Last updated: 2026-09-20 05:01 UTC
All documents
Number of pages: 174
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Deepak Kanneganti, Sajib Mistry, Sheik Mohammad Mostakim Fattah, Erik Elmroth, Aneesh Krishna, Monowar Bhuyan | Performance Drift Detection in Machine Learning as a Service (MLaaS) for IoT Environments | 2026 | Early Access | Modeling Signal detection Internet of Things Accuracy Monitoring Machine learning Human activity recognition Streams Training Electricity Machine Learning as a Service IoT Performance Drift Drift Detection Model Monitoring | Machine Learning as a Service (MLaaS) is a powerful cloud paradigm enabling data-driven intelligent applications in Internet of Things (IoT) environments, widely adopted across healthcare, smart homes, and industry due to its costeff-ectiveness. However, the dynamic nature of IoT frequently alters data distributions, affecting MLaaS stability, while periodic MLaaS updates further introduce performance drift. Unlike traditional ML systems, MLaaS clients operate as black-box users without access to internal data or parameters, making drift detection particularly challenging. To address this, we propose a novel MLaaS Performance Drift Detection framework for IoT environments. The framework first employs an MLaaS extraction model that learns service behavior from input–output pairs and identifies prediction-influenced features. Building on this, the proposed MLaaS Performance Drift Detection (MPDD) model jointly captures variations in input data and MLaaS behavior.We further design an Adaptive-Temporal Performance Drift Detection Mechanism (APDDM) that dynamically adjusts monitoring frequency based on behavioral and data variations, enabling timely drift detection for effective service management. Extensive experiments on real-world datasets demonstrate that MPDD achieves up to 22–25% accuracy improvement over baseline drift detection methods. APDDM provides an average accuracy gain of approximately 4% and reduces the miss detection rate by around 9% compared to fixed-interval monitoring. | 10.1109/TNSM.2026.3732372 |
| Yuya Miyaoka, Masaki Inoue, Kengo Urata, Shigeaki Harada | Chat-Driven Optimal Management for Virtual Network Services | 2026 | Early Access | Modeling Large language models Central Processing Unit Virtual machines Resource management Program processors Routing Timing Optimization Conferences Natural language processing Intent-based networking Virtual network allocation Optimization | This paper proposes a chat-driven network management framework that integrates natural language processing (NLP) with optimization-based virtual network allocation, enabling intuitive and reliable reconfiguration of virtual network services. Conventional intent-based networking (IBN) methods depend on statistical language models to interpret user intent, but cannot guarantee the feasibility of generated configurations. To overcome this, we develop a two-stage framework consisting of an Interpreter, which extracts intent from natural language prompts using NLP, and an Optimizer, which computes feasible virtual machine (VM) placement and routing via integer linear programming. In particular, the Interpreter translates user chats into update directions, i.e., whether to increase, decrease, or maintain parameters such as CPU demand and latency bounds, thereby enabling iterative refinement of the network configuration. In this paper, two distinct Interpreter implementations are introduced: a Sentence-BERT model with support vector machine (SVM) classifiers and a large language model (LLM). Experiments in single-user and multi-user settings show that the framework dynamically updates VM placement and routing while preserving feasibility. The LLM-based approach achieves higher accuracy with fewer labeled samples, whereas the Sentence-BERT with SVM classifiers provides significantly lower latency suitable for real-time operation. We also compare our cascade structure method with an end-to-end LLM approach, highlighting our proposed method’s high level of reliability. | 10.1109/TNSM.2026.3726950 |
