Score
Design, build, and evaluate end-to-end systems and models that detect and analyze abusive behavior or content by identifying abuse patterns, vectors, and signals; develop algorithms and detection models to recognize abuse cases and perform abuse-case analysis. Create and assess mitigation strategies and system-level defenses, and translate analytic findings into operational abuse-detection designs and signal-development pipelines.
To address the growing prevalence of cyberbullying, harassment, and other hostile behaviors on social media—and their associated emotional distress and mental health crises—this study proposes a socio-computational integrative paradigm. Methodologically, it introduces the first unified definition of “online aggressiveness” and establishes an interdisciplinary framework encompassing multi-source data collection, joint language–context modeling, machine learning/deep learning detection algorithms, social network analysis, and behavioral trajectory mining. Key contributions include: (1) a synergistic mechanism integrating content-based detection with behavior-oriented analysis; (2) empirical evidence demonstrating that sociological factors—including group dynamics and cultural context—significantly enhance model robustness and intervention interpretability; and (3) a systematic mapping of the field’s intellectual landscape and core challenges, thereby laying a theoretical foundation and technical roadmap for building trustworthy, interpretable, and actionable intelligent governance systems.
Social media platforms face critical challenges in addressing online harassment—including detection latency, inefficient response mechanisms, and the marginalization of victims—particularly among minority ethnic student populations. Method: Drawing on 230 surveys and 15 in-depth interviews, this study adopts a victim-centred design paradigm grounded in empirical victim experiences and self-defense strategies. It proposes the ARI system blueprint: integrating user-driven crowdsourced awareness (Awareness), perpetrator-oriented economic accountability (Repercussion), and personalized, transparent intervention (Intervention). The design employs mixed-method qualitative research, needs-driven prototyping, incentive modeling, and privacy-enhancing architecture. Contribution/Results: The work delivers a deployable system specification that reconciles privacy preservation, anonymity, and attributable accountability. It establishes a fair, sustainable, and technically feasible anti-abuse mechanism prototype for platform deployment.
This work addresses the limitations of existing abuse detection methods, which rely on static models and manual annotations and struggle to handle dynamic, context-sensitive online abusive behaviors. It proposes the first large language model (LLM)-integrated framework spanning the entire lifecycle of abuse detection, systematically encompassing label and feature generation, detection, appeal review, and audit governance. Bridging academic research and industrial practice, the study explores LLMs’ capabilities in contextual reasoning, policy interpretation, and cross-modal understanding. The authors delineate key architectural considerations for each phase, evaluate LLMs’ potential and limitations regarding interpretability, policy alignment, and multimodal fusion, and identify critical challenges—including latency, cost, determinism, adversarial robustness, and fairness—thereby offering a principled direction toward building reliable, accountable, large-scale abuse governance systems.
Online textual abuse—including hate speech and cyberbullying—seriously harms users’ mental health and erodes social trust. While large language models (LLMs) enhance detection capabilities, they may also generate harmful content, exacerbating governance challenges. This study systematically reviews text abuse detection methods in Chinese social media and introduces, for the first time, a “technical–ethical” co-analysis framework. We empirically evaluate leading LLMs across four critical dimensions: detection accuracy, bias, robustness, and risk of generating abusive content. By integrating text classification, psychosocial impact modeling, and adversarial generation analysis, we uncover the dialectical role of LLMs—both mitigating and amplifying online abuse. Our findings provide empirically grounded, actionable insights for safe AI governance, including a phased technical roadmap for responsible deployment and mitigation.
Existing behavioral malware detection research heavily relies on sandbox-derived features, leading to severe performance degradation—accuracy drops to 20%–50%, far below the reported >90%—when deployed on real endpoints. This exposes three fundamental challenges: label noise, distribution shift, and spurious feature reliance. To address this, we conduct the first large-scale empirical evaluation on real endpoints and propose a robust end-to-end training framework tailored for endpoint environments. Our approach integrates behavioral trajectory modeling, cross-environment distribution alignment, noise-robust learning, and telemetry-driven training leveraging real-world endpoint telemetry. Experiments demonstrate a 5%–30% relative improvement in detection accuracy over sandbox-trained baselines. Crucially, our work shifts the detection paradigm from sandbox-centric training to direct training on endpoint data. As part of this contribution, we release the first publicly available benchmark dataset comprising authentic endpoint behavioral trajectories, enabling reproducible, realistic evaluation of behavioral malware detection systems.
This work addresses the limitations of traditional automated approaches that extract only volatile indicators—such as IP addresses, domains, and file hashes—from cyber threat intelligence (CTI), resulting in rapidly obsolete detection rules. To overcome this, the authors propose a GraphRAG-based knowledge graph-enhanced retrieval framework that, for the first time, integrates graph-structured semantic information into the automated generation of SOC hunting plans. By combining large language models with unified prompt engineering, the method extracts persistent, high-order tactical cues from CTI reports to construct robust detection logic. Experimental evaluation on nine real-world CTI reports demonstrates that, even after all underlying indicators have been rotated, the proposed approach maintains 100% detection efficacy—significantly outperforming conventional vector-retrieval RAG, which achieves only 29%—thereby substantially enhancing coverage of adversaries’ advanced tactical behaviors.
This study addresses the challenge of achieving both high accuracy and interpretability in malicious code detection under static analysis settings where package metadata, maintainer information, and dynamic execution traces are unavailable. To this end, we propose the first interpretable detection framework that derives behavioral sequences from static call graphs, leverages a Transformer architecture to model these sequences, and integrates an explanation module to precisely localize suspicious source code regions. Designed to operate within the practical constraints of real-world DevSecOps pipelines, our approach significantly outperforms existing open-source tools on Python and JavaScript packages from PyPI and npm, meeting production-grade requirements in terms of detection accuracy, runtime overhead, memory consumption, and false positive rate. We also release Open Malicious-Code Bench, an open benchmark accompanying this work.
This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.
This study addresses the limitations of existing SysML verification approaches, which are often tool-dependent and restricted to performance properties, lacking support for automated validation of behavioral and interface requirements. To overcome these shortcomings, this work proposes a tool-agnostic, automated verification workflow driven by SysML test cases, integrating UML Testing Profile and behavioral diagram constructs to enable unified validation of multidimensional attributes—including behavior, timing, and state responses. The methodology was developed through a mixed-methods research strategy combining literature review and stakeholder interviews, and its efficacy was empirically validated across two independent SysML toolchains. The approach not only transcends the constraints of conventional parametric methods but also enables automatic traceability of verification results back to the original model elements.