{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:39:22Z","timestamp":1780634362626,"version":"3.54.1"},"reference-count":128,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T00:00:00Z","timestamp":1762128000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["High-Confidence Computing"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1016\/j.hcc.2025.100371","type":"journal-article","created":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T05:56:07Z","timestamp":1762322167000},"page":"100371","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"title":["Securing educational LLMs: A generalised taxonomy of attacks on LLMs and DREAD risk assessment"],"prefix":"10.1016","volume":"6","author":[{"given":"Farzana","family":"Zahid","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anjalika","family":"Sewwandi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lee","family":"Brandon","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vimal","family":"Kumar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9486-7833","authenticated-orcid":false,"given":"Roopak","family":"Sinha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.hcc.2025.100371_b1","series-title":"A survey of large language models","author":"Zhao","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b2","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2024.3365742","article-title":"A review on large language models: Architectures, applications, taxonomies, open issues and challenges","author":"Raiaan","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2025.100371_b3","series-title":"Prompt injection attack against LLM-integrated applications","author":"Liu","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b4","article-title":"A survey on large language models: Applications, challenges, limitations, and practical usage","author":"Hadi","year":"2023","journal-title":"Authorea Prepr."},{"key":"10.1016\/j.hcc.2025.100371_b5","series-title":"Large language model alignment: A survey","author":"Shen","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b6","series-title":"A comprehensive overview of large language models","author":"Naveed","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b7","doi-asserted-by":"crossref","unstructured":"Sanjay Kukreja, Tarun Kumar, Amit Purohit, Abhijit Dasgupta, Debashis Guha, A literature survey on open source large language models, in: Proceedings of the 2024 7th International Conference on Computers in Management and Business, 2024, pp. 133\u2013143.","DOI":"10.1145\/3647782.3647803"},{"key":"10.1016\/j.hcc.2025.100371_b8","series-title":"Scaling Language Modeling with Pathways","author":"Chowdhery","year":"2022"},{"key":"10.1016\/j.hcc.2025.100371_b9","series-title":"Llama: Open and efficient foundation language models","author":"Touvron","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b10","series-title":"Gemini: a family of highly capable multimodal models","author":"Team","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b11","series-title":"Falcon LLM: Open-source large language models","author":"Technology Innovation Institute (TII)","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b12","unstructured":"mhopkins-msft DOMARS, aviviano, Models."},{"key":"10.1016\/j.hcc.2025.100371_b13","unstructured":"mhopkins-msft DOMARS, aviviano, GPT-4."},{"key":"10.1016\/j.hcc.2025.100371_b14","series-title":"DeepSeek - into the unknown","author":"DeepSeek","year":"2025"},{"key":"10.1016\/j.hcc.2025.100371_b15","first-page":"1","article-title":"How should we change teaching and assessment in response to increasingly powerful generative artificial intelligence? Outcomes of the ChatGPT teacher survey","author":"Bower","year":"2024","journal-title":"Educ. Inf. Technol."},{"key":"10.1016\/j.hcc.2025.100371_b16","series-title":"Several categories of large language models (llms): A short survey","author":"Pahune","year":"2023"},{"issue":"16","key":"10.1016\/j.hcc.2025.100371_b17","doi-asserted-by":"crossref","DOI":"10.3390\/su151612451","article-title":"New era of artificial intelligence in education: Towards a sustainable multifaceted revolution","volume":"15","author":"Kamalov","year":"2023","journal-title":"Sustainability"},{"key":"10.1016\/j.hcc.2025.100371_b18","series-title":"2024 IEEE 14th Annual Computing and Communication Workshop and Conference","first-page":"0316","article-title":"Chatgpt in education, healthcare, and cybersecurity: Opportunities and challenges","author":"Mohammed","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b19","series-title":"Large language models for education: A survey","author":"Xu","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b20","series-title":"Large language models in cybersecurity: State-of-the-art","author":"Motlagh","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b21","series-title":"2023 Systems and Information Engineering Design Symposium","first-page":"274","article-title":"ChatGPT: Applications, opportunities, and threats","author":"Bahrini","year":"2023"},{"issue":"7","key":"10.1016\/j.hcc.2025.100371_b22","doi-asserted-by":"crossref","first-page":"184","DOI":"10.3390\/bdcc9070184","article-title":"LLMs in cyber security: Bridging practice and education","volume":"9","author":"Atlam","year":"2025","journal-title":"Big Data Cogn. Comput."