| Francisco Muro, Eduardo Baena, Tomaso De Cola, Sergio Fortes, Raquel Barco | AI-Driven Optimization of Virtual Network Function Allocation in 6G Non-Terrestrial Networks | 2026 | Early Access | Resource management Optimization Satellites Modeling Artificial intelligence Information rates Throughput Measurement 5G mobile communication Loading 6G Non-Terrestrial Networks O-RAN Kubernetes Virtual Network Functions VNF Allocation Machine Learning VNF Placement Gradient-Free Optimization Network Performance Resource Management | The integration of 6G technologies into Non-Terrestrial Networks (NTNs) raises a fundamental orchestration problem: how to allocate Virtual Network Functions (VNFs) across satellite and terrestrial domains under tight onboard resource constraints and a continuously changing topology. The virtualized 6G Open Radio Access Network (O-RAN) paradigm makes it possible to run 5G software stacks on Software-Defined Radios (SDRs) based on General Purpose Processors (GPPs), but it also turns VNF placement into a high-dimensional, multi-objective decision that static heuristics and model-based formulations struggle to capture. This paper addresses that gap by introducing an AI-driven VNF allocation framework for 6G-NTN environments built on an O-RAN-based distributed architecture and orchestrated on top of Kubernetes. The VNF allocation problem is formalized for a multi-domain 6G-NTN scenario with constrained satellite resources, and a measurement-based test campaign is designed to characterize the emulated platform in terms of virtual resource utilization and end-to-end performance. The framework couples tree-based machine learning predictors with a gradient-free optimizer to reach the optimal feasible allocation, outperforming two heuristic baselines drawn from the VNF placement literature by reducing the service RTT by up to 39% and delivering up to 3× higher YouTube DL throughput with respect to the best feasible heuristic. Beyond these gains, the proposed framework establishes a measurement-driven, reproducible methodology for VNF allocation in 6GNTN scenarios, demonstrating that AI-driven orchestration can systematically uncover non-obvious resource configurations that purely analytical or static approaches consistently miss. | 10.1109/TNSM.2026.3724474 |
| Martine S. Lenders, Carsten Bormann, Thomas C. Schmidt, Matthias Wählisch | A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPS | 2026 | Early Access | Internet of Things Encoding Internet Arrays Gain Recording Tagging Timing HTTP Decoding CBOR World Wide Web JSON DNS application/dns+cbor Internet measurements | The Internet community has taken major efforts to decrease latency on the World Wide Web with significant improvements in accelerating content transport and in compressing static content. Less attention, however, has been dedicated to compression of dynamic content. Such content is commonly provided by JSON and DNS over HTTPS. Dynamic content objects continue to grow in size, which increases latency and fosters the digital inequality. In this paper, we propose to mitigate this increase by utilizing Concise Binary Object Representation (CBOR), a standard originally designed for the constrained Internet of Things (IoT) to restrict packet sizes and enable efficient encoding of data objects. We provide protocol design and three new data sets for the evaluation of dynamic content, DNS, and the loading of websites. Our key findings are the following: (i) Switching the data representation from JSON to CBOR reduces data by up to 80%. This size reduction can decrease loading times by up to 13.8% when downloading large objects—even in local setups. (ii) Enabling CBOR for DNS over HTTPS (DoH) and DNS over CoAP (DoC) reduces packet sizes significantly. Compressing only names combined with unpacked CBOR achieves maximum gain of 52.2%, using more complex but still lightweight Packed CBOR allows minimizing packets by up to 95.5%. Our lean decoder for name compression can fit into as little as 314 bytes of build size. Our results clearly show the potential of CBOR outside of IoT scenarios. Parts of this research have already influenced work within the IETF. | 10.1109/TNSM.2026.3722114 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Stephen Jasina, Loqman Salamatian, Joshua Mathews, Scott Anderson, Paul Barford, Mark Crovella, Walter Willinger | Matisse: Visualizing Measured Internet Latencies as Manifolds | 2026 | Early Access | Manifolds Internet Measurement Visualization Delays Distance measurement Joining processes Surfaces Timing Europe network internet measurement curvature manifold visualization | Manifolds are complex topological spaces that can be used to represent datasets of real-world measurements. Visualizing such manifolds can help with illustrating their topological characteristics (e.g., curvature) and providing insights into important properties of the underlying data (e.g., anomalies in the measurements). In this paper, we describe a new methodology and system for generating and visualizing manifolds that are inferred from actual Internet latency measurements between different cities and are projected over a 2D Euclidean space (e.g., a geographic map). Our method leverages a series of graphs that capture critical information contained in the data, including well-defined locations (for vertices) and Ricci