Last updated: 2026-10-09 05:01 UTC
All documents
Number of pages: 175
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Chengsheng Pan, Yingzhi Wang, Huaifeng Shi, Lishang Qin, Xiaosong Cui | DBSDD-AQM: Dynamic Buffer Sizing-Based Deep Deterministic Active Queue Management for Edge IoT Networks | 2026 | Early Access | Delays Satellite broadcasting Internet of Things Modeling Management Learning (artificial intelligence) Information rates Throughput TCP Jitter Edge IoT networks network congestion active queue management dynamic buffer sizing deep deterministic policy gradient | Bursty heterogeneous traffic can build persistent queues at edge IoT gateways when the offered load converges on a lower-rate bottleneck. Conventional active queue management (AQM) regulates packet dropping under a fixed buffer capacity, whereas adaptive buffer sizing alone does not coordinate capacity adjustment with queue-removal control. We propose Dynamic Buffer Sizing-Based Deep Deterministic Active Queue Management (DBSDD-AQM), which combines a bounded buffersizing loop with a faster continuous queue-removal controller. DBS adjusts the admissible capacity according to sustained queue evolution, while the DDPG Actor selects packet-granular removal actions for the resident backlog. A class-aware extension maps three concurrent service classes to logical FIFO queues sharing the same dynamic physical buffer. DBSDD-AQM is implemented using an NS3-PyTorch framework. Aggregate experiments compare it with RED, ARED, PIE, CoDel, and DQN-AQM, while the class-aware evaluation additionally includes FQ-CoDel and FQ-PIE. Matched-DBS comparisons show similar throughput but different delay–loss operating points among the aggregate controllers, and component ablation distinguishes the effects of capacity adaptation and learned queue removal. Relative to a fixed 50 KB buffer, DBS reduces average queueing delay by 16.23% for UDP and 17.70% for TCP Westwood in controlled transport experiments. In the evaluated three-class overload scenarios, all classes retain nonzero throughput. Class-aware DBSDD-AQM provides stronger D- and T-class differentiation, whereas FQ-CoDel and FQ-PIE produce more uniform class-level outcomes and stronger R-class performance. The measured 95th-percentile batch-one Actor inference latency is 0.109 ms on the reported x86-64 platform. | 10.1109/TNSM.2026.3741334 |
| Hongyuan Cheng, Lihua Yin, Tianqing Zhu, Hongyu Yang, Dexin Zhu, Weixiang Jiang, Nan Wei | Pattern2Bot: A malicious server IP detection model based on self-trained heterogeneous graph neural network | 2026 | Early Access | Labeling Modeling Signal detection Training Botnet Servers IP networks Sequential analysis Conferences Security Botnet detection Self-supervised Graph neural network Command & Control service | Botnets play a key role in network attacks such as Distributed Denial-of-Service (DDoS) attacks, spamming and click fraud. Command & Control server is an important node for botmaster to control bots and distribute attack commands. Bot disguise as normal domain requests through DNS traffic, but leave malicious records in DNS logs containing client IP, query domain, server IP and other complex interactions. This information provides important clues for detecting those botnets. In the current study, researchers detect botnets through multiple perspectives, including abstracting DNS communication records into graphs and using graph neural network models for detection. Conventional approaches often necessitate massive labeled datasets for model training, which substantially incurs training costs. Moreover, despite enriching node embeddings via topological relations, graph models often suffer performance degradation when confronted with structural semantic obfuscation from evasion techniques like double-flux. In order to understand the abstract and complex relationship patterns in DNS records while reducing label usage to lower training costs, we propose a botnet Command & Control server detection model based on DNS traffic. This is a self-training heterogeneous graph neural network model that does not require a large number of labels. By integrating the high-order relational semantics derived from multiple meta-paths with the local topologies of target nodes, the model achieves finer-grained structural awareness and semantic abstraction, thereby enhancing detection performance. We validate the effectiveness of the model in a real dataset, and the results show that the model has a better understanding of the special structure possessed by the IPs of Command & Control servers. | 10.1109/TNSM.2026.3741111 |
