<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity journal &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/cybersecurity-journal/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Fri, 09 Oct 2026 04:41:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>Cybersecurity journal &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Automated Tools Sharpen Cryptanalytic Attacks on Reduced-Round ChaCha</title>
		<link>https://scienmag.com/automated-tools-sharpen-cryptanalytic-attacks-on-reduced-round-chacha/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Fri, 09 Oct 2026 04:41:50 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[ARX cipher]]></category>
		<category><![CDATA[ARX cipher vulnerabilities]]></category>
		<category><![CDATA[automated attack optimization in cryptography]]></category>
		<category><![CDATA[automated cryptanalysis]]></category>
		<category><![CDATA[automated cryptanalysis tools]]></category>
		<category><![CDATA[bit puncturing]]></category>
		<category><![CDATA[ChaCha]]></category>
		<category><![CDATA[ChaCha cipher security assessment]]></category>
		<category><![CDATA[cryptanalysis of cipher round reduction]]></category>
		<category><![CDATA[cryptanalytic attacks on ChaCha]]></category>
		<category><![CDATA[Cybersecurity journal]]></category>
		<category><![CDATA[differential-linear cryptanalysis]]></category>
		<category><![CDATA[GPU correlation estimation]]></category>
		<category><![CDATA[key recovery]]></category>
		<category><![CDATA[MILP]]></category>
		<category><![CDATA[MILP and MIQCP methods in cryptography]]></category>
		<category><![CDATA[MIQCP]]></category>
		<category><![CDATA[NVIDIA RTX 4090 cryptanalysis hardware]]></category>
		<category><![CDATA[open-access cybersecurity research]]></category>
		<category><![CDATA[reduced-round ChaCha]]></category>
		<category><![CDATA[security margin]]></category>
		<category><![CDATA[stream cipher]]></category>
		<category><![CDATA[stream cipher security analysis]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=251861</guid>

					<description><![CDATA[Researchers combined MILP search, GPU-based correlation measurements and MIQCP modeling to produce a sharper estimate of a key differential-linear component of ChaCha, lowering the resource requirements of published attacks on 7- and 7.5-round variants while leaving the full 20-round cipher secure.]]></description>
										<content:encoded><![CDATA[<p>ChaCha, the stream cipher designed by Daniel Bernstein in 2008 as a variant of Salsa20, protects an enormous share of the world&#8217;s encrypted traffic. It runs inside TLS 1.3, QUIC, WireGuard, SSH, Noise and S/MIME 4.0, usually in the ChaCha-Poly1305 authenticated-encryption construction, and it owes its popularity to the fact that it is built entirely from three cheap operations: addition modulo 2 to the 32nd power, bitwise rotation, and XOR. This so-called ARX design makes ChaCha exceptionally fast in software, from cloud servers down to Internet-of-Things devices. But the same arithmetic simplicity that makes it fast also makes it a favorite target for cryptanalysts, who have spent nearly two decades probing how its security degrades as rounds are stripped away.</p>
<p>A new open-access study in the journal Cybersecurity, authored by Guoqiang Liu, Guiyan Ren, Bing Sun, Bo Yu and Chao Li of the National University of Defense Technology in Changsha, China, pushes that probing further by putting automation at the center of the analysis. The team combined mixed-integer linear programming (MILP) searches, massive correlation measurements on NVIDIA RTX 4090 graphics cards, and a mixed-integer quadratically constrained programming (MIQCP) model to re-examine the strongest known differential-linear attacks on reduced-round ChaCha. The result is a sharper, experimentally grounded estimate of a key component shared by several recent attacks, along with lower data and time complexity figures for 7- and 7.5-round variants of the cipher. Crucially, the full 20-round ChaCha deployed in real protocols remains far out of reach; the work measures the cipher&#8217;s security margin rather than signaling any practical threat to users.</p>
<p>The technique at the heart of the study is differential-linear cryptanalysis, a hybrid introduced by Langford and Hellman in 1994. Differential cryptanalysis, pioneered by Biham and Shamir against DES, tracks how a fixed difference between two plaintexts propagates through a cipher; linear cryptanalysis, introduced by Matsui, exploits statistical biases in linear approximations between input and output bits. The differential-linear combination splits a cipher into two sub-ciphers: a differential part that maps an input difference to an intermediate difference with probability p, and a linear part that connects that intermediate state to an output mask with correlation q. Under idealized independence assumptions, the combined distinguisher has correlation p times q squared, meaning an attacker can detect the bias given roughly the inverse square of that quantity in known keystream samples.</p>
