifts in practical social-media environments. To improve detection reliability, this paper proposes a lightweight deepfake image detection framework that integrates a CNN backbone, a Squeeze-and-Excitation (SE) attention module, and an adaptive threshold optimization strategy. The key novelty of this work is not conventional threshold tuning alone, but a lightweight detection framework that jointly combines SE-based channel-wise feature recalibration, F1-score-driven adaptive threshold optimization, and leakage-aware group-level evaluation. Compared with post-hoc threshold tuning or calibration methods that mainly adjust the output boundary after training, the proposed framework improves both forgery-sensitive feature representation and the final classification decision mechanism. Specifically, the SE module enhances forgery-related feature representation through channel-wise feature recalibration, while the adaptive threshold is selected according to the F1-score, which is the harmonic mean of precision and recall. A group-level data split is also adopted to ensure that frames from the same video are not shared across the training, validation, and test sets, thereby reducing identity leakage. Experiments are conducted on a FaceForensics++-derived dataset using multiple CNN backbones and five-fold cross-validation. The evaluation metrics include accuracy, F1-score, the area under the receiver operating characteristic curve (ROC-AUC), and the area under the precision-recall curve (PR-AUC). The results show that threshold optimization improves the ResNet18 baseline accuracy from 0.8835 ± 0.0186 to 0.9016 ± 0.0151 and the F1-score from 0.8773 ± 0.0253 to 0.9042 ± 0.0138. Among the tested backbones, ResNet50 achieves the best cross-validation performance, with an accuracy of 0.9061 ± 0.0161 and a ROC-AUC of 0.9680 ± 0.0075. Under the strict group-level test setting, the proposed framework achieves 0.9960 accuracy and 0.9959 F1-score on the constructed test set. Compared with more complex detection pipelines. The proposed method is simple, computationally practical, and easy to integrate into common CNN-based deepfake detectors. Therefore, this work provides a practical visual security detection approach for social-media content verification and cyber-security applications.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/33142 EW-GAT: An Edge-Weighted Graph Attention Network with Multi-Source Feature Fusion for Encrypted Malicious Traffic Classification 2026-06-01T12:02:11+02:00 Junli Zong junli4562026@outlook.com <p>The increase in the number of encryption schemes for communication networks has resulted in a persistent challenge for network security, as malicious activities can be concealed within otherwise legitimate encrypted communication flows. Current methods using graph theory do not consider semantic behavior while creating links and assuming that all neighbors contribute equally to message transmission regardless of their importance to discriminatory power for fine-grained categories. The current work introduces a model for edge weight calculation with multi-source feature fusion named EW-GAT. A semantic similarity graph is constructed via cosine similarity and Top-<span id="MathJax-Element-1-Frame" class="MathJax" style="position: relative;" tabindex="0" role="presentation" data-mathml="&lt;math xmlns=&quot;http://www.w3.org/1998/Math/MathML&quot; id=&quot;S0.SSx1.p1.m1&quot; display=&quot;inline&quot;&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/math&gt;"><span id="S0.SSx1.p1.m1" class="math" style="width: 0.974em; display: inline-block;"><span style="display: inline-block; position: relative; width: 0.91em; height: 0px; font-size: 103%;"><span style="position: absolute; clip: rect(1.319em, 1000.91em, 2.367em, -1000em); top: -2.184em; left: 0em;"><span id="MathJax-Span-2" class="mrow"><span id="MathJax-Span-3" class="mi" style="font-family: MathJax_Math; font-style: italic;">K</span></span></span></span></span></span> sparsification, with similarity values directly embedded as edge weights to quantitatively encode behavioral closeness between flows. A multi-source fusion scheme integrates flow-level statistical features, KNN-based neighborhood representations, and class-prior signals from a gradient boosting model to enrich node representations. An edge-weighted attention mechanism further modulates attention coefficients with the pre-computed edge weights, enabling behavior-aware neighbor aggregation. Experiments on two benchmark datasets, CIC-IDS2017 and CSE-CIC-IDS2018, show that the proposed approach attains 99.59% and 99.53% Accuracy on the respective binary tasks, and 94.07% Accuracy with 94.20% Macro-F1 on the CIC-IDS2017 15-class task and 93.33% Accuracy with 93.14% Macro-F1 on the CSE-CIC-IDS2018 15-class task, consistently outperforming all baselines across both datasets. Ablation analysis reveals Macro-F1 drops of 9.29% and 9.73% on the two datasets when the similarity graph is replaced by a random graph, confirming the robustness of the three innovations across different network environments.