M.J.G. van Eeten
Please Note
40 records found
1
Security by Expectation
Establishing an Empirical Understanding of Reasonable User Expectations in the Internet of Things
Growing security challenges of the IoT reflect a structural imbalance in the market. Consumers typically lack the information or technical capacity to evaluate or influence a product’s security, while manufacturers face little incentive to prioritize it over features or cost efficiency. To address this, governments, particularly within the European Union, are increasingly introducing legislation that codifies how security should be built, maintained, and enforced across the IoT ecosystem. Key among these initiatives are the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD), which place explicit emphasis on the expectations of users as a benchmark for determining compliance and responsibility.
The concept of reasonable user expectations has therefore become central to the regulation of IoT products. It provides a flexible legal standard to assess what users can justifiably anticipate regarding the safety and security of their devices. However, despite its prominence in emerging laws, there is no agreed-upon method for determining what these expectations actually are. Courts may consider factors such as prevailing industry practices or product marketing, but empirical evidence of what users themselves expect in practice has been scarce. This creates uncertainty for regulators and manufacturers alike, who must interpret and act on these expectations long before any case law emerges. Against this backdrop, the overarching research question guiding the work is: What are users’ expectations regarding preventive and reactive security measures of IoT devices?
To answer this research question, this dissertation investigates user expectations at different stages of the IoT device lifecycle: when security or privacy incidents occur, how they are prevented over the device's lifespan, and when devices are used in organizational environments. The studies link these expectations to the broader regulatory concepts of product liability and product conformity, providing evidence that can inform both policy and industry practice.
...
Growing security challenges of the IoT reflect a structural imbalance in the market. Consumers typically lack the information or technical capacity to evaluate or influence a product’s security, while manufacturers face little incentive to prioritize it over features or cost efficiency. To address this, governments, particularly within the European Union, are increasingly introducing legislation that codifies how security should be built, maintained, and enforced across the IoT ecosystem. Key among these initiatives are the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD), which place explicit emphasis on the expectations of users as a benchmark for determining compliance and responsibility.
The concept of reasonable user expectations has therefore become central to the regulation of IoT products. It provides a flexible legal standard to assess what users can justifiably anticipate regarding the safety and security of their devices. However, despite its prominence in emerging laws, there is no agreed-upon method for determining what these expectations actually are. Courts may consider factors such as prevailing industry practices or product marketing, but empirical evidence of what users themselves expect in practice has been scarce. This creates uncertainty for regulators and manufacturers alike, who must interpret and act on these expectations long before any case law emerges. Against this backdrop, the overarching research question guiding the work is: What are users’ expectations regarding preventive and reactive security measures of IoT devices?
To answer this research question, this dissertation investigates user expectations at different stages of the IoT device lifecycle: when security or privacy incidents occur, how they are prevented over the device's lifespan, and when devices are used in organizational environments. The studies link these expectations to the broader regulatory concepts of product liability and product conformity, providing evidence that can inform both policy and industry practice.
Patchwork security
Municipal Cybersecurity Measures in Practice
In response to this threat landscape, municipalities are expected to implement a range of cybersecurity measures. These include complying with security frameworks and standards, managing vulnerabilities through patching and configuration, participating in information sharing and coordination structures, and preparing for incident response and recovery. At the same time, municipalities typically operate under constraints that distinguish them from many other organizations, including limited internal cybersecurity capacity, extensive reliance on outsourcing and shared service providers, and complex internal structures in which responsibility for systems and data is distributed across departments and external parties.
As a result, municipal cybersecurity is rarely a matter of isolated technical controls. Instead, it is shaped by interactions between municipalities and a broader ecosystem of actors, including vendors, managed service providers, sectoral and national CSIRTs, and commercial security firms. Information about threats and vulnerabilities often reaches municipalities through intermediaries, and the ability to act on that information depends on institutional arrangements, contractual relationships, and organizational processes. Understanding municipal cybersecurity, therefore, requires examining not only which security measures are in place but also how those measures function in practice within this institutional context.
This dissertation examines the security measures municipalities use to address cyber threats and how they function in practice under these conditions. It investigates vulnerability remediation, institutional support for incident prevention and response, and the use of commercial threat intelligence, and asks how these security measures can be improved in practice, addressing the central research question: How can municipalities improve security measures to address cyber threats? To answer this question, the dissertation presents three empirical studies that combine technical measurements with practitioner perspectives, adopting a socio-technical approach that connects technical observations to organizational and institutional contexts.
...
In response to this threat landscape, municipalities are expected to implement a range of cybersecurity measures. These include complying with security frameworks and standards, managing vulnerabilities through patching and configuration, participating in information sharing and coordination structures, and preparing for incident response and recovery. At the same time, municipalities typically operate under constraints that distinguish them from many other organizations, including limited internal cybersecurity capacity, extensive reliance on outsourcing and shared service providers, and complex internal structures in which responsibility for systems and data is distributed across departments and external parties.