<p>Reality is messier than those assumptions. Later work by Blondeau, Leander and Nyberg showed that the naive formula can be inaccurate, and Bar-On and colleagues introduced the Differential-Linear Connectivity Table at EUROCRYPT 2019 to handle dependencies between the two halves. For ChaCha specifically, the modern attack literature has converged on a four-round differential-linear component that starts from a two-bit input difference in the cipher&#8217;s state and ends, three and a half rounds later, at a five-bit output mask. Previous analyses estimated the correlation of this component at around 2 to the power of minus 32.2 by summing over a limited set of intermediate linear masks. The new paper attacks the same component from the differential side, enumerating the actual paths a difference can take rather than the masks it can be observed through.</p>
<p>The enumeration itself is a MILP tour de force. Exploiting the Lipmaa-Moriai formula for differential propagation through modular addition, the authors built a model whose objective minimizes the total differential weight of one-round characteristics. The search found all 128 one-round differentials with two-bit input differences and eight-bit output differences, including the 18 optimal characteristics previously reported by Bellini and coauthors at CT-RSA 2023. Focusing on the specific input difference used by the strongest published distinguishers, the model then enumerated 61 intermediate differences with differential weight at most 14, where weight denotes the negative binary logarithm of the transition probability. One path had weight 12, nine had weight 13, and 51 sat at the cutoff of 14.</p>
<p>Enumerating paths is only half the job; each path&#8217;s contribution to the overall correlation must be measured. The authors turned to GPUs, running Monte Carlo experiments with sample sizes between 2 to the 52nd and 2 to the 55th power, generating random inputs on the fly rather than storing them. A single reported correlation took roughly 24 hours of GPU time on average. Thirty-nine of the 61 paths yielded statistically reliable correlation estimates, each exceeding a Bonferroni-adjusted detection threshold for 39 simultaneous tests. The 22 remaining paths, two with probability 2 to the minus 13 and twenty with probability 2 to the minus 14, could not be resolved even at the largest sample size, but the authors bounded their total worst-case contribution at 2 to the minus 33.81, about sixteen percent of the measured sum. The signed weighted sum of the 39 resolved paths came to 2 to the power of minus 31.16, with a 95 percent confidence interval spanning roughly 2 to the minus 31.46 to 2 to the minus 30.92 when unresolved contributions are allowed to take adverse signs.</p>
<p>That refined four-round estimate of 2 to the minus 31.16 is the paper&#8217;s central number, and plugging it into published attack frameworks yields immediately improved complexity figures. Combining it with the Mixderive linear approximations of Li and colleagues, which have correlations of 2 to the minus 20.97 over two rounds and 2 to the minus 42.17 over two and a half rounds, gives distinguisher data complexities of 2 to the 160.20 for 7-round ChaCha and 2 to the 245.00 for 7.5 rounds, each a factor of about 2 to the 2.08 better than before. Applied to the ReBitP key-recovery framework of Wang and coauthors, which layers bit puncturing, partitioning, guessed-key covering and two-phase distillation on top of the same differential-linear component, the new estimate lowers the 7-round attack to 2 to the 125.91 data and 2 to the 140.00 time, and the 7.5-round attack to 2 to the 122.96 data and 2 to the 241.31 time, while preserving the original success probabilities of 88.27 and 99.99 percent respectively. A sensitivity analysis using the pessimistic endpoint of the confidence envelope shows the conclusions are robust to the residual statistical uncertainty.</p>
<p>The study&#8217;s second major contribution is a sobering audit of automated correlation prediction. The authors adapted an MIQCP framework, originally developed for the cipher Speck, that models how correlations propagate through ARX operations using continuous difference values, and tested it against GPU measurements on three fixed differential-linear distinguishers. The gaps were dramatic: predicted correlation weights exceeded experimental values by 26.86, 43.08 and 497.01 bits respectively, with the third prediction also carrying the wrong sign. A half-round-by-half-round comparison localized the failure, showing the gap stays below 0.3 bits through two rounds but explodes to 5.41 bits at 2.5 rounds and nearly 27 bits at three rounds. The authors trace the problem to two structural omissions: the model propagates a single scalar value per bit and cannot capture carry dependencies that couple successive modular additions within a ChaCha quarter-round, and it cannot represent the signed summation over competing paths that defines a differential-linear hull. Speck, with one modular addition per round, hides these issues; ChaCha&#8217;s quarter-round chains four additions together through XOR and rotation and exposes them brutally.</p>
