{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T18:08:26Z","timestamp":1783966106553,"version":"3.55.0"},"reference-count":40,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T00:00:00Z","timestamp":1761696000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Email continues to serve as a primary vector for cyber-attacks, with phishing, spoofing, and polymorphic malware evolving rapidly to evade traditional defences. Conventional email security systems, often reliant on static, signature-based detection struggle to identify zero-day exploits and protect user privacy in increasingly data-driven environments. This paper introduces TwinGuard, a privacy-preserving framework that leverages digital twin technology to enable adaptive, personalised email threat detection. TwinGuard constructs dynamic behavioural models tailored to individual email ecosystems, facilitating proactive threat simulation and anomaly detection without accessing raw message content. The system integrates a BERT\u2013LSTM hybrid for semantic and temporal profiling, alongside federated learning, secure multi-party computation (SMPC), and differential privacy to enable collaborative intelligence while preserving confidentiality. Empirical evaluations were conducted using both synthetic AI-generated email datasets and real-world datasets sourced from Hugging Face and Kaggle. TwinGuard achieved 98% accuracy, 97% precision, and a false positive rate of 3%, outperforming conventional detection methods. The framework offers a scalable, regulation-compliant solution that balances security efficacy with strong privacy protection in modern email ecosystems.<\/jats:p>","DOI":"10.3390\/jcp5040091","type":"journal-article","created":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T03:44:39Z","timestamp":1761795879000},"page":"91","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["TwinGuard: Privacy-Preserving Digital Twins for Adaptive Email Threat Detection"],"prefix":"10.3390","volume":"5","author":[{"given":"Taiwo Oladipupo","family":"Ayodele","sequence":"first","affiliation":[{"name":"School of Technology and Maritime Industry, Southampton Solent Universitries, Southampton SO14 0YN, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,29]]},"reference":[{"key":"ref_1","unstructured":"Verizon (2025, October 11). Data Breach Investigations Report 2024. Available online: https:\/\/www.verizon.com."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Jabbar, H., and Al-Janabi, S. (2025). AI-Driven Phishing Detection: Enhancing Cybersecurity with Reinforcement Learning. J. Cybersecur. Priv., 5.","DOI":"10.3390\/jcp5020026"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Thakur, K., Ali, M.L., Obaidat, M.A., and Kamruzzaman, A. (2023). A systematic review on deep learning-based phishing email detection. Electronics, 12.","DOI":"10.3390\/electronics12214545"},{"key":"ref_4","first-page":"374","article-title":"Towards federated learning at scale: System design","volume":"1","author":"Bonawitz","year":"2019","journal-title":"Proc. Mach. Learn. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Thapa, C., Tang, J.W., Abuadbba, A., Gao, Y., Camtepe, S., Nepal, S., Almashor, M., and Zheng, Y. (2023). Evaluation of federated learning in phishing email detection. Sensors, 23.","DOI":"10.3390\/s23094346"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Tao, F., Zhang, M., and Nee, A.Y.C. (2019). Digital Twin Driven Smart Manufacturing, Elsevier.","DOI":"10.1016\/B978-0-12-817630-6.00010-2"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Lucchese, M., Salerno, G., and Pugliese, A. (2024). A Digital Twin-Based Approach for Detecting Cyber\u2013Physical Attacks in ICS Using Knowledge Discovery. Appl. Sci., 14.","DOI":"10.3390\/app14198665"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s10462-024-10805-3","article-title":"A review of digital twins and their application in cybersecurity based on artificial intelligence","volume":"57","author":"Rathore","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"3906","DOI":"10.14778\/3685800.3685815","article-title":"SecuDB: An in-enclave privacy-preserving and tamper-resistant relational database","volume":"17","author":"Yang","year":"2024","journal-title":"Proc. VLDB Endow."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Vialar, L., Menetrey, J., Schiavoni, V., and Felber, P. (2024). BlindexTEE: A blind index approach towards TEE-supported encrypted DBMS. Stabilization, Safety, and Security of Distributed Systems, Springer. SSS 2024, Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-031-74498-3_19"},{"key":"ref_11","unstructured":"Wang, Q., Cui, S., Zhou, L., Wu, O., Zhu, Y., and Russello, G. (June, January 30). EnclaveTree: Privacy-preserving data stream training and inference using TEE. Proceedings of the A.C.M. Asia Conference Computer and Communications Security, Nagasaki, Japan."},{"key":"ref_12","unstructured":"Siemens, A.G. (2024). Digital Twin Applications in Smart Manufacturing. Siemens White Paper, Siemens AG."},{"key":"ref_13","unstructured":"IBM (2025). Maximo Application Suite: Digital Twins for Asset Performance, IBM Research."},{"key":"ref_14","unstructured":"Tech, U.K. (2025, October 11). Future Defence Success in the UK Will Depend on Digital Twins. Available online: https:\/\/www.techuk.org\/resource\/future-defence-success-in-the-uk-will-depend-on-digital-twins.html."},{"key":"ref_15","unstructured":"Wisdiam (2025, October 11). Boeing Hit by LockBit Ransomware. Available online: https:\/\/wisdiam.com\/publications\/recent-cyber-attacks-manufacturing-industry."},{"key":"ref_16","unstructured":"SOCRadar (2025, October 11). Denso Supply Chain Breach. Available online: https:\/\/socradar.io\/major-cyber-attacks-manufacturing-industry-in-2025."},{"key":"ref_17","unstructured":"McKinsey & Company (2025). Digital Twins in Supply Chain Optimization, McKinsey Insights."