curvature information (for edges). Our visualization approach then generates a curved surface (manifold) in which (a) geographical locations of vertices are maintained and (b) the Ricci curvature values of the graph edges determine the curvature properties of the manifold. The resulting manifold highlights areas of critical connectivity and defines an instance of “Internet delay space” where latency measurements manifest as geodesics. We describe details of our method and its implementation in a tool, which we call Matisse, for generating, visualizing and manipulating manifolds projected onto a base map. We illustrate Matisse with three case studies: a simple example to demonstrate key concepts, and visualizations of the US and Europe public Internet to show Matisse’s utility. | 10.1109/TNSM.2026.3730274 |
| Bita Fatemipour, Zhe Zhang, Marc St-Hilaire | Adaptive Routing Optimization with Cost and Deadline Awareness Using Hierarchical Deep Reinforcement Learning | 2026 | Early Access | Costing Costs Routing Optimization Graph neural networks Timing Topology Joining processes Training Learning (artificial intelligence) Deep Reinforcement Learning Graph Neural Networks Optimization Traffic Engineering Wide-Area Networks Hierarchical RL Adaptive Routing | Timely and cost-efficient data transfers in large-scale networks remain challenging due to diverse topologies, non-uniform pricing models, and variable traffic demands. Existing literature often relies on multi-objective optimization, employing heuristic methods to reduce computational complexity; however, these approaches typically assume stable or predictable demand and struggle to scale effectively. Reinforcement Learning (RL) has been explored for its adaptability, yet many RL-based methods remain single-objective or topology-agnostic. This paper introduces CD-DRL, a hierarchical Deep RL framework that jointly optimizes transmission cost and deadline satisfaction, two objectives that often conflict in large-scale networks, through two cooperative agents. A routing agent, built on a Graph Neural Network, selects paths over a structured, multi-binary action space, enabling topology-aware routing across varying network scales and demand patterns. An adaptive tuning agent observes network state and recent performance to dynamically adjust the cost-deadline tradeoff to best fit current conditions. This hierarchical design allows CD-DRL to respond to dynamic network events such as congestion and bandwidth fluctuations, where no single fixed tradeoff remains optimal. We validate CD-DRL through extensive experiments on diverse backbone topologies and request distributions under static and time-varying network conditions. Compared with a state-of-the-art GNN-based RL method and traditional heuristics, CD-DRL improves the deadline-met ratio by up to 25% while maintaining competitive total cost and demonstrating strong scalability. Additionally, CD-DRL achieves faster execution time than mathematical optimization baselines, enabling high-throughput, latency-sensitive routing in dynamic environments. | 10.1109/TNSM.2026.3731031 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Ahmed Rjiba, Hicham Lakhlef, Joachim Bruneau-Queyreix, Meriem Afif | Federated Learning in Fog Computing within IoT Environments: An up-to-date and comprehensive survey | 2026 | Early Access | Federated learning Internet of Things Edge computing Modeling Clouds Security Training Surveys Privacy Timing Internet of Things (IoT) Federated Learning (FL) Fog Computing (FC) Survey Digital Twin (DT) | The Internet of Things (IoT) connects diverse, resource-constrained devices, driving innovation in domains such as healthcare, smart cities, and industrial automation. However, the exponential growth of IoT devices poses critical challenges in data processing, privacy, security, and latency. Fog Computing (FC) mitigates these issues by decentralizing computational resources, processing and storing data locally to enable low-latency, high-quality services. This makes FC an ideal platform for integrating Federated Learning (FL), a decentralized machine learning paradigm that trains models locally on IoT devices and shares only aggregated updates, preserving data privacy. Since its introduction, FL has garnered considerable attention for enabling privacy-preserving collaborative model training in distributed environments. The convergence of IoT, FC, and FL offers substantial opportunities to advance IoT system performance, but it also presents challenges in resource allocation, security, energy efficiency, computational complexity, and system heterogeneity. This survey provides a comprehensive and up-to-date analysis of the integration of FL and FC within IoT environments, exploring their synergies, challenges, and state-of-the-art advancements.We review critical aspects, including infrastructure enhancements, security mechanisms, and the emerging role of Digital Twin (DT) technology, which creates virtual replicas of IoT devices to optimize system efficiency and real-time performance. Through case studies in healthcare and smart cities, we highlight practical applications of FL-FC integration. We compare our work with existing surveys, highlight its specific focus on the FL-FC-IoT-DT convergence, and identify open challenges and future research directions toward secure, scalable, and intelligent IoT ecosystems. | 10.1109/TNSM.2026.3731410 |