| Haotian Lu, Yuning Dong, Guanming Lu, Pingping Tang, Jiong Jin | Federated Unknown Traffic Detection with Enhanced Contrastive Pre-training and Prototyping | 2026 | Early Access | Modeling Training Federated learning Fluid flow Prototypes Labeling Servers Signal detection Timing Indexes open-set traffic classification federated learning network traffic classification contrastive learning | With the increasing demand for privacy and distributed data compliance, federated learning (FL) has become a promising paradigm for collaborative network traffic classification (NTC) without sharing raw traffic data. However, real-world network environments are inherently open, where the emergence of new applications and unknown attacks introduces open-set challenges. To ensure service quality and network security, models need not only to classify known traffic classes accurately but also to identify unknown ones. Despite recent efforts to extend FL to Open-Set NTC (OSNTC), most current FL methods are still confined to the closed-set assumption, leaving the challenge of Federated OSNTC (FedOSNTC) largely unresolved. Therefore, this paper proposes FedUTD, a novel Federated Unknown Traffic Detection framework that introduces: (1) multi-scale prefix truncation, a customized contrastive learning strategy that leverages multi-granularity traffic characteristics to enhance feature discriminability; (2) an improved federated communication mechanism that enriches the transmitted information through pseudo-sample generation to mitigate data heterogeneity while retaining substantially lower communication cost; (3) a lightweight dual-layer OSNTC approach designed to reduce local training and inference overhead during local unknown-traffic detection. Extensive experiments on four real-world network traffic datasets demonstrate that FedUTD consistently outperforms existing methods, achieving an F1 gain of 5–21%. | 10.1109/TNSM.2026.3739767 |
| Mohammad Khosravi, Setareh Maghsudi | A Robust Optimization Approach for Regenerator Placement in Fault-Tolerant Networks Under Discrete Cost Uncertainty | 2026 | Early Access | IP networks Costing Costs Timing Modeling Optimization Uncertainty Joining processes Fluid flow Distance measurement Survivable networks robust optimization regenerator placement integer programming | We focus on robust, survivable communication networks, where network links and nodes are affected by an uncertainty set. In this sense, any network links might fail. Besides, a signal can only travel a maximum distance before its quality falls below a certain threshold, necessitating its regeneration by regenerators installed at network nodes. In addition, the price of installing and maintaining regenerators belongs to a discrete uncertainty set. Robust optimization seeks a solution with guaranteed performance against all scenarios modeled in an uncertainty set. Thus, the problem is to find a subset of nodes with minimum cost for the placement of the regenerator, ensuring that all nodes can communicate even if a subset of network links fails. To solve the problem optimally, we propose two solution approaches, including one flow-based and one cut-based integer programming formulation, as well as their iterative exact method. Our theoretical and experimental results show the effectiveness of our methods. | 10.1109/TNSM.2026.3740028 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Yingjie Hu, Weiping Wang, Shigeng Zhang, Hong Song, Ziheng Huang, Song Guo | Dual-State Representation Learning for Multi-Granularity IoT Device Identification | 2026 | Early Access | Internet of Things Modeling Training Labeling Sequences Sequential analysis Testing Accuracy Contrastive learning Multitasking IoT security device identification self-supervised learning contrastive learning multi-granularity | The rapid growth of IoT devices has increased demand for traffic-based network asset management and security monitoring. Most existing methods operate in closed-set settings and may misclassify unseen devices as known models or return only an unknown label. To address this problem, this paper proposes a multi-granularity IoT device identification method based on dual-state representation learning. Device identity is modeled at three levels: type, manufacturer, and model, retaining type and manufacturer information when the device model cannot be reliably identified. The method extracts statistical, sequence, and raw-byte features and learns sequence and byte embeddings from idle and behavior traffic. Self-supervised learning and contrastive learning are used to improve the discriminative ability of representations. A state-aware gating mechanism then dynamically fuses the dual-state embeddings. Multi-task classification heads and confidence thresholds are used to support joint identification and rejection. Experiments on three public datasets show over 98% accuracy for known-device identification. The method also achieves over 97% accuracy for type and manufacturer prediction on the unknown-model test set and over 95% rejection rate for unknown models. Online deployment achieves an average latency of 3.1 ms and a throughput of 322 samples/s, demonstrating practical potential in open network environments. | 10.1109/TNSM.2026.3738728 |