As a result, municipal cybersecurity is rarely a matter of isolated technical controls. Instead, it is shaped by interactions between municipalities and a broader ecosystem of actors, including vendors, managed service providers, sectoral and national CSIRTs, and commercial security firms. Information about threats and vulnerabilities often reaches municipalities through intermediaries, and the ability to act on that information depends on institutional arrangements, contractual relationships, and organizational processes. Understanding municipal cybersecurity, therefore, requires examining not only which security measures are in place but also how those measures function in practice within this institutional context.
This dissertation examines the security measures municipalities use to address cyber threats and how they function in practice under these conditions. It investigates vulnerability remediation, institutional support for incident prevention and response, and the use of commercial threat intelligence, and asks how these security measures can be improved in practice, addressing the central research question: How can municipalities improve security measures to address cyber threats? To answer this question, the dissertation presents three empirical studies that combine technical measurements with practitioner perspectives, adopting a socio-technical approach that connects technical observations to organizational and institutional contexts.
Investigating Toxic Language in TikTok’s Autocomplete
A Cross-Regional Empirical Analysis of Gender, Race, and Sexual Orientation Bias
To approach this, the study conceptualises algorithmic bias as a form of representational distortion, when identities are disproportionately linked to hostile, stereotypical, or derogatory language. Toxicity is used as a measurable proxy for this phenomenon, with scores derived from Google’s Perspective API and validated against a human-annotated subset. This framework allows the study to scale while maintaining conceptual clarity, offering a bridge between statistical insight and social meaning. The use of a cross-national dataset further adds depth, enabling the analysis to explore both universal and context-specific patterns of bias.
The findings show clear evidence that identity matters. Prompts referencing homosexual identities and Black identity terms consistently produced higher toxicity scores than their heterosexual and White counterparts. Gender-based disparities were also observed, though they were less pronounced. Interestingly, these patterns held steady across all ten countries studied. Despite cultural, regulatory, and linguistic differences, the toxicity distributions remained largely similar, suggesting that TikTok’s autocomplete system likely runs on a globally standardised model that does not meaningfully adapt to regional contexts. In contrast, the ranking of suggestions, where a toxic output appears within the top eight, had only a marginal impact on overall exposure. While some toxic completions did surface in mid-list positions, their distribution lacked a clear or consistent pattern.
Taken together, the research offers an empirical audit of TikTok’s search interface from a bias and fairness perspective. It shows that autocomplete, though often overlooked, can act as a subtle mechanism through which social hierarchies are reproduced. This insight carries implications for platform accountability and algorithmic design, especially in the context of ongoing policy efforts such as the EU AI Act, an emerging regulatory landscape that is likely to include systems like TikTok's autocomplete. By demonstrating that toxic associations are not isolated glitches but predictable patterns, the study highlights the limitations of moderation strategies that focus solely on removals or post hoc filtering. Ultimately, the thesis argues that mitigating algorithmic bias requires more than adjusting output rankings, it demands deeper attention to how predictive models are trained, evaluated, and governed. As TikTok continues to shape how a new generation accesses information, improving the social impact of features like autocomplete is not only a technical challenge but a public responsibility. ...
To approach this, the study conceptualises algorithmic bias as a form of representational distortion, when identities are disproportionately linked to hostile, stereotypical, or derogatory language. Toxicity is used as a measurable proxy for this phenomenon, with scores derived from Google’s Perspective API and validated against a human-annotated subset. This framework allows the study to scale while maintaining conceptual clarity, offering a bridge between statistical insight and social meaning. The use of a cross-national dataset further adds depth, enabling the analysis to explore both universal and context-specific patterns of bias.
The findings show clear evidence that identity matters. Prompts referencing homosexual identities and Black identity terms consistently produced higher toxicity scores than their heterosexual and White counterparts. Gender-based disparities were also observed, though they were less pronounced. Interestingly, these patterns held steady across all ten countries studied. Despite cultural, regulatory, and linguistic differences, the toxicity distributions remained largely similar, suggesting that TikTok’s autocomplete system likely runs on a globally standardised model that does not meaningfully adapt to regional contexts. In contrast, the ranking of suggestions, where a toxic output appears within the top eight, had only a marginal impact on overall exposure. While some toxic completions did surface in mid-list positions, their distribution lacked a clear or consistent pattern.
Taken together, the research offers an empirical audit of TikTok’s search interface from a bias and fairness perspective. It shows that autocomplete, though often overlooked, can act as a subtle mechanism through which social hierarchies are reproduced. This insight carries implications for platform accountability and algorithmic design, especially in the context of ongoing policy efforts such as the EU AI Act, an emerging regulatory landscape that is likely to include systems like TikTok's autocomplete. By demonstrating that toxic associations are not isolated glitches but predictable patterns, the study highlights the limitations of moderation strategies that focus solely on removals or post hoc filtering. Ultimately, the thesis argues that mitigating algorithmic bias requires more than adjusting output rankings, it demands deeper attention to how predictive models are trained, evaluated, and governed. As TikTok continues to shape how a new generation accesses information, improving the social impact of features like autocomplete is not only a technical challenge but a public responsibility.