},{"issue":"6","key":"10.1016\/j.hcc.2025.100371_b23","first-page":"182","article-title":"Cybersecurity for education","volume":"3","author":"Sadiku","year":"2023","journal-title":"Eur. J. Innov. Nonform. Educ."},{"key":"10.1016\/j.hcc.2025.100371_b24","first-page":"526","article-title":"Exploring cybersecurity implications in higher education","volume":"vol. 23","author":"Siphambili","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b25","series-title":"Education sector common breaches and cyber threats","author":"Sara","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b26","series-title":"4 cyberattacks that shook universities and colleges in the last year","author":"Asimily","year":"2024"},{"issue":"1","key":"10.1016\/j.hcc.2025.100371_b27","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1016\/j.infsof.2008.09.009","article-title":"Systematic literature reviews in software engineering \u2013 a systematic literature review","volume":"51","author":"Kitchenham","year":"2009","journal-title":"Inf. Softw. Technol."},{"key":"10.1016\/j.hcc.2025.100371_b28","series-title":"Threat modeling for drivers","author":"Microsoft Learn Challenge","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b29","article-title":"A comparative analysis of threat modelling methods: STRIDE, DREAD, VAST, PASTA, OCTAVE, and LINDDUN","author":"Naik","year":"2024","journal-title":"Authorea Prepr."},{"key":"10.1016\/j.hcc.2025.100371_b30","series-title":"The Car Hacker\u2019s Handbook: a Guide for the Penetration Tester","author":"Smith","year":"2016"},{"issue":"2","key":"10.1016\/j.hcc.2025.100371_b31","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2024.100211","article-title":"A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly","volume":"4","author":"Yao","year":"2024","journal-title":"High-Confid. Comput."},{"key":"10.1016\/j.hcc.2025.100371_b32","series-title":"Survey of vulnerabilities in large language models revealed by adversarial attacks","author":"Shayegani","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b33","series-title":"LLM platform security: Applying a systematic evaluation framework to openai\u2019s ChatGPT plugins","author":"Iqbal","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b34","doi-asserted-by":"crossref","DOI":"10.1109\/MNET.2024.3367788","article-title":"A comprehensive overview of backdoor attacks in large language models within communication networks","author":"Yang","year":"2024","journal-title":"IEEE Netw."},{"key":"10.1016\/j.hcc.2025.100371_b35","article-title":"Unveiling security, privacy, and ethical concerns of chatgpt","author":"Wu","year":"2023","journal-title":"J. Inf. Intell."},{"key":"10.1016\/j.hcc.2025.100371_b36","series-title":"Mapping LLM security landscapes: A comprehensive stakeholder risk assessment proposal","author":"Pankajakshan","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b37","series-title":"Beyond the safeguards: Exploring the security risks of chatgpt","author":"Derner","year":"2023"},{"issue":"1","key":"10.1016\/j.hcc.2025.100371_b38","first-page":"1","article-title":"Do ChatGPT and other AI chatbots pose a cybersecurity risk?: An exploratory study","volume":"15","author":"Sebastian","year":"2023","journal-title":"Int. J. Secur. Priv. Pervasive Comput. (IJSPPC)"},{"key":"10.1016\/j.hcc.2025.100371_b39","series-title":"Risk taxonomy, mitigation, and assessment benchmarks of large language model systems","author":"Cui","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b40","series-title":"Comprehensive assessment of jailbreak attacks against llms","author":"Chu","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b41","series-title":"Breaking down the defenses: A comparative survey of attacks on large language models","author":"Chowdhury","year":"2024"},{"issue":"1","key":"10.1016\/j.hcc.2025.100371_b42","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1186\/s42400-025-00361-w","article-title":"When llms meet cybersecurity: A systematic literature review","volume":"8","author":"Zhang","year":"2025","journal-title":"Cybersecurity"},{"issue":"4","key":"10.1016\/j.hcc.2025.100371_b43","doi-asserted-by":"crossref","DOI":"10.5195\/jmla.2018.513","article-title":"Covidence","volume":"106","author":"Kellermeyer","year":"2018","journal-title":"J. Med. Libr. Assoc."