| Pingping Dong, Liying Chen, Xuan Yao, Kai Wang, Lianming Zhang, Jiawei Huang | Fumer: Proactive Time-Shifting for Synchronized Periodic Traffic in Distributed Training | 2026 | Early Access | Training Timing Modeling Optimization Joining processes Bandwidth Synchronization Algorithms Educational institutions Windows Data center network Distributed training traffic RDMA | The growth of distributed training models, with parameters now reaching the billion-scale, has shifted the system bottleneck from computation to communication. While Remote Direct Memory Access (RDMA) is widely deployed to improve network performance by circumventing the kernel mechanism, the synchronization-computation cycles under the synchronous parallel mode introduce a highly synchronized and periodic “on-off” bursty traffic pattern, which poses significant challenges to data center networking. Consequently, distributed training suffers from two critical bottlenecks: instantaneous congestion during communication and persistent link idleness during computation. These issues lead to severe bandwidth contention and resource underutilization, ultimately hindering overall training efficiency. To address these challenges, this paper proposes Fumer, a proactive periodic traffic optimization framework that shifts the congestion control paradigm from reactive rate adjustment to proactive time-shifting. Specifically, Fumer leverages In-band Network Telemetry (INT) and Fast Fourier Transform (FFT) with signal-wave separation to decompose interleaved traffic signals, aiming to overcome the lack of periodic awareness. Furthermore, Fumer employs an off-peak transmission optimization algorithm to calculate optimal time-shift values, thereby tackling synchronized congestion and link idleness. By executing proactive off-peak scheduling, Fumer shifts overlapping communication windows into idle periods to smooth traffic peaks in the time domain. Experimental results show that Fumer boosts average path throughput across all workloads to 86.3 Gbps, improving upon DCQCN (42.6 Gbps) by 102.6% and RECC by 22.1%. Furthermore, it reduces the average and 99.9th-percentile iteration times by up to 25.0%-45.4% and 25.5%-49.3%, respectively, demonstrating its efficacy and robustness across diverse large-scale training workloads. | 10.1109/TNSM.2026.3728016 |
| Ren-Hung Hwang, Jiao-Chuan Huang, Yuan-Cheng Lai, Ying-Dar Lin | Reinforcement Learning Meets LLM Honeypots: A MITRE Engage–Aligned Approach | 2026 | Early Access | Large language models Modeling Training Design methodology Linux Reinforcement learning Windows Learning (artificial intelligence) Art Tuning Cyber deception honeypot reinforcement learning large language models MITRE ATT&CK MITRE Engage SSH | The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A finetuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline (p < 0.001). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux (p < 0.001), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety. | 10.1109/TNSM.2026.3731455 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Jianer Zhou, Xinyi Qiu, Zhenyu Li, Gareth Tyson, Encheng Yu, Weichao Li, Heng Pan, Xinyi Zhang, Zhiwei Xu | Themis: An Adjustable Congestion Control Framework for Improving Video QoE | 2026 | Early Access | Quality of experience Videos Fluid flow TCP Timing TV Servers Optimization Algorithms Bandwidth Video QoE Congestion Control eBPF | Optimizing congestion control algorithms (CCAs) has the potential to enhance video quality of experience (QoE). The goal of this work is to devise a congestion control framework that (i) ensures that individual users enjoy high video QoE, while (ii) minimizing variance, such that QoE is fairly distributed across all users, especially in fluctuating network, such as cellular network. We present Themis, a video-centric congestion control framework. Themis first uses a distributed approach to allocate a fair target QoE for each client. Based on this fair QoE, Themis then selects congestion control actions to optimize for video QoE (rather than throughput) based on application-layer signals provided by the client. Thus, rather than trying to maximize a flow’s (fair) share of bandwidth, Themis optimizes a flow’s share of the QoE budget. We evaluate Themis in both emulated and production networks. We show that in cellular network Themis achieves a 12.4% QoE improvement compared with BBR, and 37.1% QoE standard deviation decrease compared with the state-of-the-art, Minerva. | 10.1109/TNSM.2026.3732350 |
