Search Articles & Publications

Showing 5 articles found for "Injection"

Cross-Lingual Indirect Prompt Injection Across Retrieval, Reranking, And Generation In Multilingual RAG

Fauzi Bondan Prihananto, Erlangga Bayu Yudho Prakoso, Aprilisa Arum Sari, Tomy Anugrah Islami
Abstract: External evidence can make retrieval-augmented generation (RAG) more informative, yet retrieved passages also provide a path for adversarial instructions to enter the model context. We examine that path in an English-Indonesian… onesian RAG system and track cross-lingual indirect prompt injection separately at retrieval, reranking, and generation. The experiment starts from 75 semantic items and evaluates every item in eight query/body/payload language combinations, for 600 paired trials. Qwen3-Embedding-0.6B and BGE-M3 produce top-20 candidate sets, BGE-reranker-v2-m3 reduces each set to five documents, and Qwen3-0.6B answers from the resulting context with either a standard prompt or an explicit trust-boundary prompt. Statistical uncertainty is estimated by resampling semantic items, and paired binary outcomes are modeled with generalized estimating equations. Poison documents reached the top 20 in 80.50% of Qwen trials and 37.67% of BGE-M3 trials (odds ratio 6.94, 95% CI 4.53-10.63). Top-five exposure was 18.50% and 16.17%, respectively. Standard end-to-end attack success was 6.33% for Qwen and 6.00% for BGE-M3; boundary-aware prompting lowered both rates to 1.33%, with no canary false positives. The results indicate that multilingual RAG security depends on several linked stages rather than generation alone.

THE DIFFERENCE CHANGE IN WEIGHT FAMILY PLANNING INJECTION ACCEPTORS THREE MONTHS WITH ONE MONTH IN MUARA VILLAGE CIREBON DISTRICT

Anugerahwati, Dwi Lestari
Abstract: Injected contraception is the most contraception method chosen by Indonesian women. There are 2 types of injected contraception, 3 monthly injecion which consists of progesterone  only and 1 monthly injection consists of… f a combination of oesterogen-progesterone. One of its side effect is increase weight, which is  usually distressing for women due to the increase risk of suffering from many diseases such as heart attack, type-2 diabetes mellitus, sleep apnea, certain cancer, osteoarthritis, and asthma. The study aim was to identify the difference weight gain occurence between 3 monthly and 1 monthly injected contraception users in Muara Village- Suranenggala District. This research method uses comparative analytic studies using cross sectional resulting research which measured in interval scale. The sample is all 3 months KB injecting participants as much as 30 respondents and 1 month KB injections as much as 30 respondents. The data is analysis using t-test. The result showed a  ρ value of  0,005 which meant there was a difference in weight gain occurence between the users of 3 monthly and 1 monthly injected contraception. The 3 monthly  injection had been proven increasing the incidence of weight gain compared to the 1 monthly one. It was suggested that midwives should give proper counselling regarding to side effect of increasing weight gain during the use of 3 monthly contraceptive injection to be aware of by the users. Further investigation on other influencing factors of weight gain among contraceptive injection users.

OPTIMIZING RETRIEVAL-AUGMENTED GENERATION FOR DOMAIN-SPECIFIC KNOWLEDGE SYSTEMS THROUGH FINE-TUNING AND PROMPT ENGINEERING