},{"key":"10.1016\/j.hcc.2025.100371_b44","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.infsof.2015.03.007","article-title":"Guidelines for conducting systematic mapping studies in software engineering: an update","volume":"64","author":"Petersen","year":"2015","journal-title":"Inf. Softw. Technol."},{"key":"10.1016\/j.hcc.2025.100371_b45","unstructured":"MITRE Corporation, Mitre Atlas. https:\/\/atlas.mitre.org\/."},{"key":"10.1016\/j.hcc.2025.100371_b46","unstructured":"AI Incident Database https:\/\/incidentdatabase.ai\/."},{"key":"10.1016\/j.hcc.2025.100371_b47","unstructured":"Sandy Dunn, LLM AI cybersecurity and governance checklist."},{"key":"10.1016\/j.hcc.2025.100371_b48","doi-asserted-by":"crossref","first-page":"396","DOI":"10.1016\/j.jss.2018.12.018","article-title":"Landscaping systematic mapping studies in software engineering: a tertiary study","volume":"149","author":"Khan","year":"2019","journal-title":"J. Syst. Softw."},{"key":"10.1016\/j.hcc.2025.100371_b49","series-title":"IJCAI","first-page":"983","article-title":"Character as pixels: A controllable prompt adversarial attacking framework for black-box text guided image generation models","author":"Kou","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b50","series-title":"Bloomberggpt: A large language model for finance","author":"Wu","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b51","series-title":"Text-to-image cross-modal generation: A systematic review","author":"\u017belaszczyk","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b52","article-title":"Adversarial attacks and defenses on text-to-image diffusion models: A survey","author":"Zhang","year":"2024","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.hcc.2025.100371_b53","series-title":"Adversarial attacks on multimodal agents","author":"Wu","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b54","series-title":"Generative AI under attack: Flowbreaking exploits trigger data leaks","author":"Nizan","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b55","series-title":"Suicide bot: New AI attack causes LLM to provide potential \u201cself-harm\u201d instructions","author":"Gadi","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b56","series-title":"LLM flowbreaking","author":"Willison","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b57","doi-asserted-by":"crossref","unstructured":"Sander Schulhoff, Jeremy Pinto, Anaum Khan, Louis-Fran\u00e7ois Bouchard, Chenglei Si, Svetlina Anati, Valen Tagliabue, Anson Kost, Christopher Carnahan, Jordan Boyd-Graber, Ignore this title and HackAPrompt: Exposing systemic vulnerabilities of LLMs through a global prompt hacking competition, in: Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, 2023, pp. 4945\u20134977.","DOI":"10.18653\/v1\/2023.emnlp-main.302"},{"key":"10.1016\/j.hcc.2025.100371_b58","series-title":"SoutheastCon 2025","first-page":"143","article-title":"Cyberattacks on large language models-attack detection and architecture adaptability","author":"Alla","year":"2025"},{"key":"10.1016\/j.hcc.2025.100371_b59","doi-asserted-by":"crossref","unstructured":"Kai Greshake, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, Mario Fritz, Not what you\u2019ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection, in: Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security, 2023, pp. 79\u201390.","DOI":"10.1145\/3605764.3623985"},{"key":"10.1016\/j.hcc.2025.100371_b60","series-title":"Adaptive attacks break defenses against indirect prompt injection attacks on LLM agents","author":"Zhan","year":"2025"},{"key":"10.1016\/j.hcc.2025.100371_b61","doi-asserted-by":"crossref","DOI":"10.1109\/ACCESS.2023.3300381","article-title":"From chatgpt to threatgpt: Impact of generative ai in cybersecurity and privacy","author":"Gupta","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2025.100371_b62","unstructured":"Surender\u00a0Suresh Kumar, M.L. Cummings, Alexander Stimpson, Strengthening LLM trust boundaries: a survey of prompt injection attacks, in: 2024 IEEE 4th International Conference on Human-Machine Systems, ICHMS, 2024, pp. 1\u20136."},{"key":"10.1016\/j.hcc.2025.100371_b63","series-title":"Scalable extraction of training data from (production) language models","author":"Nasr","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b64","series-title":"2023 IEEE Symposium on Security and Privacy","first-page":"346","article-title":"Analyzing leakage of personally identifiable information in language models","author":"Lukas","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b65","series-title":"PLeak: Prompt leaking attacks against large language model applications","author":"Hui","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b66","doi-asserted-by":"crossref","unstructured":"Wentao Wang, Han Xu, Yuxuan Wan, Jie Ren, Jiliang Tang, Towards adversarial learning: from evasion attacks to poisoning attacks, in: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, 2022, pp. 4830\u20134831.","DOI":"10.1145\/3534678.3542608"},{"issue":"3","key":"10.1016\/j.hcc.2025.100371_b67","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1007\/s13735-024-00334-8","article-title":"Adversarial attacks and defenses for large language models (LLMs): methods, frameworks & challenges","volume":"13","author":"Kumar","year":"2024","journal-title":"Int. J. Multimed. Inf. Retr."