| Yonglin Huang, Ping Du, Xixuan Zhou, Mingji Dong, Jiayu Zhou, Yu Cen, Min Shi, Hongbo Li, Xiaoliang Chen, Zuqing Zhu | Two-Tier Cooperative Routing Leveraging GSL Diversity for Large-Scale LEO Satellite Networks | 2026 | Early Access | Satellites Routing Low earth orbit satellites Timing Algorithms Modeling Orbits Orbits (stellar) Topology Stars LEO satellite networks Two-tier routing protocol Deflection routing GSL diversity | Nowadays, the fast development of large-scale low Earth orbit (LEO) satellite networks has been pushing for highly-efficient routing schemes that can realize quality-of-service (QoS) aware routing adaptively. However, the dynamic nature of LEO satellite networks and the capacity mismatch between their inter-satellite links (ISLs) and ground-satellite links (GSLs) make QoS-aware routing very challenging. In this work, we propose a two-tier cooperative routing framework (namely, 2T-CoR) to leverage GSL diversity and deflection routing for effectively relieving congestion, thereby improving QoS parameters such as packet loss rate and end-to-end (E2E) latency. We first develop a time-sliced model to utilize the orbital periodicity of LEO satellite networks for accelerating their routing calculations. Then, a two-tier cooperative routing algorithm is designed to seamlessly synergize orbital periodicity with GSL-state awareness to efficiently reduce congestion as well as improving GSL utilization. Extensive simulations with a constellation of 3; 840 LEO satellites verify the effectiveness of our proposal over the state-of-the-arts. | 10.1109/TNSM.2026.3740700 |
| Ahmed Métwalli, Moustafa H. Aly, Heba A. Fayed, Waleed K. Badawi | MITO: Physics-Gated Multi-Domain Digital-Twin Orchestration for 6G Network and Service Management | 2026 | Early Access | Modeling Management Joining processes Synchronization Couplings Schedules Scheduling Service level agreements Physics Calibration Network and service management network digital twin multi-agent orchestration service assurance fault management performance management robust evidence fusion 6G networks | Heterogeneous sixth-generation (6G) services can fail through coupled degradation across radio access, photonic fronthaul, free-space optical backhaul, and the service-monitoring plane. These domains are commonly optimized independently by existing artificial-intelligence controllers, for which limited support is provided for safe closed-loop service management. Multi-domain Intelligent Twin Orchestration (MITO) is presented as a trace-driven, physics-gated network digital twin for cross-domain service assurance. Four domain-evidence sources totaling 41,554 records are synchronized; 15 scheduled agent tasks are executed through a safety-gated directed acyclic graph; time-varying cross-domain coupling is learned; contradictory evidence is robustly fused; and service-level recovery actions are calibrated. The evaluated trace-driven synchronization/update path requires 0.289 ms on average (p95: 0.347 ms), while the one-time validation threshold calibration requires 41.93 ms and the online FUSE/FALLBACK/BLOCK threshold decision requires approximately 0.0003 ms (0.3 μs). Under three-step telemetry delay and structured missingness, reference-aligned state consistency is reduced to 0.950 and 0.983, with action agreement of 0.915 and 0.971. Through validation-only service-specific policy calibration, a macro-F1 of 0.514 and balanced accuracy of 0.538 are obtained while FUSE, FALLBACK, and BLOCK are all produced on held-out data. On the measured 15-task DAG, a p95 makespan of 224.2 ms is achieved by the best safety-preserving scheduler, whereas lower latency under unconstrained full parallelism is accompanied by an unsafe-action rate of 1.0. Coupling recovery, ablations, attacks, and distribution shifts are also evaluated. | 10.1109/TNSM.2026.3741431 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Messaoud Ait-Yahia, Wael Jaafar, Rami Langar | Joint Design of Blockchain-Enabled Service Placement and Task Assignment in Vehicular Fog Computing Networks | 2026 | Early Access | Delays Timing Optimization Autonomous aerial vehicles Modeling Gallium Central Processing Unit Joints Bandwidth Elementary particles Resource allocation Blockchain VNF placement task assignment vehicular fog computing PSO GA IoV | Driven by the evolution of blockchain and fog computing, vehicular networks are increasingly capable of supporting latency-sensitive applications with enhanced security and trust guarantees. However, the joint resource allocation for task offloading and blockchain services has been insufficiently investigated in existing works. To address this gap, this paper proposes a framework for jointly