The research is structured around five studies. The first two chapters focus on cryptojacking, a cybercrime involving the unauthorized use of computing resources for cryptocurrency mining. The first study assesses the prevalence of cryptojacking on websites, identifying attack vectors, targeted website categories, and large-scale campaigns. The second extends this inquiry to compromised infrastructure, particularly MikroTik routers, revealing a broader and more organized set of cryptojacking operations. Using Internet traffic analysis and campaign mapping, this chapter uncovers the operational lifecycles of infected infrastructure and the varying sophistication of attackers.
The third study addresses phishing, particularly targeting Dutch citizens. By examining the development and trade of phishing kits, the research uncovers the full life cycle of phishing campaigns against the Dutch financial sector. Insights into attackers’ techniques, including their use of TLS certificates and phishing kit usage, inform policy recommendations for anti-phishing initiatives.
The fourth study examines the anti-abuse ecosystem, focusing on how intermediaries such as hosting providers handle abuse reports. Through access to the internal data of a Dutch hosting provider, the study shows that responses depend largely on the source and type of abuse notification. Governance instruments like blocklisting or law enforcement pressure prove more effective in eliciting responses than individual reports, highlighting gaps in current mitigation practices.
The fifth study reviews 38 academic works on phishing, booter services, and remote access trojans, structuring them through the concept of value chains. By comparing methods and data sources, and incorporating reflections from law enforcement professionals, the study identifies which scientific measurements are considered most valuable. This highlights the need for measurement approaches that align more closely with law enforcement priorities, especially regarding the development and monetization components of cybercrime.
The dissertation concludes by emphasizing that Internet measurements of cybercrime must reflect the intent and decision-making processes of criminals, as well as incorporate geographical demarcation to match the jurisdictional constraints of law enforcement agencies. Value chain analysis, lifecycle mapping, and campaign analysis emerge as tools for structuring meaningful measurements. Ultimately, the research demonstrates that bridging technical and criminological approaches produces insights that better serve governance needs and provide actionable intelligence for law enforcement. ...
The research is structured around five studies. The first two chapters focus on cryptojacking, a cybercrime involving the unauthorized use of computing resources for cryptocurrency mining. The first study assesses the prevalence of cryptojacking on websites, identifying attack vectors, targeted website categories, and large-scale campaigns. The second extends this inquiry to compromised infrastructure, particularly MikroTik routers, revealing a broader and more organized set of cryptojacking operations. Using Internet traffic analysis and campaign mapping, this chapter uncovers the operational lifecycles of infected infrastructure and the varying sophistication of attackers.
The third study addresses phishing, particularly targeting Dutch citizens. By examining the development and trade of phishing kits, the research uncovers the full life cycle of phishing campaigns against the Dutch financial sector. Insights into attackers’ techniques, including their use of TLS certificates and phishing kit usage, inform policy recommendations for anti-phishing initiatives.
The fourth study examines the anti-abuse ecosystem, focusing on how intermediaries such as hosting providers handle abuse reports. Through access to the internal data of a Dutch hosting provider, the study shows that responses depend largely on the source and type of abuse notification. Governance instruments like blocklisting or law enforcement pressure prove more effective in eliciting responses than individual reports, highlighting gaps in current mitigation practices.
The fifth study reviews 38 academic works on phishing, booter services, and remote access trojans, structuring them through the concept of value chains. By comparing methods and data sources, and incorporating reflections from law enforcement professionals, the study identifies which scientific measurements are considered most valuable. This highlights the need for measurement approaches that align more closely with law enforcement priorities, especially regarding the development and monetization components of cybercrime.
The dissertation concludes by emphasizing that Internet measurements of cybercrime must reflect the intent and decision-making processes of criminals, as well as incorporate geographical demarcation to match the jurisdictional constraints of law enforcement agencies. Value chain analysis, lifecycle mapping, and campaign analysis emerge as tools for structuring meaningful measurements. Ultimately, the research demonstrates that bridging technical and criminological approaches produces insights that better serve governance needs and provide actionable intelligence for law enforcement.
The Signals We Send
Analysing the Market Signals for IoT Security and Privacy
The underlying reasons for the S&P issues in IoT devices are not merely technical, there are socio-technical and economic dimensions associated with them. For instance, large scale DDoS attacks from insecure IoT devices are a classic example of negative externalities where the consequences of the attack are experienced by a party that is neither the manufacturer nor the consumer. In such a context, manufacturers often face a lack of incentives to improve on the underlying S&P issues since doing so would increase their development costs and delay their time to market. Although consumers as device owners may not be directly targeted by DDoS attacks, they do face indirect consequences from DDoS attacks on governments, banks and other websites. Moreover, they bear the brunt of individual losses to S&P, for example, when their IoT devices are hacked or their personal video feeds are exposed. Therefore, consumers have incentives to buy IoT devices with strong S&P features. Recent studies affirm this, and show that consumers not only care about IoT S&P, they are also willing to pay a premium for it – if they are informed about the S&P at the time of purchase.
