SCVI

Towards Inclusive Cybersecurity: Protecting the Vulnerable with Social Cyber Vulnerability Metrics

This paper addresses the need for developing an inclusive social cyber vulnerability (iSCV) metric to assess the unique risks faced by underrepresented groups in cyberspace. Current metrics often fail to capture the vulnerabilities specific to marginalized populations, particularly in terms of digital literacy, access to resources, and behavioral traits. By integrating demographic representation, psychosocial stressors, and exposure to targeted attacks, the proposed iSCV aims to serve as a practical tool for improving security measures. The study emphasizes the importance of tailored interventions to enhance the resilience of vulnerable groups against social cyberattacks. Future research will focus on refining the metric through real-world applications and expanding its scope to address intersectional vulnerabilities.

Publications

IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TSP)- Workshop on Inclusive AI for Online Cybersecurity (an invited paper)

Authors: Shutonu Mitra, Qi Zhang, Chen-Wei Chang, Hossein Salemi, Hemant Purohit, Fengxiu Zhang, Michin Hong, Chang-Tien Lu, Jin-Hee Cho

Paper

Assessing Socio-Cyber Vulnerability Using Survey and Social Media Data

The rapid growth of social media participation has increased exposure to socially engineered cyber threats (e.g., phishing, romance fraud, tech-support scams), yet prevailing assessment tools remain fragmented: the Common Vulnerability Scoring System (CVSS) is primarily technical and largely omits human susceptibility, while the Social Vulnerability Index (SVI) is community-oriented and lacks cyber-specific modeling. To address emerging needs in computational intelligence for sociocyber risk assessment, this paper proposes the Social Cyber Vulnerability Index (SCVI), an interpretable, uncertainty-aware metric that fuses two complementary components: (i) an Individual Vulnerability Index (IVI) capturing awareness/knowledge, behavioral patterns, psychological factors, and prior victimization experience, and (ii) an Attack Severity Index (ASI) capturing attack frequency, consequences, and sophistication. We instantiate and validate SCVI across heterogeneous modalities: a nationally scoped survey (iPoll; 4,596 U.S. adults) and social-media narratives (450 Reddit r/scams reports, 2016–2024), showing SCVI can be computed from both structured questionnaires and CI-driven feature extraction from text (linguistic/annotation-derived factors). Robustness is quantified via sensitivity analysis and 10,000-iteration Monte Carlo simulations, demonstrating stable rankings under plausible weight variability and revealing context-dependent drivers (e.g., experience and sophistication in iPoll versus frequency in Reddit). Comparative evaluation shows SCVI captures distinct socio-technical signals (Spearman correlation with CVSS 𝜌 = 0.33; with SVI 𝜌 ≈ −0.01) and surfaces demographic and regional disparities. Key finding: SCVI provides substantially stronger separation between victim and non-victim groups than CVSS and SVI, enabling more reliable identification of high-risk populations and prioritization of interventions against emerging AI-enabled scams.

Publications

Under Review

Authors: Shutonu Mitra, Qi Zhang, Tomas Neguyen, Hossein Salemi, Fengxiu Zhang, Michin Hong, Chang-Tien Lu, Hemant Purohit, Jin-Hee Cho

Paper