<p>From this diagnosis the authors distill three concrete principles for the next generation of automated tools: link carry information across successive additions, for instance with joint carry-difference variables solved first on single quarter-rounds; enumerate the relevant differential-linear paths and sum their signed contributions explicitly, as the differential-cluster method does here; and validate predicted weights and signs on small-round instances with exact or GPU-measured correlations before trusting the model to search for long distinguishers. The paper&#8217;s supplementary material, including CUDA programs, C++ prediction code, MiniZinc models and a verification script for the complexity arithmetic, makes the entire pipeline reproducible.</p>
<p>For the cryptographic community, the study lands at an inflection point. The past three years have seen a rapid succession of improvements against reduced-round ChaCha, from syncopation at CRYPTO 2023 to bit puncturing at EUROCRYPT 2025 and divide-and-conquer trail enumeration at ASIACRYPT 2025, each shaving exponents off attacks that once seemed theoretical curiosities. The new work does not break ChaCha; it demonstrates that hybrid pipelines of MILP search, GPU-scale experimentation and optimization-based prediction can now quantify, and tighten, the exact components on which those attacks rest. As long as the security margin of the full 20-round cipher remains comfortable, that is precisely the kind of stress test a widely deployed primitive needs, and the methodological lessons about carry dependencies and signed path aggregation will echo well beyond ChaCha, informing automated cryptanalysis of the ARX ciphers that underpin lightweight security everywhere.</p>
<p><strong>Subject of Research:</strong> Automated differential-linear cryptanalysis of the reduced-round ChaCha stream cipher</p>
<p><strong>Article Title:</strong> Differential-linear cryptanalysis against ChaCha based on automated tools</p>
<p><strong>Article References:</strong> Liu, G., Ren, G., Sun, B., Yu, B., &amp; Li, C. (2026). Differential-linear cryptanalysis against ChaCha based on automated tools. <em>Cybersecurity, 9</em>(1), Article 228. <a href="https://doi.org/10.1186/s42400-026-00671-7" rel="noopener noreferrer">https://doi.org/10.1186/s42400-026-00671-7</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s42400-026-00671-7" rel="noopener noreferrer">10.1186/s42400-026-00671-7</a></p>
<p><strong>Keywords:</strong> ChaCha, stream cipher, differential-linear cryptanalysis, MILP, MIQCP, GPU correlation estimation, ARX cipher, key recovery, bit puncturing, security margin, automated cryptanalysis, Cybersecurity journal</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">251861</post-id>	</item>
		<item>
		<title>Physics-Aware AI Exposes Camouflaged Attacks Hiding Inside Power Grids</title>
		<link>https://scienmag.com/physics-aware-ai-exposes-camouflaged-attacks-hiding-inside-power-grids/</link>
		
		<dc:creator><![CDATA[Katie Riggs]]></dc:creator>
		<pubDate>Sun, 20 Sep 2026 23:21:06 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[advanced cybersecurity for smart grids]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[camouflage strategies in power systems]]></category>
		<category><![CDATA[CR-PGNN]]></category>
		<category><![CDATA[cyberattack detection in energy infrastructure]]></category>
		<category><![CDATA[Cybersecurity journal]]></category>
		<category><![CDATA[deep learning for grid security]]></category>
		<category><![CDATA[digital camouflage in power system monitoring]]></category>
		<category><![CDATA[false data injection attacks]]></category>
		<category><![CDATA[fault detection in electrical grids]]></category>
		<category><![CDATA[feature camouflage]]></category>
		<category><![CDATA[Graph Neural Networks]]></category>
		<category><![CDATA[graph neural networks for anomaly detection]]></category>
		<category><![CDATA[intelligent fault diagnosis in power distribution]]></category>
		<category><![CDATA[multi-relational graph]]></category>
		<category><![CDATA[neural network-based power grid analysis]]></category>
		<category><![CDATA[physics-informed machine learning]]></category>
		<category><![CDATA[power grid anomaly exposure techniques]]></category>
		<category><![CDATA[Power grid cybersecurity]]></category>