However, the problem still remains that consumers do not have sufficient information – at the time of purchase – to discern IoT devices that have good S&P features from those that do not. While regulations like the Cyber Resilience Act (CRA) in the EU, and the US Cyber TrustMark aim to decrease this information asymmetry, they are not yet in effect. In the absence of official information about an IoT device’s S&P at the time of purchase, consumers might use other signals that directly or indirectly indicate the S&P posture of IoT devices like mention of security concerns in consumer reviews on e-commerce platforms. Since consumers currently depend on such indirect sources to assess S&P, insights into these signals can help design more effective interventions that fit into their current decision-making flow. However, there is currently no empirical analysis on these market signals which limits our understanding of how much the consumer base already recognises and signals a need for S&P.
This dissertation addresses this gap by analyzing S&P of consumer IoT devices through a market-based empirical lens that examines how economic incentives, S&P signals, and purchase decisions interact across different stakeholders in real-world e-commerce settings. Specifically, five mature and popular IoT device types are considered: IP cameras, smart printers, smart speakers, smart TVs and smart watches. By examining the interactions between manufacturers, consumers, sellers, and the e-commerce platforms that sell these devices, using actual market data (sales figures, prices, reviews, and product listings), this dissertation provides a unique vantage point on the market signals for IoT S&P and information asymmetry experienced by consumers. Overall, this dissertation aims to answer the following overarching research question through five research studies. What signals for security and privacy are present in the e-commerce platforms that sell IoT devices?
...
The underlying reasons for the S&P issues in IoT devices are not merely technical, there are socio-technical and economic dimensions associated with them. For instance, large scale DDoS attacks from insecure IoT devices are a classic example of negative externalities where the consequences of the attack are experienced by a party that is neither the manufacturer nor the consumer. In such a context, manufacturers often face a lack of incentives to improve on the underlying S&P issues since doing so would increase their development costs and delay their time to market. Although consumers as device owners may not be directly targeted by DDoS attacks, they do face indirect consequences from DDoS attacks on governments, banks and other websites. Moreover, they bear the brunt of individual losses to S&P, for example, when their IoT devices are hacked or their personal video feeds are exposed. Therefore, consumers have incentives to buy IoT devices with strong S&P features. Recent studies affirm this, and show that consumers not only care about IoT S&P, they are also willing to pay a premium for it – if they are informed about the S&P at the time of purchase.
However, the problem still remains that consumers do not have sufficient information – at the time of purchase – to discern IoT devices that have good S&P features from those that do not. While regulations like the Cyber Resilience Act (CRA) in the EU, and the US Cyber TrustMark aim to decrease this information asymmetry, they are not yet in effect. In the absence of official information about an IoT device’s S&P at the time of purchase, consumers might use other signals that directly or indirectly indicate the S&P posture of IoT devices like mention of security concerns in consumer reviews on e-commerce platforms. Since consumers currently depend on such indirect sources to assess S&P, insights into these signals can help design more effective interventions that fit into their current decision-making flow. However, there is currently no empirical analysis on these market signals which limits our understanding of how much the consumer base already recognises and signals a need for S&P.
This dissertation addresses this gap by analyzing S&P of consumer IoT devices through a market-based empirical lens that examines how economic incentives, S&P signals, and purchase decisions interact across different stakeholders in real-world e-commerce settings. Specifically, five mature and popular IoT device types are considered: IP cameras, smart printers, smart speakers, smart TVs and smart watches. By examining the interactions between manufacturers, consumers, sellers, and the e-commerce platforms that sell these devices, using actual market data (sales figures, prices, reviews, and product listings), this dissertation provides a unique vantage point on the market signals for IoT S&P and information asymmetry experienced by consumers. Overall, this dissertation aims to answer the following overarching research question through five research studies. What signals for security and privacy are present in the e-commerce platforms that sell IoT devices?
From Disclosure to Exploitation
A Comprehensive Analysis of IoT Vulnerability Targeting and Attacker Decision-Making
This dissertation investigates how IoT vulnerabilities are selected for exploitation in practice, with a particular focus on attacker behavior, exploit development, and vulnerability characteristics. It systematically examines the interplay between these factors to understand how they collectively shape exploitation trends in IoT ecosystems. To answer the central research question on What factors shape the exploitation in IoT vulnerabilities, from target selection to exploit development and prediction?, this dissertation presents four peer-reviewed studies.... ...
This dissertation investigates how IoT vulnerabilities are selected for exploitation in practice, with a particular focus on attacker behavior, exploit development, and vulnerability characteristics. It systematically examines the interplay between these factors to understand how they collectively shape exploitation trends in IoT ecosystems. To answer the central research question on What factors shape the exploitation in IoT vulnerabilities, from target selection to exploit development and prediction?, this dissertation presents four peer-reviewed studies....
Beyond CVEs
An Analysis of Untracked Software Vulnerabilities Disclosed in Public Issue Trackers
Privacy: the more, the merrier?
A case study of how Amazon uses privacy protection to expand its power over IoT manufacturers
I answered the research question “How does Amazon’s use of privacy-enhancing technologies in Sidewalk affect its power over IoT manufacturers?” by reviewing grey literature, analysing the Sidewalk technology, and elite interviewing with high-ranking employees of Sidewalk-adopting manufacturers. I have shown that Amazon leveraged PETs to mitigate public security concerns, but in the meantime reshapes how manufacturers produce their devices. Part of this ploy is cementing AWS in their production processes. Amazon also uses this leverage to mobilise manufacturers’ and silicon providers’ resources to improve Sidewalk’s public reception, technology, and governance.