| Siyu Jiang, Feng Guo, Di Chen, Yuan Liu, Ying Chen, Weijun Sun, Yu Wang, Shen Su | Smart Contract Vulnerability Detection via Mask Consistency with Dynamic Margin Adjustment | 2026 | Early Access | Labeling Modeling Smart contracts Signal detection Codes Contracts Learning (artificial intelligence) Training Educational institutions Conferences Smart contract vulnerability detection semi-supervised domain adaptation mask learning dynamic margin adjustment | With the rise of smart contract applications, new attacks that exploit contract vulnerabilities continue to emerge, and effective vulnerability detection methods are urgently needed. Deep learning-based methods have shown excellent performance. However, for new types of vulnerabilities, due to the lack of real labels to help the model learn subtle code differences, previous methods have difficulty distinguishing between vulnerable contracts and safe contracts with similar key code segments, resulting in false negatives. To address this problem, this paper proposes a smart contract vulnerability detection method that uses mask consistency (MC) and dynamic margin adjustment (DMA). Unlike traditional Masked Language Modeling (MLM) in CodeBERT that performs token-level reconstruction for general representation learning, our MC enforces classification-level consistency between a masked student network and an unmasked EMA teacher network at the semantic graph block level under semi-supervised domain adaptation. This enhances the model’s discriminative ability by adding contextual information of similar code segments as additional clues. Specifically, we define a student network to learn masked contracts, a teacher network to learn complete contracts, and implement few-shot learning through semi-supervised domain adaptation. In this process, the student network is helped to learn to correctly distinguish similar contracts by fusing contextual information. In order to guide students more effectively, we use DMA to screen high-quality pseudo-labels. We conduct extensive experiments on open source real-world vulnerability datasets, and the results show that our method significantly outperforms current mainstream deep learning methods in detecting six types of vulnerabilities. This approach also pioneers the application of domain adaptation and integrates MC with DMA in vulnerability detection, providing guidance for detecting different types of vulnerabilities. | 10.1109/TNSM.2026.3733072 |
| Yao Xin, Yuqiao Luo, Shufan Cao, Chongwu Dong, Qingfeng Tan | HBT: A Hybrid Bidding Tree for High-Performance Packet Classification | 2026 | Early Access | Heterojunction bipolar transistors Trees (botanical) Vegetation Memory Pediatrics Construction Information rates Throughput Indexes Indexing Decision tree packet classification performance rule partitioning | Traditional packet classification algorithms based on decision trees often rely on rule replication to increase lookup speed, which inevitably leads to memory explosion. Conversely, existing zero-replication methods frequently suffer from extreme tree depth and structural fragmentation. To address this dilemma, this paper proposes the Hybrid Bidding Tree (HBT), a high-performance architecture designed to enforce zero-replication while sustaining deterministic lookup throughput. First, HBT employs an Overlap-Aware Rule Decomposition (OARD) framework to proactively isolate topologically entangled rules, purifying the primary geometric space. Second, HBT introduces a dynamic competitive bidding mechanism for tree construction. At each node, a discrete bit-selection path and a continuous range-partitioning path compete to determine the optimal splitting strategy based on local geometric heterogeneity. Finally, to guarantee an O(N) memory boundary, unpartitionable residual rules are assigned to a single-level Onion-Peeling fallback structure, preserving linear memory growth while introducing additional sequential checks in the auxiliary path. Experimental evaluations on ClassBench-ng rulesets containing up to 256k rules demonstrate the efficacy of HBT. Compared with state-of-the-art algorithms such as PT-Tree and TupleTree, HBT achieves the highest lookup throughput across all twelve evaluated rulesets at both the 128k and 256k scales, while maintaining strong memory efficiency and highly competitive construction and update latencies. | 10.1109/TNSM.2026.3734240 |