		<category><![CDATA[power grid security]]></category>
		<category><![CDATA[reinforcement learning]]></category>
		<category><![CDATA[relation camouflage]]></category>
		<category><![CDATA[smart grid]]></category>
		<category><![CDATA[voltage and phase angle manipulation detection]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=203868</guid>

					<description><![CDATA[Researchers have developed a physics-aware graph neural network that detects power grid anomalies hidden by manipulated measurements and deceptive network connections.]]></description>
										<content:encoded><![CDATA[<p>Modern power grids are under a quiet, persistent threat that conventional monitoring tools struggle to see. Faulty devices and malicious attackers no longer simply fail loudly or strike openly; instead, they deliberately disguise themselves, tweaking voltage readings, phase angles, and power injections until their abnormal signals look statistically indistinguishable from healthy operation. A new study published in the journal Cybersecurity introduces a graph neural network framework, called CR-PGNN, that is specifically engineered to strip away this digital camouflage and expose anomalies that would otherwise slip through unnoticed.</p>
<p>The research team, led by Ya Guo of the State Grid Henan Information &amp; Telecommunication Company in Zhengzhou, China, identified two distinct camouflage strategies that undermine existing graph-based detectors. The first, feature camouflage, involves manipulating local measurement data—current, voltage, temperature, or power figures—so that a failing or compromised device appears statistically similar to its healthy neighbors. The second, relation camouflage, is subtler still: an anomalous node deliberately embeds itself within a dense cluster of healthy equipment, so that when a standard graph neural network aggregates information from neighbors, the overwhelming volume of benign signals dilutes the anomaly into invisibility. Both strategies exploit the very mechanism that makes graph neural networks powerful for grid monitoring.</p>
<p>Graph neural networks have become a leading approach for anomaly detection across fraud detection and infrastructure monitoring because they model the grid as a multi-relational graph, with buses and transformers as nodes and physical transmission lines, geographic proximity, and logical control dependencies as edges. These models assume that anomalies deviate from healthy patterns and use neighborhood aggregation to surface them. But as the authors demonstrate, that assumption collapses when adversaries actively mimic normal statistics or hide among benign neighbors. In experiments across IEEE 14-, 57-, and 118-bus benchmark systems, conventional architectures such as GCN, GAT, and GraphSAGE suffered significant performance degradation under simulated camouflage attacks.</p>
<p>The key insight behind CR-PGNN is that while an attacker can falsify digital measurements, it is far harder to fake the underlying physics of the grid. The framework&#8217;s Multi-head Physics Consistency module checks whether reported measurements actually obey the alternating current power flow equations that govern real transmission lines. For each pair of connected nodes, the model computes a residual based on the mismatch between the power flow implied by voltage magnitudes, phase angles, and line reactance, and the power flow that the devices actually report. A node can make its numbers look statistically normal, but if those numbers violate electrical law, the residual grows—and the camouflage is exposed.</p>
<p>This physics-aware similarity measure is computed across multiple independent projection heads, allowing the model to simultaneously monitor different physical properties such as active power balance and reactive power compensation. Connections with high physical inconsistency are heavily penalized in the similarity score, effectively unmasking nodes that look normal but act in violation of grid physics. The authors note that a simplified lossless line approximation is used for efficiency, a reasonable choice for high-voltage transmission lines where series resistance is much smaller than reactance, keeping estimation error within roughly five percent.</p>
<p>To combat relation camouflage, CR-PGNN deploys a reinforcement learning agent that adaptively tunes filtering thresholds for each relation type and network layer. The agent observes summary statistics of the similarity distribution—its mean, variance, and skewness—along with the historical change in physical consistency, and then decides whether to tighten or loosen the neighborhood filter. Edges with similarity scores below the threshold are pruned before message passing occurs, preventing deceptive connections from diluting anomaly signals. The reward function balances detection F1-score, physical plausibility, and neighborhood size, discouraging both excessive sparsification and over-retention of suspicious links.</p>