These reconfigurations are expensive and complicated to realise, but manufacturers stressed the importance of Sidewalk adoption to leverage Amazon’s reputation vis-à-vis suppliers and customers, and “befriend the giant” for they rely on Amazon’s Marketplace, cloud, and logistics.
Meanwhile, Amazon’s reductionist framing of privacy and security as protecting user identity and data confidentiality, means that confidentiality of manufacturers’ business-sensitive information is not discussed. With this vantage point, Amazon can learn which endpoint types are popular and how they work; but Sidewalk might also be a vehicle for Amazon to attract more IoT developers to AWS.
In sum, I have demonstrated that strictly pursuing user privacy (or confidentiality) in digital services may have unforeseen effects on production. Therefore, I call upon privacy and competition scholars, advocates, and regulators to question how privacy protection actually augments companies’ power, and stepping away from their narrow “consumer harm” lenses. These actors should debate a right to personal control over devices. A mere consumer focus in studying these developments is insufficient: I established that business-to-business relations and businesses’ production processes are more significantly affected than consumers. The production focus of this work lays bare the novel power dynamics between Amazon and manufacturers, shaped by PETs. ...
I answered the research question “How does Amazon’s use of privacy-enhancing technologies in Sidewalk affect its power over IoT manufacturers?” by reviewing grey literature, analysing the Sidewalk technology, and elite interviewing with high-ranking employees of Sidewalk-adopting manufacturers. I have shown that Amazon leveraged PETs to mitigate public security concerns, but in the meantime reshapes how manufacturers produce their devices. Part of this ploy is cementing AWS in their production processes. Amazon also uses this leverage to mobilise manufacturers’ and silicon providers’ resources to improve Sidewalk’s public reception, technology, and governance.
These reconfigurations are expensive and complicated to realise, but manufacturers stressed the importance of Sidewalk adoption to leverage Amazon’s reputation vis-à-vis suppliers and customers, and “befriend the giant” for they rely on Amazon’s Marketplace, cloud, and logistics.
Meanwhile, Amazon’s reductionist framing of privacy and security as protecting user identity and data confidentiality, means that confidentiality of manufacturers’ business-sensitive information is not discussed. With this vantage point, Amazon can learn which endpoint types are popular and how they work; but Sidewalk might also be a vehicle for Amazon to attract more IoT developers to AWS.
In sum, I have demonstrated that strictly pursuing user privacy (or confidentiality) in digital services may have unforeseen effects on production. Therefore, I call upon privacy and competition scholars, advocates, and regulators to question how privacy protection actually augments companies’ power, and stepping away from their narrow “consumer harm” lenses. These actors should debate a right to personal control over devices. A mere consumer focus in studying these developments is insufficient: I established that business-to-business relations and businesses’ production processes are more significantly affected than consumers. The production focus of this work lays bare the novel power dynamics between Amazon and manufacturers, shaped by PETs.
From the Outside In
Predicting internal security incidents with external network data
The study delves into how smart contracts can offer a solution. Smart contracts are computerized protocols that can automate contract clauses, potentially aligning better with industry goals. The examination focuses on their impact on transaction costs, involving expenses incurred by insurers and reinsurers to execute transactions.
Findings reveal that smart contracts can effectively reduce administrative costs by automating tasks, particularly in high-volume and standardized scenarios. However, their effect on dispute resolution costs is more nuanced, as the reinsurance sector still benefits from human interpretation.
In conclusion, while smart contracts hold promise for reducing transaction costs in reinsurance, the industry's unique complexities and high financial stakes may pose challenges and necessitate post-implementation adjustments. The paper recommends exploring smart contract applications in industries with smaller disputed amounts and lower trust levels than reinsurance. ...
The study delves into how smart contracts can offer a solution. Smart contracts are computerized protocols that can automate contract clauses, potentially aligning better with industry goals. The examination focuses on their impact on transaction costs, involving expenses incurred by insurers and reinsurers to execute transactions.
Findings reveal that smart contracts can effectively reduce administrative costs by automating tasks, particularly in high-volume and standardized scenarios. However, their effect on dispute resolution costs is more nuanced, as the reinsurance sector still benefits from human interpretation.
In conclusion, while smart contracts hold promise for reducing transaction costs in reinsurance, the industry's unique complexities and high financial stakes may pose challenges and necessitate post-implementation adjustments. The paper recommends exploring smart contract applications in industries with smaller disputed amounts and lower trust levels than reinsurance.
The AI Act covers various AI applications, including machine learning, logical, statistical, and knowledge-based approaches. It provides a classification framework based on the purpose and risks posed by AI applications: Prohibited/Unacceptable risk, High-Risk, Limited-Risk, and Minimal/No risk. However, there are concerns about the clarity of the classification criteria mentioned in the AI Act. Some AI systems may fall into multiple classifications, leading to ambiguity. For example, a social robot used in patient treatment could be classified as High-Risk or Limited-Risk. This ambiguity is also observed in classifying AI systems in enterprise functions, where 40{\%} of the classifications remain unclear.