},{"key":"10.1016\/j.hcc.2025.100371_b68","series-title":"RED QUEEN: Safeguarding large language models against concealed multi-turn jailbreaking","author":"Jiang","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b69","series-title":"Catastrophic jailbreak of open-source llms via exploiting generation","author":"Huang","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b70","series-title":"Taking off the rose-tinted glasses: A critical look at adversarial ML through the lens of evasion attacks","author":"Eykholt","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b71","series-title":"Noisy neighbors: Efficient membership inference attacks against LLMs","author":"Galli","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b72","series-title":"Composite backdoor attacks against large language models","author":"Huang","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b73","series-title":"Prompt as triggers for backdoor attack: Examining the vulnerability in language models","author":"Zhao","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b74","series-title":"Data poisining attacks and LLMs chatbots: How experts are responding","author":"Antispoofing","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b75","series-title":"Persistent pre-training poisoning of LLMs","author":"Zhang","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b76","series-title":"ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing","first-page":"7745","article-title":"Poisonprompt: Backdoor attack on prompt-based large language models","author":"Yao","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b77","doi-asserted-by":"crossref","unstructured":"Bargav Jayaraman, David Evans, Are attribute inference attacks just imputation?, in: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 1569\u20131582.","DOI":"10.1145\/3548606.3560663"},{"key":"10.1016\/j.hcc.2025.100371_b78","series-title":"2021 IEEE European Symposium on Security and Privacy","first-page":"232","article-title":"On the (in) feasibility of attribute inference attacks on machine learning models","author":"Zhao","year":"2021"},{"key":"10.1016\/j.hcc.2025.100371_b79","series-title":"Multi-stage prompt inference attacks on enterprise LLM systems","author":"Balashov","year":"2025"},{"key":"10.1016\/j.hcc.2025.100371_b80","article-title":"Token-based prompt manipulation for automated large language model evaluation","author":"Gereti","year":"2024","journal-title":"Authorea Prepr."},{"issue":"2","key":"10.1016\/j.hcc.2025.100371_b81","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1109\/MIC.2021.3130380","article-title":"Adversarial machine learning for protecting against online manipulation","volume":"26","author":"Cresci","year":"2021","journal-title":"IEEE Internet Comput."},{"key":"10.1016\/j.hcc.2025.100371_b82","series-title":"Model leeching: An extraction attack targeting llms","author":"Birch","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b83","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al., Extracting training data from large language models, in: 30th USENIX Security Symposium, USENIX Security 21, 2021, pp. 2633\u20132650."},{"key":"10.1016\/j.hcc.2025.100371_b84","series-title":"Adversarial evasion attack efficiency against large language models","author":"Vitorino","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b85","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/s11633-019-1211-x","article-title":"Adversarial attacks and defenses in images, graphs and text: A review","volume":"17","author":"Xu","year":"2020","journal-title":"Int. J. Autom. Comput."},{"issue":"2","key":"10.1016\/j.hcc.2025.100371_b86","first-page":"102","article-title":"Unveiling security, privacy, and ethical concerns of ChatGPT","volume":"2","author":"Wu","year":"2024","journal-title":"J. Inf. Intell."