},{"key":"ref_18","unstructured":"Jaber, A., Al-Khafaji, A., and Al-Sammarraie, A. (2025, January 3\u20137). A comprehensive state-of-the-art review for digital twin: Cybersecurity perspectives and open challenges. Proceedings of the A.C.M. S.I.G.K.D.D. Conference Knowledge Discovery and Data Mining, Toronto, ON, Canada."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1007\/s10462-025-11170-5","article-title":"Exploring privacy mechanisms and metrics in federated learning","volume":"58","author":"Shenoy","year":"2025","journal-title":"Artif. Intell. Rev."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Shalabi, E., Khedr, W., Rushdy, E., and Salah, A. (2025). A comparative study of privacy-preserving techniques in federated learning: A performance and security analysis. Information, 16.","DOI":"10.3390\/info16030244"},{"key":"ref_21","unstructured":"Face, H., and Enron and SpamAssassin Email Datasets (2025, October 11). Hugging Face. Available online: https:\/\/huggingface.co\/datasets\/LLM-PBE\/enron-email."},{"key":"ref_22","unstructured":"Cratchley, E. (2025, October 11). Email Phishing Dataset. Available online: https:\/\/www.kaggle.com\/datasets\/ethancratchley\/email-phishing-dataset."},{"key":"ref_23","unstructured":"Munshaw, J. (2025, October 11). How Are Attackers Using QR Codes in Phishing Emails and Lure Documents?. Available online: https:\/\/blog.talosintelligence.com\/how-are-attackers-using-qr-codes-in-phishing-emails-and-lure-documents."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Vassilev, A., Oprea, A., Fordyce, A., Anderson, H., Davies, X., and Hamin, M. (2025). Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, National Institute of Standards and Technology. NIST AI 100-2e2025.","DOI":"10.6028\/NIST.AI.100-2e2023"},{"key":"ref_25","unstructured":"Devlin, J., Chang, M.-W., Lee, K., and Toutanova, K. (2019, January 2\u20137). BERT: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the NAACL-HLT, Minneapolis, MN, USA."},{"key":"ref_26","first-page":"327","article-title":"A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities","volume":"76","author":"Alshamrani","year":"2018","journal-title":"Comput. Sec."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"134","DOI":"10.1016\/j.clsr.2017.05.015","article-title":"EU General Data Protection Regulation: Changes and implications for personal data collecting companies","volume":"34","author":"Rohunen","year":"2018","journal-title":"Comput. Law Secur. Rev."},{"key":"ref_28","first-page":"1","article-title":"An Introduction to the California Consumer Privacy Act (CCPA)","volume":"36","author":"Goldman","year":"2020","journal-title":"Santa Clara Univ. Leg. Stud. Res. Pap."},{"key":"ref_29","unstructured":"Ma, J., Saul, L.K., Savage, S., and Voelker, G.M. (July, January 28). Beyond blacklists: Learning to detect malicious web sites from suspicious URLs. Proceedings of the 15th A.C.M. S.I.G.K.D.D. International Conference on Knowledge Discovery and Data Mining, Paris, France."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1016\/j.eswa.2018.09.029","article-title":"Machine learning based phishing detection from URLs","volume":"117","author":"Sahingoz","year":"2019","journal-title":"Expert Syst. Appl."},{"key":"ref_31","first-page":"7","article-title":"New filtering approaches for phishing email","volume":"18","author":"Bergholz","year":"2010","journal-title":"J. Comput. Sec."},{"key":"ref_32","unstructured":"Face, H. (2025, October 12). Phishing Email Classification Dataset. Available online: https:\/\/huggingface.co\/datasets\/zeroshot\/phishing_email."},{"key":"ref_33","unstructured":"Abdullahalam, N. (2025, October 12). Phishing Email Dataset. Available online: https:\/\/www.kaggle.com\/datasets\/naserabdullahalam\/phishing-email-dataset."},{"key":"ref_34","unstructured":"Phan, N., Wu, X., Dou, D., and Hu, H. (2020, January 12\u201318). Scalable Differential Privacy with Certified Robustness in Adversarial Learning. Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kinasih, D.P., Mulyadi, P.P., Hartono, R., and Lucky, H. (2024, January 20\u201321). Enhancing Phishing Email Detection Using Hybrid Ensemble Learning. Proceedings of the 2023 International Conference on Computer, Communication, and Electrical Technology (ICECCT), Jakarta, Indonesia.","DOI":"10.1109\/ICIMCIS63449.2024.10956336"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Vorobeychik, Y., and Kantarcioglu, M. (2018). Adversarial Machine Learning, Springer.","DOI":"10.1007\/978-3-031-01580-9"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Alshahrani, E., Alghazzawi, D., Alotaibi, R., and Rabie, O. (2022). Adversarial attacks against supervised machine learning-based network intrusion detection systems. PLoS ONE, 17.","DOI":"10.1371\/journal.pone.0275971"},{"key":"ref_38","unstructured":"UK Statistics Authority (2025, October 12). Ethical Considerations in the Use of Machine Learning for Research and Statistics, Available online: https:\/\/www.gov.uk\/data-ethics-guidance\/ethical-considerations-in-the-use-of-machine-learning-for-research-and-statistics."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Rodrigues, M., Lino, R., Alves, F., and Novais, P. (2025). Ethical considerations in artificial intelligence and machine learning. Advances in Computational Intelligence, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-032-02728-3_3"},{"key":"ref_40","unstructured":"Information Commissioner\u2019s Office (ICO) (2025, October 12). Guidance on AI and Data Protection. Available online: https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/artificial-intelligence\/guidance-on-ai-and-data-protection."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/91\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T04:32:46Z","timestamp":1761798766000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/91"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,29]]},"references-count":40,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040091"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040091","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,29]]}}}