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32983 Image Information Security Protection in the Big Data Era Based on Reversible Data Hiding in Encrypted Images 2026-06-04T13:06:45+02:00 JunYi Lu Lujunyi202512@163.com <p>Massive image sharing and cloud-based storage in big data environments have significantly increased the risks of privacy leakage, unauthorized tampering, and insecure transmission. To address these issues, a reversible data hiding in encrypted images (RDHEI) framework integrating reserved room before encryption (RRBE) and vacating room after encryption (VRAE) is proposed for secure image information protection. The method combines high-bit plane prediction compression, key-controlled image encryption, and ciphertext-domain adaptive embedding to simultaneously achieve high-capacity data hiding, strict permission separation, and lossless image recovery. In addition, an error reverse reduction mechanism is introduced to suppress pixel distortion and improve recovery stability. Experimental evaluation is conducted on the UCID public image dataset containing 1338 uncompressed color images with rich texture and structural characteristics, including natural scenes, urban buildings, portraits, vehicles, plants, animals, and indoor environments. Experimental results on the UCID dataset demonstrate that the proposed method achieves an embedding rate of 0.99 bpp, a payload capacity of 524000 bits, Peak Signal-to-Noise Ratio (PSNR) of 52.14 dB, and Structural Similarity Index Measure (SSIM) of 0.994. Meanwhile, the bit error rate is reduced to 0.028, the information entropy reaches 7.999, and the Number of Pixels Change Rate (NPCR) reaches 99.37%, indicating strong encryption randomness and resistance to differential attacks. Compared with Convolutional Neural Network-based Reversible Data Hiding (CNN-RDH) and Generative Adversarial Network-based Reversible Data Hiding (GAN-RDH) methods, the proposed framework achieves superior performance in embedding efficiency, recovery accuracy, visual quality, and computational efficiency. The proposed RDHEI framework provides an effective and scalable solution for secure image storage, privacy-preserving transmission, and encrypted multimedia sharing in large-scale big data applications.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/33024 Feature-Driven Framework for Interpretable Detection and Analysis of Android Malware Through Network and Application Behaviors 2026-06-14T19:02:29+02:00 Chao Tan xinlu_tech@163.com Xinlu Li xinlu_tech@163.com <p>This paper presents a complete framework for feature-driven Android malware detection that combines predictive modeling with explainable artificial intelligence to improve classification accuracy, interpretability, and operational dependability. The system initiates by examining network-flow metrics, including Source Port (SP), Initial Window Bytes Forward (IW), packet rates, and user activity indicators, derived from a publicly accessible dataset including 355,630 cases across four classifications: Adware, Scareware, SMS malware, and benign. Feature preprocessing utilizes the Variance Inflation Factor (VIF) analysis to eliminate multicollinearity to discern the most important variables, hence assuring a non-redundant and highly relevant feature collection. Subsequently, Gradient Boosting Classifier (XGBC) and Decision Tree Classifier (DTC) are augmented with metaheuristic optimization algorithms, Tailor Optimization Algorithm (TOA) and Spotted Deer Optimization Algorithm (SDOA), to boost convergence, stability, and generalization. Model interpretability is attained by Delta-XAI, which identifies SP, IW, and User Interaction/Write operations as the principal features, collectively representing approximately 80% of the explanatory power of the top features. Assessment by five-fold cross-validation indicates that the XGBC+TOA (XGTO) configuration attains an overall accuracy of 98.0%, exhibiting excellent precision and Matthews Correlation Coefficient (MCC), surpassing all other models. This framework combines feature-centric selection, enhanced learning, and explainable AI to deliver a dependable, interpretable, and pragmatic approach for identifying Android malware, thereby connecting data-driven analysis with practical cybersecurity implementations.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/33176 Robust Multimodal Deepfake Forensics for Digital Human Identity Protection in Mobile Multimedia Security 2026-07-10T01:09:00+02:00 Xiao Han xiaohan998@outlook.com <p>Deepfake forgeries pose increasing risks to digital identity protection, media integrity, and forensic reliability in mobile multimedia environments. Although recent detection methods have shown promising results on benchmark datasets, their performance often degrades under cross-domain distribution shifts and real-world perturbations, particularly in digital-human scenarios with complex appearance and motion patterns. To address this issue, this paper proposes a robust multimodal deepfake forensics framework for digital human identity protection. The proposed method jointly exploits visual, audio, and motion cues and further enhances deployment robustness through perturbation-aware learning, adversarial robustness enhancement, and domain-specific adaptation. Experimental results show that the EfficientNet-based implementation achieves ACC/F1-score/AUC values of 0.9245/0.9246/0.9728 on the benchmark setting. Under cross-dataset evaluation, the proposed framework obtains ACC/F1-score/AUC values of 0.8612/0.8729/0.9285 on Celeb-DFv2 and 0.8346/0.8481/0.9043 on WildDeepfake. After opera-domain fine-tuning, performance on OperaDeepfake improves from 0.8415/0.8568/0.9017 to 0.9317/0.9385/0.9781. Under five perturbation settings, the proposed robustness-oriented training strategy improves the F1-score by 0.0662-0.0909 compared with the baseline. These quantitative results demonstrate that the proposed framework provides a practical and robust solution for deepfake forensics, digital human identity protection, and mobile multimedia security applications.