Therefore, these challenges provide an opportunity to improve the classification process of AI systems under the AI Act, facilitating the classification process and accommodating emerging AI technologies. The main research question addressed in this thesis is: \textbf{"To what extent can the process of AI systems classification under the AI Act be improved?"}
The research focuses specifically on AI systems classification. It explores specific provisions of the AI Act, including Prohibited Risk, Classification Rules for High-Risk AI systems, Transparency Obligations, and Annexes II and III.
To achieve the objective of improving the classification accuracy of AI systems based on the AI Act, the study adopts the Design Science Methodology. This methodology involves systematically studying existing AI systems classifications and challenges, extracting themes to develop a framework, and evaluating the framework through feedback from AI experts.
A decision tree is designed as the proposed framework. It is evaluated on 16 respondents from two different backgrounds: legal and non-legal. In order to obtain comprehensive insights, the evaluation is designed to incorporate an experiment where respondents are tasked to classify AI systems to the risk level with the AI Act only. Then in the second experiment, they have to classify AI systems using the proposed decision tree framework. It is important to note that the study acknowledges the possibility of overestimating or underestimating respondents' ability to classify AI systems due to their diverse backgrounds and levels of understanding of the AI Act. Furthermore, a semi-structured interview is conducted to strengthen the analysis.
Based on the evaluation, the decision tree's performance revealed higher accuracy than the classification approach without the decision tree. However, the overall accuracy remained low, indicating room for improvement. Challenges identified include the need for additional context and understanding of terms, definitions, and examples in the decision tree and the potential for misclassification due to vague definitions and assumptions. Respondents also expressed the need for more detailed information about AI system use cases to improve classification accuracy.
The decision tree's performance varied between obvious and non-obvious use cases, with non-obvious cases presenting challenges in accurate classification. The accuracy for obvious cases was higher, highlighting the difficulty of distinguishing between High-Risk and Unacceptable Risk categories. Lack of clarity in terms and definitions and limited contextual information contributed to the challenges faced in classifying non-obvious cases.
Legal experts demonstrated higher accuracy than non-legal respondents, indicating familiarity with legal terminology and the AI Act. However, legal and non-legal respondents encountered difficulties classifying non-obvious cases, emphasizing the need for clearer frameworks and tools to enhance clarity and streamline the classification process. Greater clarity in the AI Act and an interdisciplinary approach were recommended to address these challenges and facilitate understanding of the risks associated with AI systems.
Based on the analysis, several areas for improving AI systems classification under the AI Act have been identified. The current classification process faces challenges related to ambiguities in definitions, lack of contextual information, and difficulties in distinguishing between different risk levels.
To address these challenges and enhance the classification process, it is recommended to introduce clearer guidelines and refine the decision tree used for classification. The decision tree should incorporate additional criteria and features that provide more clarity and context. It is important to consider biases, subjective interpretations, clarity, and the dynamic nature of AI technologies in these improvements.
The study has certain limitations. The small sample size of respondents may impact the generalizability of the findings. The number of participants might not be representative of the entire population. Additionally, the limited number of use cases utilized in the research may limit the comprehensiveness of the classification framework. The study is based on the latest amendment of a policy proposal, and there is a potential for changes in the regulation's details, which may affect the effectiveness of the results. Finally, potential biases may exist in the development of the research, such as in making the decision tree and selecting the use cases.
Future research should explore the continuity of the decision tree's performance over time and its evaluation. There should be more research on non-obvious cases in specific domains or industries. It is crucial to focus on potential issues in classifying certain risk levels in the AI Act that hinder classification accuracy. Understanding the differences between legal and non-legal perspectives on the AI Act is also important to establish standardized understanding among stakeholders. Additionally, conducting quantitative research with larger and more diverse respondents from industrial backgrounds can further evaluate the proposed framework. ...
The AI Act covers various AI applications, including machine learning, logical, statistical, and knowledge-based approaches. It provides a classification framework based on the purpose and risks posed by AI applications: Prohibited/Unacceptable risk, High-Risk, Limited-Risk, and Minimal/No risk. However, there are concerns about the clarity of the classification criteria mentioned in the AI Act. Some AI systems may fall into multiple classifications, leading to ambiguity. For example, a social robot used in patient treatment could be classified as High-Risk or Limited-Risk. This ambiguity is also observed in classifying AI systems in enterprise functions, where 40{\%} of the classifications remain unclear.
Therefore, these challenges provide an opportunity to improve the classification process of AI systems under the AI Act, facilitating the classification process and accommodating emerging AI technologies. The main research question addressed in this thesis is: \textbf{"To what extent can the process of AI systems classification under the AI Act be improved?"}
The research focuses specifically on AI systems classification. It explores specific provisions of the AI Act, including Prohibited Risk, Classification Rules for High-Risk AI systems, Transparency Obligations, and Annexes II and III.
To achieve the objective of improving the classification accuracy of AI systems based on the AI Act, the study adopts the Design Science Methodology. This methodology involves systematically studying existing AI systems classifications and challenges, extracting themes to develop a framework, and evaluating the framework through feedback from AI experts.