<p>A final relation-aware gated aggregation layer fuses information from the filtered neighborhoods across all relation types, weighting physical connections—those constrained by electrical law—more heavily than auxiliary geographic or logical relations. Residual connections preserve information from previous layers and mitigate the over-smoothing that plagues deep graph networks. The entire system is trained jointly: the graph encoder optimizes a weighted cross-entropy loss to handle the extreme imbalance between normal and anomalous nodes, while the reinforcement learning policy is updated with policy gradient methods to maximize cumulative reward.</p>
<p>The experimental results are striking. Trained on simulated phasor measurement unit data from AC power flow simulations, with stealthy anomalies synthetically injected under controlled camouflage strategies, CR-PGNN consistently outperformed sixteen state-of-the-art baselines, including specialized fraud detectors such as CARE-GNN and PC-GNN and robust graph models such as MSDG and MAFI. On the largest, most complex IEEE 118-bus system, the framework achieved an F1-score of 0.875, meeting the authors&#8217; own criterion for camouflage resistance—maintaining an F1-score above 0.85 even when anomalies are strongly camouflaged. Statistical analysis of the physics consistency residuals revealed a dramatic separation: normal states clustered in a near-zero interval between 0 and 0.08, while camouflaged attacks ranged from 0.22 to 0.98, with a clean decision boundary at 0.2 and no observable overlap between the two distributions.</p>
<p>An ablation study confirmed that every component contributes meaningfully. Adding the physics consistency module on the 118-bus system raised precision from 0.812 to 0.892 and F1-score from 0.803 to 0.875, while the reinforcement learning pruning module lifted recall from 0.682 to 0.794 by preserving anomaly information under relation camouflage. Visualization of the learned relation selection probabilities showed that the agent assigns near-zero weights to edges propagating adversarial perturbations, isolating attacks from the rest of the network. The framework is also computationally practical: with roughly 0.34 million parameters, it achieves 8.4 milliseconds of inference latency per sample on an NVIDIA RTX 4090, and pruning cuts message passing costs by more than half—well within the real-time requirements of utility control centers.</p>
<p>The implications extend beyond the laboratory. As smart grids grow more interconnected and more dependent on sensors, communications, and automated controls, the attack surface for coordinated cyber-physical manipulation expands accordingly. Purely physics-based methods such as weighted least squares state estimation and interval analysis scored below 0.74 F1 across all test systems because they rely on fixed residual thresholds and cannot learn adaptive patterns, while purely data-driven models remain blind to statistically deceptive but physically inconsistent behavior. CR-PGNN&#8217;s hybrid approach—fusing domain-specific electrical laws with adaptive graph learning—suggests a promising path forward. The authors acknowledge limitations, including the assumption of a static grid topology and reliance on accurate physical measurements, and point to future work on temporal graph modeling and detection of coordinated multi-node attacks. Code and data are publicly available, offering grid operators and researchers a concrete tool in the escalating contest between grid defenders and the adversaries who hide in plain sight.</p>
<p><strong>Subject of Research:</strong> Camouflage-resistant graph neural networks for detecting stealthy anomalies and cyber-physical attacks in smart power grids</p>
<p><strong>Article Title:</strong> Camouflage-resistant graph neural networks for power grid anomaly detection</p>
<p><strong>Article References:</strong> Guo, Y., Wang, J., Liu, B., Li, D., Meng, Z., &amp; Zhu, Y. (2026). Camouflage-resistant graph neural networks for power grid anomaly detection. <em>Cybersecurity, 9</em>(1), Article 219. <a href="https://doi.org/10.1186/s42400-026-00656-6" rel="noopener noreferrer">https://doi.org/10.1186/s42400-026-00656-6</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s42400-026-00656-6" rel="noopener noreferrer">10.1186/s42400-026-00656-6</a></p>
<p><strong>Keywords:</strong> power grid security, graph neural networks, anomaly detection, reinforcement learning, feature camouflage, relation camouflage, physics-informed machine learning, smart grid, false data injection attacks, multi-relational graph, Cybersecurity journal, CR-PGNN</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">203868</post-id>	</item>
	</channel>
</rss>