| Larisa-Mihaela Tufeanu, Marius-Constantin Vochin, Frank Y. Li | Residual Artifact Governance With ML-Enabled Garbage Collection Prediction in Kubernetes-Based 5G/6G Service-Based Architecture | 2026 | Early Access | Management Retrieval augmented generation Monitoring 5G mobile communication Modules (abstract algebra) Evolution (biology) Modeling Architecture Computer architecture 3GPP 5G/6G service-based architecture Kubernetes residual artifact governance ML-enabled garbage collection prediction implementation and experiments | The evolution of the service-based architecture (SBA) requires cloud-native core networks, and its open and modular design nature makes Kubernetes the most eminent platform for SBA implementation. One critical-yet-underexplored issue when deploying the SBA based on Kubernetes is the accumulation of residual artifacts that persist and degrade observability and stability inside Kubernetes clusters. In this paper, we propose residual artifact governance (RAG), a non-intrusive add-on module to the SBA that enforces bounded garbage collection (GC) policies without modifying the underlying architecture. The module follows a master–agent structure: a GC-master derives data-driven machine learning-enabled cleanup policies using the GC data provided by GC-agents, while GC-agents co-located at each network function execute deterministic, auditable cleanup actions. As a proof-of-concept demonstration, we implement a Kubernetes-based prototype to validate the operability and feasibility of RAG. While a machine learning predictor located at the GC-master provides early warning signals on time-to-collapse caused by the accumulation of residual artifacts, periodic fractional cleanup actions at GC-agents keep residual peaks bounded under both nominal and stress leak regimes. Results reveal that the accumulation of residual artifacts can be measured, predicted, and controlled using Kubernetes-native mechanisms through our RAG enhancement while remaining compatible with 3GPP-aligned observability and stability assurance principles. | 10.1109/TNSM.2026.3734448 |
| Liwei Zhang, Tong Zhang, Xiaoqin Feng, Wenxue Wu, Hao Yang, Ping Liu, Yanying Ma, Fengyuan Ren | Leveraging Hot Standby Routing to Improve Reliability in TSN | 2026 | Early Access | Fluid flow Timing Joining processes Bandwidth Routing Switches Ports (computers) Delays Schedules Topology Time-Sensitive Networking Link Failure Reliability Reroute Hot Standby Routing | Time-Sensitive Networking (TSN) is widely deployed in industrial networks because it can provide deterministic transmission services for Time-Triggered (TT) flows. Link failures pose severe threats to the reliability of TT flows. Frame Replication and Elimination for Reliability (FRER) defined by IEEE 802.1 CB tolerates such failures by transmitting the same frames via disjoint paths, but this introduces excessive bandwidth overhead. To this end, we present a Hot Standby Routing (HSR) mechanism tailored for TSN to ensure the reliability of TT flows while minimizing bandwidth usage. Unlike FRER, HSR can locally reroute a single frame to achieve tolerance to link failures. Specifically, the primary and secondary paths are computed hop-by-hop for each TT flow and installed on the switches in the network. Under normal conditions, the secondary path is in a silent standby state. If the primary path fails, the affected TT flow will be seamlessly rerouted to the secondary path by the local switch for transmission. The simulation results show that HSR can provide highly reliable transmission for TT flows while significantly reducing bandwidth consumption. Furthermore, HSR exhibits stronger robustness in large-scale networks. | 10.1109/TNSM.2026.3733170 |
| Ang Cao, Xiaodan Yan, Yongli Zhao, Yuanjian Zhang, Jian Yang, Ruiqi Liu | RoQuant: Resilient LLM Service Provisioning and Resource Management in Soft-Error-Prone Satellite Networks | 2026 | Early Access | Modeling Matrices Sensitivity Quantization (signal) Large language models Bit error rate Training Resource management Encoding Accuracy Large Language Models Network and Service Management Non-Terrestrial Networks Service Resilience Resource-Constrained Provisioning Single Event Upsets | Deploying Large Language Models (LLMs) on satellite-edge platforms requires aggressive compression under strict Size, Weight, and Power (SWaP) constraints, yet low-bit models are vulnerable to radiation-induced soft errors. We propose RoQuant, a three-stage framework that profiles matrix-level fault vulnerability, selects a resource-aware mixed-precision configuration