A decision tree is designed as the proposed framework. It is evaluated on 16 respondents from two different backgrounds: legal and non-legal. In order to obtain comprehensive insights, the evaluation is designed to incorporate an experiment where respondents are tasked to classify AI systems to the risk level with the AI Act only. Then in the second experiment, they have to classify AI systems using the proposed decision tree framework. It is important to note that the study acknowledges the possibility of overestimating or underestimating respondents' ability to classify AI systems due to their diverse backgrounds and levels of understanding of the AI Act. Furthermore, a semi-structured interview is conducted to strengthen the analysis.
Based on the evaluation, the decision tree's performance revealed higher accuracy than the classification approach without the decision tree. However, the overall accuracy remained low, indicating room for improvement. Challenges identified include the need for additional context and understanding of terms, definitions, and examples in the decision tree and the potential for misclassification due to vague definitions and assumptions. Respondents also expressed the need for more detailed information about AI system use cases to improve classification accuracy.
The decision tree's performance varied between obvious and non-obvious use cases, with non-obvious cases presenting challenges in accurate classification. The accuracy for obvious cases was higher, highlighting the difficulty of distinguishing between High-Risk and Unacceptable Risk categories. Lack of clarity in terms and definitions and limited contextual information contributed to the challenges faced in classifying non-obvious cases.
Legal experts demonstrated higher accuracy than non-legal respondents, indicating familiarity with legal terminology and the AI Act. However, legal and non-legal respondents encountered difficulties classifying non-obvious cases, emphasizing the need for clearer frameworks and tools to enhance clarity and streamline the classification process. Greater clarity in the AI Act and an interdisciplinary approach were recommended to address these challenges and facilitate understanding of the risks associated with AI systems.
Based on the analysis, several areas for improving AI systems classification under the AI Act have been identified. The current classification process faces challenges related to ambiguities in definitions, lack of contextual information, and difficulties in distinguishing between different risk levels.
To address these challenges and enhance the classification process, it is recommended to introduce clearer guidelines and refine the decision tree used for classification. The decision tree should incorporate additional criteria and features that provide more clarity and context. It is important to consider biases, subjective interpretations, clarity, and the dynamic nature of AI technologies in these improvements.
The study has certain limitations. The small sample size of respondents may impact the generalizability of the findings. The number of participants might not be representative of the entire population. Additionally, the limited number of use cases utilized in the research may limit the comprehensiveness of the classification framework. The study is based on the latest amendment of a policy proposal, and there is a potential for changes in the regulation's details, which may affect the effectiveness of the results. Finally, potential biases may exist in the development of the research, such as in making the decision tree and selecting the use cases.
Future research should explore the continuity of the decision tree's performance over time and its evaluation. There should be more research on non-obvious cases in specific domains or industries. It is crucial to focus on potential issues in classifying certain risk levels in the AI Act that hinder classification accuracy. Understanding the differences between legal and non-legal perspectives on the AI Act is also important to establish standardized understanding among stakeholders. Additionally, conducting quantitative research with larger and more diverse respondents from industrial backgrounds can further evaluate the proposed framework.
Unraveling Incentives: Understanding the Adoption Barriers of SBOM in the Software Supply Chain
Obtaining novel insights into how a current misalignment of (dis)incentives among business stakeholders in the software supply chain can explain the limited adoption of SBOM
This research examines the perspectives of four key business stakeholders involved in the software supply chain to understand their incentives and disincentives surrounding SBOM adoption. Through a series of in-depth interviews with representatives from each stakeholder group, we aimed to identify stakeholder-specific risks, benefits, concerns, and incentives related to SBOM adoption. The analysis reveals that SBOM adoption potential is notably higher among system integrators and software vendors. These stakeholders perceive the benefits of enhanced transparency and supply chain risk mitigation, which align with their strategic objectives. On the contrary, B2B customers and Individual Developers exhibit the least motivation for SBOM adoption. Their limited interest stems from a perception that SBOMs may impose additional complexities without commensurate benefits. Given that B2B customers and individual developers are the primary consumers and suppliers of SBOMs, respectively, the findings suggest that the overall adoption potential of this technology remains restricted.
...
This research examines the perspectives of four key business stakeholders involved in the software supply chain to understand their incentives and disincentives surrounding SBOM adoption. Through a series of in-depth interviews with representatives from each stakeholder group, we aimed to identify stakeholder-specific risks, benefits, concerns, and incentives related to SBOM adoption. The analysis reveals that SBOM adoption potential is notably higher among system integrators and software vendors. These stakeholders perceive the benefits of enhanced transparency and supply chain risk mitigation, which align with their strategic objectives. On the contrary, B2B customers and Individual Developers exhibit the least motivation for SBOM adoption. Their limited interest stems from a perception that SBOMs may impose additional complexities without commensurate benefits. Given that B2B customers and individual developers are the primary consumers and suppliers of SBOMs, respectively, the findings suggest that the overall adoption potential of this technology remains restricted.