Ahmad Fajri, Rila Mandala
Abstract: Abstract: This study discusses the optimization of RAG for a FAQ system in the field of information technology product security certification at BSSN. Although LLM generate reliable responses, they often lack up-to-date… and domain-specific knowledge, which can be addressed through the RAG approach. This research aims to optimize a domain-specific RAG system by improving embedding performance, enhancing prompt robustness, and increasing retrieval accuracy. The research methods consist of three stages. The first stage involves fine-tuning the bge-m3 embedding model and evaluating its performance using MRR, Recall, and AUC. The second stage applies prompt engineering techniques, namely the SRSM and Autodefense, to mitigate direct-injection and escape-character prompt injection attacks. The third stage evaluates the proposed RAG system using Precision, Recall, and F1-Score metrics against four baseline models. The results of research show that the fine-tuned embedding model achieves higher performance than the original model, with MRR@1 and Recall@1 values of 0.80 and an AUC@100 of 0.7023. In addition, the proposed prompt engineering techniques demonstrate robustness against prompt injection attacks, while the overall RAG system attains a perfect Precision, Recall, and F1-Score of 1.00. In conclusion, the proposed approach effectively enhances retrieval accuracy, embedding quality, and system security, resulting in a more reliable RAG-based FAQ system for information technology product security certification. Keywords: embedding fine-tuning; large language model; prompt engineering; prompt injection mitigation; retrieval-augmented generation   Abstrak: Studi ini membahas optimasi RAG untuk sistem FAQ di bidang sertifikasi keamanan produk teknologi informasi di BSSN. Meskipun LLM menghasilkan respons yang andal, mereka seringkali kurang memiliki pengetahuan terkini dan spesifik domain, yang dapat diatasi melalui pendekatan RAG. Penelitian ini bertujuan untuk mengoptimalkan sistem RAG spesifik domain dengan meningkatkan kinerja embedding, meningkatkan ketahanan prompt dan meningkatkan akurasi pengambilan. Metode penelitian terdiri dari tiga tahap. Tahap pertama melibatkan fine-tuning model embedding bge-m3 dan mengevaluasi kinerjanya menggunakan Mean Reciprocal Rank (MRR), Recall, dan AUC. Tahap kedua menerapkan teknik rekayasa prompt, yaitu Self- SRSM dan Autodefense, untuk mengurangi serangan direct-injection dan escape-character prompt injection. Tahap ketiga mengevaluasi sistem RAG yang diusulkan menggunakan metrik Presisi, Recall, dan F1-Score terhadap empat model dasar. Hasil penelitian menunjukkan bahwa model embedding yang disempurnakan mencapai kinerja yang lebih tinggi daripada model asli, dengan nilai MRR@1 dan Recall@1 sebesar 0,80 dan AUC@100 sebesar 0,7023. Selain itu, teknik rekayasa prompt yang diusulkan menunjukkan ketahanan terhadap serangan injeksi prompt, sementara sistem RAG secara keseluruhan mencapai Presisi, Recall, dan F1-Score sempurna sebesar 1,00. Kesimpulannya, pendekatan yang diusulkan secara efektif meningkatkan akurasi pengambilan, kualitas embedding dan keamanan sistem, menghasilkan sistem FAQ berbasis RAG yang lebih andal untuk sertifikasi keamanan produk teknologi informasi. Kata kunci: penyempurnaan embedding; model bahasa besar; rekayasa prompt; mitigasi injeksi prompt; retrieval-augmented generation