with SAPS, and stabilizes the selected backbone using DoRA adaptation and PACT clipping. Under the BER = 1 × 10−6 stress test, RoQuant avoids catastrophic QoS collapse on all three evaluated backbones, whereas several uniform low-bit baselines collapse. On Qwen2.5-1.5B, Qwen2.5-3B, and Llama-3.2-3B, RoQuant reduces the analytical encoded-weight footprint by 52.6%, 54.4%, and 49.2% relative to FP16, retains 81.1%, 85.6%, and 94.6% of the respective RoQuant configurations’ clean GSM8K accuracies, and incurs measured end-to-end service-delay overheads of 10.6%, 12.4%, and 17.0% relative to the corresponding FP16 baselines, respectively. These results provide a practical resilience–efficiency operating point for SWaP-constrained satellite-edge LLM deployment, particularly when on-board model storage is the dominant constraint and a modest software-latency increase is acceptable. | 10.1109/TNSM.2026.3734530 |
| Hussein Fawaz, Jacopo Talpini, Marco Savi, Silvia Giordano, Omran Ayoub | Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty | 2026 | Early Access | Modeling Uncertainty Training Internet of Things Poles and zeros Radio frequency Signal detection Intrusion detection Machine learning Fluid flow Network Intrusion Detection Explainable AI Uncertainty Quantification Zero-day Attacks | In practical Network Intrusion Detection System (NIDS) deployments, detecting anomalies is only the first step, while determining the exact nature of those anomalies is equally important. Commonly, anomalous traffic is forwarded to a supervised multiclass classifier trained to identify known attack categories. While effective for known threats, this step presents a significant limitation, as zero-day attacks can be misclassified as known attacks. Therefore, there is a need for approaches that go beyond standard classification and can reliably recognize when an input does not conform to any learned attack pattern, i.e., zero-day attacks. To tackle this problem, we propose a novel detection strategy that leverages per-instance feature importance scores from an explainable Artificial Intelligence (XAI) framework and prediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experiments using a leave-one-attack-out strategy across three benchmark datasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, and test performance under two underlying classifiers, namely XG-Boost and Random Forest, demonstrating the model-agnostic nature of our method. Experimental results show that our approach achieves best-case AUROC gains approaching 40% and F1-score improvements of up to 73%, while maintaining positive or near-neutral worst-case performance across datasets, highlighting the effectiveness and robustness of jointly modeling explanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification. | 10.1109/TNSM.2026.3731401 |
| Xiaodi Wang, Yunwei Dong, Weizhi Meng, Meng Li, Yining Liu | Dropout-Tolerant Privacy-Preserving Aggregation for Federated Mobile Crowdsensing | 2026 | Early Access | Modeling Privacy Internet of Things Training Federated learning Accuracy Calcium Timing Silicon Security Mobile crowdsensing Federated learning Privacy preservation Dropout tolerance Homomorphic encryption | Federated Learning (FL) has emerged as a key enabler for privacy-preserving, decentralized sensing systems, giving rise to Federated Mobile Crowdsensing (F-MCS). A well-known bottleneck in such systems is the inefficiency of synchronous training, which stalls for all participants and is susceptible to stragglers in heterogeneous environments. Although asynchronous FL methods have been explored to alleviate this, they often introduce the critical issue of stale updates, which can degrade model convergence and accuracy. To simultaneously address the challenges of efficiency, staleness, and robustness, this paper proposes a novel Dropout-Tolerant Privacy Aggregation (DTPA) scheme for FL that operates without a trusted third party (TTP). Our solution leverages the distributed decryption feature of the lifted EC-ElGamal cryptosystem to enable secure, decentralized model aggregation. We further introduce an efficient worker selection algorithm to systematically reduce waiting time. Moreover, a dedicated dropout-tolerant mechanism is developed to maintain protocol execution even under a high rate of client failures, thereby enhancing robustness. Security analysis confirms that our scheme fulfills essential privacy and security requirements. Extensive simulations demonstrate that the proposed DTPA scheme significantly improves training efficiency and convergence stability compared to state-of-the-art methods, while remaining practical for deployment on resource-constrained mobile devices. | 10.1109/TNSM.2026.3732465 |