allocating resources of blockchain, users’ virtualized services, and Mobile Edge Computing (MEC) task assignment in Vehicular Fog Computing (VFC) networks. Specifically, we formulate the optimization problem as an integer nonlinear programming model aiming to maximize the satisfaction rate of users’ service requests while minimizing the corresponding blockchain operation time under mobility, queuing, instantiation, and resource constraints. To solve it in a timely manner, we design two-stage hierarchical low-complexity solutions, namely a Particle Swarm Optimization-based Joint Blockchain-enabled Service placement and Task Assignment algorithm (PSO-JBSTA), and a Genetic Algorithm-based approach (GA-JBSTA). Through extensive simulations, we demonstrate the effectiveness of PSO-JBSTA (resp. GA-JBSTA) and their adaptability to network conditions, achieving an average 35% (resp. 24%) improvement in users’ service satisfaction rate and 9.5% (resp. 10.2%) reduction in average blockchain validation delay compared with the baselines. | 10.1109/TNSM.2026.3737068 |
| Amr Aboeleneen, Mohamed Abdallah, Aiman Erbad, Amr Salem | CIVIC: Cooperative Immersion Via Intelligent Credit-sharing in DRL-Powered Metaverse | 2026 | Early Access | Resource management Modeling Metaverse Costing Costs Optimization Head Accuracy Synchronization Actuators Deep Reinforcement Learning Immersion Metaverse Multi Service-Provider Resource Allocation Cooperative Systems Digital Twins | The Metaverse faces complex resource allocation challenges due to diverse Virtual Environments (VEs), Digital Twins (DTs), dynamic user demands, and strict immersion needs. This paper introduces CIVIC (Cooperative Immersion Via Intelligent Credit-sharing), a novel framework optimizing service-profile provisioning and budget-credit sharing among multiple Metaverse Service Providers (MSPs) to enhance user immersion. Unlike existing methods, CIVIC integrates VE rendering, DT synchronization, credit sharing, and immersion-aware provisioning within a cooperative multi-MSP model. The resource allocation problem is formulated as two NP-hard challenges: a non-cooperative setting where MSPs operate independently and a cooperative setting utilizing a General Credit Pool (GCP) for dynamic budget support. Using Deep Reinforcement Learning (DRL) for tuning resources and managing cooperating MSPs, CIVIC achieves 12-36% higher request completion, 23-70% higher fulfillment rates, 20-60% more served clients, and up to 51% more fairly distributed requests, all with competitive costs. Extensive experiments demonstrate CIVIC’s resilience, adaptability, and robust performance under dynamic load conditions and unexpected demand surges, making it suitable for real-world distributed Metaverse infrastructures. | 10.1109/TNSM.2026.3737119 |
| Marco Garofalo, Luca D’Agati, Laura García, Rafael Asorey-Cacheda, Antonio-Javier Garcia-Sanchez, Joan Garcia-Haro, Antonio Puliafito, Giovanni Merlino, Francesco Longo | Trustless SLA Enforcement and Roaming in LoRaWAN through Smart Contracts | 2026 | Early Access | Roaming Service level agreements LoRaWAN Internet of Things Smart contracts Contracts Radiation detectors Authorization Quality of service Containers Roaming LoRaWAN SLA QoS IoT blockchain smart contracts network management | LoRaWAN is widely used for Internet of Things (IoT) services that require long-range, low-power wireless connectivity. As deployments grow, roaming between different network operators becomes increasingly important to maintain service continuity for mobile IoT devices. In practice, however, roaming still depends on bilateral agreements and trusted intermediaries, which limit scalability and reduce transparency in multi-operator settings. This work introduces a blockchain-based roaming architecture that uses Algorand smart contracts to automate Service Level Agreement (SLA) management between providers. The system supports dynamic roaming agreements, immutable packet accounting, and transparent settlement. In our system, the enforced guarantee concerns forwarding-level service quality at the roaming interface, namely payment conditional on observed delivery ratio, rather than deterministic radio-layer latency or jitter guarantees. We implemented the full infrastructure, including a custom Gateway Bridge that extracts the Network Identifier (NetID), a blockchain service that interacts with Algorand smart contracts for SLA validation, and a decentralized provider catalog for operator discovery. We evaluated the system on a testbed with production-grade ChirpStack network servers and compared it with our previous non-blockchain implementation. Both versions achieve comparable throughput (5800–5900 packets/minute with 1000 devices) and maintain 99% packet forwarding efficiency. Blockchain integration adds measurable overhead, including a forwarding latency overhead in the 400–490 ms range for SLA validation, largely independent of the underlying network delay, but remains acceptable for delay-tolerant IoT services. Overall, the results show that decentralized LoRaWAN roaming can be implemented without breaking compatibility with existing network architectures. | 10.1109/TNSM.2026.3734694 |