AI-DRIVEN HYBRID ENCRYPTION FOR SECURE ELECTRONIC MEDICAL RECORDS

Prayitno, Edy, Heri Winarno, Basuki, Setyowati, Sri, Sutono, Sutono, Riyadi, Riyadi
Abstract: Abstract: In the era of sensitive health data and frequent cyberattacks, securing electronic medical records (EMR) has become a critical challenge. This study proposes a hybrid encryption framework combining Affine and AES… ES algorithms with an AI-based key management module to enhance EMR security while maintaining efficiency. A dataset of 1,000 simulated records was evaluated using five cryptographic configurations: Affine-only, AES-only, RSA-only, Affine–AES, and Affine–AES with AI. Performance was measured through encryption/decryption latency and ciphertext size, while security was assessed under brute-force, SQL injection, and phishing simulations. The AI decision tree for key generation was evaluated using accuracy, precision, recall, F1-score, and entropy metrics. Results show that the AI-enhanced hybrid method eliminates brute-force success, introduces only minor latency overhead, and generates high-entropy keys with reliability above 98%. These findings indicate that integrating AI-based dynamic key regeneration into hybrid encryption can improve EMR security while remaining practical for clinical and cloud-based healthcare systems. Future work should involve real clinical datasets and explore post-quantum cryptographic extensions.             Keywords: AI key management; attack resistance; encryption performance; electronic medical records; hybrid encryption     Abstrak: Di era meningkatnya sensitivitas data kesehatan dan maraknya serangan siber, perlindungan Rekam Medis Elektronik (RME) menjadi tantangan penting. Penelitian ini mengusulkan kerangka enkripsi hibrida yang menggabungkan algoritma Affine dan AES dengan modul manajemen kunci berbasis AI untuk meningkatkan keamanan RME tanpa mengorbankan efisiensi. Dataset simulasi berisi 1.000 entri diuji menggunakan lima konfigurasi kriptografi: Affine-only, AES-only, RSA-only, Affine–AES, serta Affine–AES dengan AI. Performa diukur melalui latensi enkripsi/dekripsi dan ukuran ciphertext, sedangkan keamanan dievaluasi melalui simulasi serangan brute force, SQL injection, dan phishing. Model decision tree untuk manajemen kunci dinilai menggunakan metrik akurasi, presisi, recall, F1-score, dan entropi. Hasil menunjukkan bahwa metode hibrida dengan AI menghilangkan keberhasilan brute force, menambah overhead latensi yang minimal, serta menghasilkan kunci berentropi tinggi dengan reliabilitas di atas 98%. Temuan ini menunjukkan bahwa regenerasi kunci dinamis berbasis AI dalam skema enkripsi hibrida dapat meningkatkan keamanan RME sekaligus tetap praktis untuk sistem klinis dan layanan kesehatan berbasis cloud. Penelitian selanjutnya disarankan menggunakan dataset klinis nyata dan mengeksplorasi kriptografi pascakuantum.   Kata kunci: enkripsi hibrida; ketahanan serangan; kinerja enkripsi; manajemen kunci berbasis AI; rekam medis elektronik

IDPS PERFORMANCE ANALYSIS FOR MITIGATING SQL INJECTIONS AND SYN FLOOD ATTACKS

Sahren, Sahren, Dalimunthe, Ruri Ashari, Saputra, Herman, Kurnia Sirni, Dian Yudha
Abstract: Abstract: Cyberattacks like SQL injection and syn flood attacks can threaten the information system security of an organisation or company. The Intrusion Detection and Prevention System (IDPS) is used as a solution to detect,… tect, prevent, and respond to these attacks. However, the effectiveness of IDPS in protecting information systems needs to be evaluated through performance analysis. IDPS performance analysis for mitigating SQL injection and syn flood attacks will use Suricata tools, where performance analysis will include evaluation of system accuracy and efficiency in detecting attacks, as well as the impact of the system on network or information system performance. By doing this performance analysis, it can be seen how effective the IDPS is in providing defences against such attacks. The results of the IDPS performance analysis can help an organisation or company select and implement the right IDPS according to the needs and conditions of the information system. Thus, organisations or companies can improve the security of their information systems from threatening cyber attacks.             Keywords: IDPS; SQL_Injection; Suricata; Syn_Flood_Attack     Abstrak: Serangan cyber seperti SQL Injection dan Syn Flood Attack dapat mengancam keamanan sistem informasi suatu organisasi atau perusahaan. Intrusion Detection and Prevention System (IDPS) digunakan sebagai solusi untuk mendeteksi, mencegah, dan merespons serangan-serangan ini. Namun, efektivitas IDPS dalam melindungi sistem informasi perlu dievaluasi melalui analisis performa. Analisis performa IDPS untuk mitigasi SQL Injection dan Syn Flood Attack ini akan menggunakan tools suricata dimana analisa performa akan meliputi evaluasi terhadap akurasi dan efisiensi sistem dalam mendeteksi serangan, serta dampak dari sistem terhadap kinerja jaringan atau sistem informasi. Dengan melakukan analisis performa ini, dapat diketahui seberapa efektif IDPS dalam memberikan perlindungan terhadap serangan-serangan tersebut. Hasil dari analisis performa IDPS dapat membantu organisasi atau perusahaan dalam memilih dan mengimplementasikan IDPS yang tepat sesuai dengan kebutuhan dan kondisi sistem informasi yang dimiliki. Dengan demikian, organisasi atau perusahaan dapat meningkatkan keamanan sistem informasi mereka dari serangan-serangan cyber yang mengancam.   Kata kunci: IDPS; SQL_Injection; Suricata; Syn_Flood_Attack