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/33255 Distributed Storage and Privacy Protection for Educational Blockchain Data 2026-07-16T11:15:36+02:00 Yufei Che manshan0606@163.com <p>To address the issues of static scheduling strategies, coarse-grained privacy protection, and their mutual independence in distributed storage of educational blockchain data, this study hypothesizes that a collaborative mechanism integrating dynamic closed-loop storage scheduling with adaptive graded desensitization can effectively balance storage efficiency and privacy protection strength. To test this hypothesis, this study conducts experiments on the Open University Learning Analytics Dataset (OULAD) educational dataset with six privacy levels and up to 5000 data blocks to evaluate throughput, latency, energy consumption, and classification accuracy. Key findings include: storage throughput reaching 35.6 MB/s with a write latency of 102.9 ms, response time and floating-point operations optimized to 85.6 ms and 33.5 MFLOP, respectively; encryption throughput of 18.7 MB/s with key generation time of only 3.9 ms; and correct classification of 548 out of 600 samples across six privacy levels with energy consumption of 20.5 J. Ablation studies confirm the irreplaceable roles of Coding Storage Allocation and the Hybrid-Dimensional Grid, while sensitivity analysis identifies the optimal configurations for the duplicate block count, learning rate, maximum privacy level, and contraction-expansion coefficient as 2, 0.001, 5, and 1.0 → 0.5, respectively. These results demonstrate that the proposed method effectively resolves the trade-off between storage efficiency and privacy protection for educational blockchain data, providing key technical support for trusted data management in education informatization.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/33369 Lightweight Edge-Based Intrusion Detection for Power Monitoring Systems 2026-07-20T11:37:16+02:00 Yan Li iyan@ha.sgcc.com.cn Cen Chen sunshinecen1@outlook.com Zhuo Lyu zhuanzhuan2325@sina.com Zhaoyang He hezhaoyang@huaqing.ai <p>The network security threats faced by the power monitoring system in the open network environment are becoming increasingly complex, and the attack forms are diversified and concealed. Undetected attacks may lead to abnormal monitoring data, control command failures, or even critical equipment shutdown, thereby threatening the security and stability of the power system. Therefore, network security protection methods that balance detection accuracy, response speed, and edge deployment efficiency have significant engineering application value. To improve the security protection capabilities and real-time response performance in a dynamic network environment, a network security protection method that integrates lightweight intelligent sensing and edge collaborative deployment is constructed. Through multi-source feature fusion and lightweight detection models, combined with the cloud-edge collaborative mechanism, efficient detection and low-latency response to complex attacks are achieved. Experiments showed that the Macro-averaged F1-score reached 0.93, which was 2.08–8.60% higher than that of baseline methods, respectively. The proportion of high-confidence samples of the proposed method was more than 77%, and it could still maintain an attack detection rate of more than 0.94 under different attack traffic proportions. The results show that the method achieves a good balance between detection accuracy, robustness and deployment efficiency, making it suitable for resource-constrained edge devices that require real-time detection and rapid response. This provides technical support for building a low-latency, deployable network security protection system for power monitoring systems.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility https://journals.riverpublishers.com/index.php/JCSANDM/article/view/32491 Blockchain Traceability and Visual Warning Based on Merkle Tree in Enterprise Data Assetization Transformation 2026-06-08T17:06:23+02:00 Qingtong Meng qingtong2026111@163.com <p>Large enterprise groups face issues such as low efficiency in data traceability and a disconnect between security and visualization in their data assetization transformation. Therefore, this paper raises a security threat perception and visualization warning model based on data visualization and blockchain traceability algorithm. This model combines Merkle Tree (MT), double hash chain, attribute encryption, and zero knowledge proof to achieve lightweight on chain auditing and privacy protection. It also collaborates with ForceTars2 and layered edge binding layout to generate dynamic risk topology, supporting full lifecycle trusted auditing and real-time threat perception. The experiment on the self-made enterprise supply chain threat perception dataset shows that the threat detection rate of the model is 98.11%, the false alarm rate is only 0.82%, the visual cognitive efficiency is 96.83%, the trusted data asset utilization rate is 96.82%, and the delay is controlled within 100 ms. Superior to existing mainstream solutions such as lightweight tracking algorithms based on MT and attribute based encryption privacy protection algorithms. The experimental results demonstrate that the model has good accuracy and applicability in enterprise level data security governance, providing an integrated governance solution with high concurrency, low latency, and high trustworthiness for data assetization transformation.</p> 2026-10-02T00:00:00+02:00 Copyright (c) 2026 Journal of Cyber Security and Mobility