},{"key":"10.1016\/j.hcc.2025.100371_b87","series-title":"Llm lies: Hallucinations are not bugs, but features as adversarial examples","author":"Yao","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b88","series-title":"Vocabulary attack to hijack large language model applications","author":"Levi","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b89","series-title":"Hijacking Large Language Models Via Adversarial In-Context Learning","author":"Qiang","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b90","series-title":"Hijacking large language models via adversarial in-context learning","author":"Qiang","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b91","series-title":"European Conference on Computer Vision","first-page":"484","article-title":"Square attack: a query-efficient black-box adversarial attack via random search","author":"Andriushchenko","year":"2020"},{"key":"10.1016\/j.hcc.2025.100371_b92","series-title":"LLM security - threats faced by large language models (LLMs)","author":"Gopi","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b93","article-title":"Jailguard: A universal detection framework for prompt-based attacks on LLM systems","author":"Zhang","year":"2025","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"10.1016\/j.hcc.2025.100371_b94","unstructured":"OWASP Top 10 for LLM Applications 2025."},{"key":"10.1016\/j.hcc.2025.100371_b95","series-title":"Securing large language models: Addressing bias, misinformation, and prompt attacks","author":"Peng","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b96","series-title":"Adversarial attacks and defenses in large language models: Old and new threats","author":"Schwinn","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b97","series-title":"Soft prompt threats: Attacking safety alignment and unlearning in open-source llms through the embedding space","author":"Schwinn","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b98","series-title":"Autodan: Generating stealthy jailbreak prompts on aligned large language models","author":"Liu","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b99","series-title":"Multi-step jailbreaking privacy attacks on chatgpt","author":"Li","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b100","series-title":"Virtual context: Enhancing jailbreak attacks with special token injection","author":"Zhou","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b101","series-title":"Scaling laws for data poisoning in llms","author":"Bowen","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b102","doi-asserted-by":"crossref","unstructured":"Takayuki Miura, Toshiki Shibahara, Naoto Yanai, Megex: Data-free model extraction attack against gradient-based explainable ai, in: Proceedings of the 2nd ACM Workshop on Secure and Trustworthy Deep Learning Systems, 2024, pp. 56\u201366.","DOI":"10.1145\/3665451.3665533"},{"issue":"11s","key":"10.1016\/j.hcc.2025.100371_b103","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3523273","article-title":"Membership inference attacks on machine learning: A survey","volume":"54","author":"Hu","year":"2022","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.hcc.2025.100371_b104","doi-asserted-by":"crossref","unstructured":"Parisa Kaghazgaran, Majid Alfifi, James Caverlee, Wide-ranging review manipulation attacks: Model, empirical study, and countermeasures, in: Proceedings of the 28th ACM International Conference on Information and Knowledge Management, 2019, pp. 981\u2013990.","DOI":"10.1145\/3357384.3358034"},{"key":"10.1016\/j.hcc.2025.100371_b105","doi-asserted-by":"crossref","unstructured":"Cong Liao, Haoti Zhong, Sencun Zhu, Anna Squicciarini, Server-based manipulation attacks against machine learning models, in: Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, 2018, pp. 24\u201334.","DOI":"10.1145\/3176258.3176321"},{"key":"10.1016\/j.hcc.2025.100371_b106","doi-asserted-by":"crossref","unstructured":"Tanmay Singla, Dharun Anandayuvaraj, Kelechi\u00a0G. Kalu, Taylor\u00a0R. Schorlemmer, James\u00a0C. Davis, An empirical study on using large language models to analyze software supply chain security failures, in: Proceedings of the 2023 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, 2023, pp. 5\u201315.","DOI":"10.1145\/3605770.3625214"},{"key":"10.1016\/j.hcc.2025.100371_b107","series-title":"Large language model supply chain: Open problems from the security perspective","author":"Hu","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b108","unstructured":"Obasdiaru Andrew, LLM Supply Chain Attack: Prevention Strategies."