| Heng He, Qin Xu, Hai Yu, Lei Nie, Jianfeng Lu | LFNC: A Lightweight and Fine-Grained Two-Stage Network Flow Classification Framework with Programmable Data Planes | 2026 | Early Access | Fluid flow Planing Modeling Switches Accuracy Internet of Things Filtering Filters Encoding Trees (botanical) Programmable data planes flow classification P4 decision tree cuckoo filter | Flow classification is a crucial component of network intrusion detection systems. Existing approaches mainly fall into two categories: in-network classification and control-data plane collaborative classification. The former is constrained by the computing and memory resources of programmable switches, often sacrificing classification accuracy and efficiency. The latter requires transmitting large volumes of packets to the control plane, leading to high processing latency, excessive control-channel overhead, and limited flow coverage. To address these challenges, we propose LFNC, a Lightweight and Fine-grained two-stage Network flow Classification framework with programmable data planes. In the first stage, LFNC introduces a Decision Tree Segmentation (DTS) algorithm to train resource-aware models in the control plane. The trained DTS models are converted into switch-compatible matching rules and deployed in the data plane to perform line-rate binary classification for preliminary anomaly detection. In the second stage, LFNC employs a cuckoo filter together with dual circular queues to selectively buffer essential packet features of preliminarily anomalous flows in the data plane and efficiently transfer them to the control plane. A multi-class energy-based flow classifier is then applied in the control plane to achieve accurate and fine-grained classification of anomalous flows. Experimental results on the Tofino hardware switch demonstrate that LFNC outperforms eight state-of-the-art baselines, improving flow collection rate by 1.07% and classification accuracy by 3.34%, while significantly reducing hardware resource consumption and maintaining low packet processing latency. | 10.1109/TNSM.2026.3738578 |
| Sheng-Shan Chen, Ren-Hung Hwang, Ying-Dar Lin, Tun-Wen Pai, Chin-Yu Sun | Extracting Attack Pattern from WAF Logs and CTIs Using Contrastive Semantic Learning | 2026 | Early Access | Modeling Payloads Cyber threat intelligence Labeling Large language models Training Cross-site scripting Modules (abstract algebra) Signal detection Grounding Web Application Firewall (WAF) Cyber Threat Intelligence (CTI) TTP Identification Contrastive Learning Monte Carlo Tree Search (MCTS) Semantic Search | Web Application Firewalls (WAFs) are widely deployed to protect web services, but their rule-based design provides limited visibility into attacker intent. WAF logs consist primarily of low-level HTTP artifacts that lack the behavioral context required for effective threat analysis. To address this limitation, we propose the first automated framework that mapsWAF logs to MITRE ATT&CK techniques through CTI-grounded semantic learning. The approach integrates structure-aware Monte Carlo Tree Search-based payload generation, CodeBERT-driven contrastive learning for attack classification, and cyber threat intelligence (CTI) alignment for TTP retrieval. The framework is evaluated on over 714,000 WAF logs derived from validated attack payloads across eight attack types, generated within a controlled environment using ModSecurity and OWASP Core Rule Set (CRS). Experimental results demonstrate 99.38% multi-class classification F1 score and identification of 206 unique ATT&CK techniques. Compared with a Rule-ID Heuristic baseline derived from OWASP CRS rule semantics, the proposed framework identifies 7.4× more unique ATT&CK techniques and provides substantially broader TTP-level visibility. External validation on a real-world ModSecurity log dataset further demonstrates that the framework preserves reliable classification and retrieval performance beyond the controlled payload-generation setting. | 10.1109/TNSM.2026.3738730 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Mubashir Murshed, Glaucio H. S. Carvalho, Robson E. De Grande | Holistic Intelligent Traffic Steering Management in Multi-RAT Vehicular Networks | 2026 | Early Access | Radio access technologies Rats Vehicles Modeling Long short term memory Poles and towers 5G mobile communication Joining processes Timing Received signal strength indicator Traffic Steering Multi-RAT Network Management Bi-level GCN-LSTM SARSA High-mobility Ultra-dense networks | Multiple Radio Access Technology (multi-RAT) environments provide a promising foundation for service-aware communication in intelligent transportation systems (ITS) and smart cities. However, traffic steering (TS) in highly mobile and ultra-dense vehicular networks remains challenging due to dynamic network conditions, heterogeneous RAT capabilities, varying vehicle requirements, packet loss, latency, and frequent ping-pong RAT switching. In this context, we propose Holistic Intelligent Traffic Steering (HITS), a proactive bi-level TS management framework for multi-RAT vehicular networks. HITS integrates centralized network-wide guidance with local vehicleside decision-making. At the central level, a Graph Convolutional Network–Long Short-Term Memory (GCN–LSTM) model captures holistic spatio-temporal network dynamics and evaluates RAT optimality. At the local level, a State-Action-Reward- State-Action (SARSA) reinforcement learning agent performs adaptive, vehicle-specific RAT selection using local observations and central-level optimality guidance. Results show that HITS achieves up to 6.5% higher average throughput, reduces packet loss ratio by more than 30.2%, lowers latency by nearly 12.2%, and reduces the ping-pong RAT switching rate by over 24% compared with baseline and state-of-the-art (SoTA) TS approaches. | 10.1109/TNSM.2026.3729840 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| João Gabriel Pazinato De Bittencourt, Fábio Gonçalves De Oliveira, Edson José Pacheco, Carlos Marcelo Pedroso | Packet-Level Causal Certification of Tail-Latency and Reliability Control in O-RAN Slicing | 2026 | Early Access | Radio access networks Regional area networks Context Modeling Ultra reliable low latency communication Tail Poles and zeros Arm Open RAN Resource management O-RAN network slicing URLLC tail latency reliability causal inference certification RAN Intelligent Controller | An O-RAN slice controller holds two levers, the resource-block budget and the scheduling discipline, and reads an aggregate proxy that can pass a slice dropping packets or overrunning its latency bound. A lever that correlates with a key performance indicator need not control it. We answer, at the packet level, which lever an operator may act on. We evaluate compliance over every generated packet and lower-bound the probability that a lever both achieved compliance and was necessary for it. The bound carries information only when computed within each operating context and then standardized. The other order reduces to the average treatment effect, and the two coincide whenever the lever effect keeps its sign. A zero-sum allocation lever breaks that condition: the budget it grants one slice is taken from another. Over 3,720 runs one lever effect reverses from +0.32 to −0.66 with the neighbour’s load while averaging −0.008, so the pooled bound is zero and the stratified bound 0.156. Two contrasts on that lever, averaging −0.008 and 0.000, certify at 0.156 and at zero, which the pooled average effect cannot separate. The error guarantee covers false declarations of an effect, not the safety of acting on one. | 10.1109/TNSM.2026.3740306 |
| Shyam Kumar Shrestha, Shiva Raj Pokhrel, Jonathan Kua | Adapting Large Language Models for TCP Fairness over Wi-Fi | 2026 | Early Access | Designing Transmission Control Protocol (TCP) Congestion Control Algorithms (CCAs) for heterogeneous Wi-Fi networks remains a challenge due to rapidly varying delay, loss, and contention dynamics. These effects often lead to CCA incompatibility, flow unfairness, and starvation among competing TCP flows. Although Deep Reinforcement Learning (DRL) has shown promise in mitigating these challenges, its slow convergence, high training costs, and limited generalization hinder practical deployments. In this paper, we propose TCP-LLM, a learning-augmented transport framework that leverages Large Language Models (LLMs) for compatibility-aware CCA selection. TCP-LLM encodes multivariate TCP time-series into token embeddings and performs single-step discrete CCA decisions through a lightweight LLM decision head. Parameter-efficient low-rank adaptation (LoRA) reduces the number of trainable parameters by approximately two orders of magnitude. Evaluation using traces collected from a physicalWi-Fi testbed with competing TCP Cubic, Bottleneck Bandwidth and Round-trip propagation time (BBR), and Performance-oriented Congestion Control (PCC) flows shows that TCP-LLM achieves the highest mean, geometric-mean, and minimum per-flow throughput among the evaluated schemes. TCP-LLM also exhibits faster and more stable training convergence and supports low-latency bounded inference. These results demonstrate the feasibility of LLM-based sequence adaptation for compatibility-aware transport-layer supervision under heterogeneous wireless conditions. | 10.1109/TNSM.2026.3739364 |