Research Library

Since 2015, CLTC has directly funded more than 160 projects by UC Berkeley students, faculty & affiliates on original cybersecurity research topics, in addition to developing our own white papers, publications, blogs, policy analysis and recommendations, and open-source curricula and toolkits.

Filter & Sort

Date

Type

Research Item

Topics

September 3, 2024

White Paper

white dots appearing to form a swarm

A Swarm Intelligence Approach to Prioritizing the CIS Controls V8.0 Implementation

By: Hayat Abdulla Asad Cue, Thirimachos Bourlai, Mark Lupo

Authored by researchers affiliated with CyberArch, a cybersecurity clinic at the University of Georgia’s Carl Vinson Institute of Government (CVIOG), this paper introduces a novel approach for ranking actions outlined in the Center for Internet Security (CIS) framework, a prioritized set of safeguards to help organizations mitigate common cyber attacks.

July 2, 2024

White Paper

Improving the Explainability of AI

Improving the Explainability of Artificial Intelligence: The Promises and Limitations of Counterfactual Explanations

By: Alexander Asemota, Improving the Explainability of Artificial Intelligence: The Promises and Limitations of Counterfactual Explanations

A new white paper from the Center for Long-Term Cybersecurity explores diverse approach to explainable artificial intelligence (xAI), focusing on counterfactual explanations, or CTEs. The paper, “Improving the Explainability of Artificial Intelligence: The Promises and Limitations of Counterfactual Explanations,” was authored by Alexander Asemota, a 2023-2024 AI Policy Hub Fellow.

May 16, 2024

White Paper

cover of report "benchmark early and red team often," showing a blurred tunnel

Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual-Use Hazards of AI Foundation Models

By: Anthony Barrett, Krystal Jackson, Jessica Newman, Nada Madkour, Evan R. Murphy, Benchmark Early and Red Team Often: A Framework for Assessing and Managing Dual-Use Hazards of AI Foundation Models

Authored by Anthony M. Barrett, Krystal Jackson, Evan R. Murphy, Nada Madkour, and Jessica Newman, this report assesses two methods for evaluating the “dual-use” hazards of AI foundation models, which include large language models (LLMs) such as GPT-4, Gemini, Claude 3, Llama 3, and other general purpose AI systems.

April 23, 2024

White Paper

a grid and cityscape made of blue dots

The Transaction Costs of Municipal Cyber Risk Management

By: Rowland Herbert-Faulkner

This white paper, The Transaction Costs of Municipal Cyber Risk Management, brings to light the transaction costs associated with municipal cyber risk management, including the costs of searching for information, coordination between parties, drawing up and enforcing contracts, negotiation, inventory and monitoring, and compliance and enforcement. The paper was authored by by Rowland Herbert-Faulkner, a PhD Candidate in the Department of City and Regional Planning at UC Berkeley whose dissertation research focuses on technology governance at the municipal and regional scales.

January 23, 2024

White Paper

cover image of the report, featuring symbols like dollar signs, padlocks, and the SEC

Representing Privacy Legislation as Business Risks

By: Andrew Chong, Richmond Wong

For this CLTC white paper, researchers Richmond Wong and Andrew Chong used Form 10-K documents — annual regulatory reports for investors that publicly traded companies must file with the U.S. Securities and Exchange Commission (SEC) — to analyze how nine major technology companies assess and integrate the business risks of privacy regulation like the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA).

December 5, 2023

White Paper

a network of boxes padlocks and other shapes

Cybersecurity Futures 2030: New Foundations

To better understand how diverse forces are shaping the future of cybersecurity for governments and organizations, the Center for Long-Term Cybersecurity (CLTC), the World Economic Forum Centre for Cybersecurity, and CNA’s Institute for Public Research collaborated on “Cybersecurity Futures 2030: New Foundations,” a foresight-focused research initiative that aims to inform cybersecurity strategic plans around the globe.

November 8, 2023

White Paper

a steam-driven tool

AI Risk-Management Standards Profile for General-Purpose AI Systems (GPAIS) and Foundation Models

By: Anthony Barrett, Jessica Newman, Brandie Nonnecke

Increasingly general-purpose AI systems, such as BERT, CLIP, GPT-4, DALL-E 2, and PaLM, can provide many beneficial capabilities, but they also introduce risks of adverse events with societal-scale consequences. This document provides risk-management practices or controls for identifying, analyzing, and mitigating risks of such AI systems. The document is intended primarily for developers of these AI systems; others that can benefit from this guidance include downstream developers of end-use applications that build on a general-purpose AI system platform. This document facilitates conformity with leading AI risk management standards and frameworks, adapting and building on the generic voluntary guidance in the NIST AI RMF and ISO/IEC 23894 AI risk management standard, with a focus on the unique issues faced by developers of increasingly general-purpose AI systems.

September 13, 2023

White Paper

report cover showing students walking through a hall

A Comparative Study of Interdisciplinary Cybersecurity Education

By: Lisa Ho, Sahar Rabiei, Drake White, A Comparative Study of Interdisciplinary Cybersecurity Education

Authored by Lisa Ho and researchers from the UC Berkeley School of Information, this report examines how different universities approach the challenge of teaching cybersecurity through an interdisciplinary lens, with a goal to guide other educational institutions as they develop and create their cybersecurity programs.

August 7, 2023

White Paper

a series of health monitors shown side-by-side

A Template for Voluntary Corporate Reporting on Data Governance, Cybersecurity, and AI

By: Jordan Famularo, A Template for Voluntary Corporate Reporting on Data Governance, Cybersecurity, and AI

Corporations are increasingly called upon to disclose their practices around technology, including how they manage data, cybersecurity, and artificial intelligence. Yet no clear standard prescribes what such reporting…

May 31, 2023

White Paper

directional sign in front of sunset

Future Directions in Corporate Disclosure on Digital Responsibility

A CLTC report, Future Directions in Corporate Disclosure on Digital Responsibility, authored by CLTC Postdoctoral Scholar Jordan Famularo, illustrates how institutional investors, technology firms, and civil society are engaged in an elaborate set of processes and communications that are shaping norms about how companies should disclose information related to digital responsibility. The paper examines organizational dynamics that deter companies from reporting on digital responsibility, as well as factors that enable or motivate them to disclose such data.