},{"key":"10.1016\/j.hcc.2025.100371_b109","series-title":"Securing large language models: Threats, vulnerabilities and responsible practices","author":"Abdali","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b110","series-title":"InputSnatch: Stealing input in LLM services via timing side-channel attacks","author":"Zheng","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b111","series-title":"2024 25th International Symposium on Quality Electronic Design","first-page":"1","article-title":"LLM-FIN: Large language models fingerprinting attack on edge devices","author":"Nazari","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b112","series-title":"What was your prompt? A remote keylogging attack on AI assistants","author":"Weiss","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b113","series-title":"Demystifying rce vulnerabilities in llm-integrated apps","author":"Liu","year":"2023"},{"key":"10.1016\/j.hcc.2025.100371_b114","article-title":"Leveraging large language models for autonomous red teaming in simulating advanced ransomware attacks","author":"Itonin","year":"2024","journal-title":"Affil. Available"},{"key":"10.1016\/j.hcc.2025.100371_b115","series-title":"When llms meet cybersecurity: A systematic literature review","author":"Zhang","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b116","series-title":"A new era in llm security: Exploring security concerns in real-world llm-based systems","author":"Wu","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b117","unstructured":"Edoardo Debenedetti, Giorgio Severi, Nicholas Carlini, Christopher\u00a0A. Choquette-Choo, Matthew Jagielski, Milad Nasr, Eric Wallace, Florian Tram\u00e8r, Privacy side channels in machine learning systems, in: 33rd USENIX Security Symposium, USENIX Security 24, 2024, pp. 48\u201361."},{"key":"10.1016\/j.hcc.2025.100371_b118","article-title":"Order vs. chaos: a language model approach for side-channel attacks","author":"Kulkarni","year":"2023","journal-title":"Cryptol. EPrint Arch."},{"issue":"3","key":"10.1016\/j.hcc.2025.100371_b119","article-title":"A threat risk modeling framework for geospatial weather information system (GWIS) a DREAD based study","volume":"1","author":"Rao","year":"2010","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"issue":"3","key":"10.1016\/j.hcc.2025.100371_b120","doi-asserted-by":"crossref","first-page":"509","DOI":"10.1007\/s10207-021-00566-3","article-title":"A risk-level assessment system based on the STRIDE\/DREAD model for digital data marketplaces","volume":"21","author":"Zhang","year":"2022","journal-title":"Int. J. Inf. Secur."},{"key":"10.1016\/j.hcc.2025.100371_b121","series-title":"Fuzzy logic approach for threat prioritization in agile security framework using DREAD model","author":"Singhal","year":"2013"},{"issue":"11","key":"10.1016\/j.hcc.2025.100371_b122","doi-asserted-by":"crossref","DOI":"10.1016\/j.asej.2025.103721","article-title":"Security risk assessment of internet of things health devices using DREAD and STRIDE models","volume":"16","author":"Zhai","year":"2025","journal-title":"Ain Shams Eng. J."},{"issue":"9","key":"10.1016\/j.hcc.2025.100371_b123","first-page":"3857","article-title":"Risk assessment threat modelling using an integrated framework to enhance security","volume":"102","author":"Subhash","year":"2024","journal-title":"J. Theor. Appl. Inf. Technol"},{"key":"10.1016\/j.hcc.2025.100371_b124","series-title":"National Vulnerability Database (NVD)","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b125","series-title":"Introducing study mode","author":"OpenAI","year":"2025"},{"key":"10.1016\/j.hcc.2025.100371_b126","series-title":"International Conference on Artificial Intelligence in Education","first-page":"324","article-title":"Jill Watson: A virtual teaching assistant powered by ChatGPT","author":"Taneja","year":"2024"},{"key":"10.1016\/j.hcc.2025.100371_b127","series-title":"Threat assessment in machine learning based systems","first-page":"arXiv","author":"Nganyewou\u00a0Tidjon","year":"2022"},{"key":"10.1016\/j.hcc.2025.100371_b128","series-title":"Threat modelling and risk analysis for large language model (LLM)-powered applications","first-page":"2406","author":"Burabari\u00a0Tete","year":"2024"}],"container-title":["High-Confidence Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000753?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295225000753?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T11:26:15Z","timestamp":1774869975000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2667295225000753"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":128,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["S2667295225000753"],"URL":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100371","relation":{},"ISSN":["2667-2952"],"issn-type":[{"value":"2667-2952","type":"print"}],"subject":[],"published":{"date-parts":[[2026,3]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Securing educational LLMs: A generalised taxonomy of attacks on LLMs and DREAD risk assessment","name":"articletitle","label":"Article Title"},{"value":"High-Confidence Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100371","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Author(s). Published by Elsevier B.V. on behalf of Shandong University.","name":"copyright","label":"Copyright"}],"article-number":"100371"}}