The identified approaches start with ‘Technology & Processes’ as this is most often the first choice for organizations. Using device management systems with corporate devices or BYOD devices with an enclave to ensure security without invading privacy. Education of the workforce is deemed one of the most successful approaches, since the security of the organizations is now more dependent on the workforce, raising awareness through education is of great importance. An approach that at first glance seems more counter-intuitive is the establishment of a security culture that takes years to achieve. Cybersecurity is involved into the daily tasks of the complete workforce. Without forcing and too many controls, but nudging employees by discussion and giving them responsibilities. The last approach shows that despite the priority challenge that is only mentioned by consultants, organizations want to become more mature, and organizations are currently giving cybersecurity a higher priority.
...
The identified approaches start with ‘Technology & Processes’ as this is most often the first choice for organizations. Using device management systems with corporate devices or BYOD devices with an enclave to ensure security without invading privacy. Education of the workforce is deemed one of the most successful approaches, since the security of the organizations is now more dependent on the workforce, raising awareness through education is of great importance. An approach that at first glance seems more counter-intuitive is the establishment of a security culture that takes years to achieve. Cybersecurity is involved into the daily tasks of the complete workforce. Without forcing and too many controls, but nudging employees by discussion and giving them responsibilities. The last approach shows that despite the priority challenge that is only mentioned by consultants, organizations want to become more mature, and organizations are currently giving cybersecurity a higher priority.
Detecting BestMixer
An exploratory study on centralized mixing services
Overall, the reconstruction attempt with filtering techniques did not perform well on BestMixer orders, as it returned an impracticable amount of possible payout combinations. The mixer showed less activity in the beginning days of the service, and there are signs that the reconstruction works better in this earlier stage of the mixer. This means that when a mixer becomes more popular, it could become more difficult to demix the orders correctly.
From this research can be concluded that the ground-truth data of BestMixer does help in developing attribution heuristics for centralized mixers, but not in developing a general reconstruction method that correctly restores the relation between deposits and payouts, thus not suffice in demixing centralized mixers. ...
Overall, the reconstruction attempt with filtering techniques did not perform well on BestMixer orders, as it returned an impracticable amount of possible payout combinations. The mixer showed less activity in the beginning days of the service, and there are signs that the reconstruction works better in this earlier stage of the mixer. This means that when a mixer becomes more popular, it could become more difficult to demix the orders correctly.
From this research can be concluded that the ground-truth data of BestMixer does help in developing attribution heuristics for centralized mixers, but not in developing a general reconstruction method that correctly restores the relation between deposits and payouts, thus not suffice in demixing centralized mixers.
Making the safe IoT choice?
A mixed methodology on the interaction of security and privacy related reviews and the customer purchase decision for IoT devices
The research was executed via a mixed methodology, with the quantative method being a discrete choice experimentation in the form of a survey and a website design. The study has found that out of a hundred respondents forty-four people chose a device with positive S\&P related reviews. Furthermore, more than half of the respondents chose the design as the main reason for choosing it. However, the qualitative data has shown that the reviews were often used as a last measure factor to pick between their 'favorite' devices. At that moment most of the respondent picked a device that had positive S\&P related reviews.
This research has contributed to science by showing how S\&P reviews interact with the customer purchase decision. Furthermore, it elaborates on the S\&P awareness process prior to the purchase instead of after. Thereby, it also presents the framing effect in the IoT field, showing that people are sensitive towards positive S\&P related reviews and therefore becoming more risk-averse. In addition, the study gave more insight in the IoT Trust/Value Paradox and the Privacy Paradox in relation the the IoT purchase decision. At last, it has shown the customer-to-customer effect to have an impact on the purchase decision even though is it not always the main reason of purchasing a certain IoT device. ...
The research was executed via a mixed methodology, with the quantative method being a discrete choice experimentation in the form of a survey and a website design. The study has found that out of a hundred respondents forty-four people chose a device with positive S\&P related reviews. Furthermore, more than half of the respondents chose the design as the main reason for choosing it. However, the qualitative data has shown that the reviews were often used as a last measure factor to pick between their 'favorite' devices. At that moment most of the respondent picked a device that had positive S\&P related reviews.
This research has contributed to science by showing how S\&P reviews interact with the customer purchase decision. Furthermore, it elaborates on the S\&P awareness process prior to the purchase instead of after. Thereby, it also presents the framing effect in the IoT field, showing that people are sensitive towards positive S\&P related reviews and therefore becoming more risk-averse. In addition, the study gave more insight in the IoT Trust/Value Paradox and the Privacy Paradox in relation the the IoT purchase decision. At last, it has shown the customer-to-customer effect to have an impact on the purchase decision even though is it not always the main reason of purchasing a certain IoT device.
SAVing the Internet
Measuring the adoption of Source Address Validation (SAV) by network providers
Dear customer, critters are crawling through your precious files
Understanding real-world evidence of QSnatch clean-up results and user experiences after warnings from the ISP
Countering money laundering
Implications of the 5th Anti-Money Laundering Directive on virtual currency exchanges in the Netherlands
Understanding the Attackers and Victims in IoT-based DDoS attacks
A mixed methodology approach to understanding cybercrime