Last updated: 2026-09-29 05:01 UTC
All documents
Number of pages: 174
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Kim Hammar, Neil Dhir, Rolf Stadler | Optimal Defender Strategies for CAGE-2 using Causal Modeling and Tree Search | 2026 | Early Access | Modeling Timing Trees (botanical) Vegetation Weighted sum model Conferences Silicon Games Security Algorithms Cybersecurity network security causal inference SCM APT CAGE-2 POMDP intrusion response | The CAGE-2 challenge is considered a standard benchmark to compare methods for autonomous cyber defense. Current state-of-the-art methods evaluated against this benchmark are based on model-free (offline) deep reinforcement learning techniques, which do not provide provably optimal defender strategies. We address this limitation and present a formal (causal) model of CAGE-2 together with a method that converges to a provably optimal defender strategy, which we call causal partially observable Monte-Carlo planning (C-POMCP). Our method has two novel properties. First, it incorporates the causal structure of the target system through causal relationships among the system variables. This structure allows for a significant reduction of the search space of defender strategies. Second, it is an online method that updates the defender strategy at each time step via tree search. Evaluations against the CAGE-2 benchmark show that C-POMCP achieves state-of-the-art performance with respect to effectiveness and requires two orders of magnitude less computation than the closest competitor method. | 10.1109/TNSM.2026.3735865 |
| Huixiang Zhang, Faria Khandaker, Mahzabeen Emu | A Topology-Aware LLM-Augmented Digital Twin Framework for Scalable IoT Device Management | 2026 | Early Access | Internet of Things Topology Management Modeling Grounding Ciphers Context Training Optimization Large language models Large Language Models Digital Twins IoT | The growing scale and dynamic nature of Internet of Things (IoT) deployments demand management approaches that can maintain accurate system awareness. Existing large language models (LLMs) can reduce the interface burden of network management. However, without explicit grounding in the physical system state, they may generate nonexistent devices, incorrect topological relations, or non-executable management actions. To address this problem, this paper proposes a digital twin (DT) grounded LLM augmented management framework for IoT device management. The framework uses the DT as a structured state source, allowing the model to access topology consistent device, connection, and status information before generating management responses. A topology importance driven adapter training method, implemented through Hierarchical Importance Organizer (HIO), is further developed to encode hierarchical paths and critical nodes into training samples. We further characterize how grounded management degrades as the DT drifts from the physical topology, isolating the robustness contribution of topology-aware adaptation. Across 34,200 completed per-sample model outputs, including a 7,200-output main benchmark and a 27,000-output topology-drift sweep, HIO is evaluated against schema-only prompting, a base plus DT model, and a GenTwin-like adapter. On the 1,800-sample main benchmark, HIO achieves 0.869 Direct F1, improving over the GenTwin-like adapter by 3.3 points and over the base plus DT model by 29.1 points. HIO also improves Exact Match from 0.753 to 0.827. The gain is most pronounced in topology-sensitive impact analysis, where HIO improves Direct F1 from 0.784 to 0.918. HIO has positive gains in all nine topology–scale cells, with 95% confidence intervals excluding zero in seven cells. Under DT topology drift, HIO consistently outperforms the GenTwin-like adapter over δ ∈ [0, 0.20] and degrades more slowly, with Direct F1 degradation slopes of −0.157 versus −0.189. | 10.1109/TNSM.2026.3736467 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Hamidreza Mazandarani, Masoud Shokrnezhad, Tarik Taleb | A Semantic-Aware Multiple Access Scheme Leveraging Spatial Redundancy for Uplink-Dominant Network Services | 2026 | Early Access | Timing Titanium Modeling Information rates Throughput Energy efficiency Media Access Control Optimization Energy Training 6G Semantic-awareness Resource Allocation Multiple Access Medium Access Control (MAC) Wireless Spectrum Utilization Fairness Sustainability Energy Throughput Deep Q-Learning Reinforcement Learning Distributed | The transition toward semantic-aware communication offers a paradigm shift for next-generation mobile networks, promising to decouple information significance from raw data transmission. Despite advances in semantic extraction, the integration of semantic intelligence into the Medium Access Control (MAC) layer remains underexplored, particularly in exploiting spatial correlations among users. To address this, we introduce a novel multiple access scheme designed for uplink-dominant network services. This framework optimizes the trade-off between spectrum utilization and sustainability by formulating variable-packet-length access as distinct α-fairness and energy efficiency problems. A key innovation of our approach is the quantification of spatial redundancies through novel metrics of self-throughput and assisted-throughput, which account for the semantic correlation of data across user equipment. We analyze these formulations to identify optimal bounds before proposing PRISM (Protocol for Redundancy Identification in Semantic Multiple-access). Grounded in Model-free Multi-Agent Deep Reinforcement Learning (MADRL), PRISM enables devices to autonomously govern spectrum access using only local observations. Extensive evaluations demonstrate that PRISM successfully leverages redundancies to outperform semantic-oblivious schemes, achieving up to 90% of the centralized optimal benchmark and improving both objectives by up to 2× across diverse user-semantic association matrices. These results validate PRISM as a viable candidate for future distributed mobile network applications, complemented by orthogonal Multiple Access Schemes where signals are multiplexed in the semantic domain. | 10.1109/TNSM.2026.3737571 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Messaoud Ait-Yahia, Wael Jaafar, Rami Langar | Joint Design of Blockchain-Enabled Service Placement and Task Assignment in Vehicular Fog Computing Networks | 2026 | Early Access | Delays Timing Optimization Autonomous aerial vehicles Modeling Gallium Central Processing Unit Joints Bandwidth Elementary particles Resource allocation Blockchain VNF placement task assignment vehicular fog computing PSO GA IoV | Driven by the evolution of blockchain and fog computing, vehicular networks are increasingly capable of supporting latency-sensitive applications with enhanced security and trust guarantees. However, the joint resource allocation for task offloading and blockchain services has been insufficiently investigated in existing works. To address this gap, this paper proposes a framework for jointly allocating resources of blockchain, users’ virtualized services, and Mobile Edge Computing (MEC) task assignment in Vehicular Fog Computing (VFC) networks. Specifically, we formulate the optimization problem as an integer nonlinear programming model aiming to maximize the satisfaction rate of users’ service requests while minimizing the corresponding blockchain operation time under mobility, queuing, instantiation, and resource constraints. To solve it in a timely manner, we design two-stage hierarchical low-complexity solutions, namely a Particle Swarm Optimization-based Joint Blockchain-enabled Service placement and Task Assignment algorithm (PSO-JBSTA), and a Genetic Algorithm-based approach (GA-JBSTA). Through extensive simulations, we demonstrate the effectiveness of PSO-JBSTA (resp. GA-JBSTA) and their adaptability to network conditions, achieving an average 35% (resp. 24%) improvement in users’ service satisfaction rate and 9.5% (resp. 10.2%) reduction in average blockchain validation delay compared with the baselines. | 10.1109/TNSM.2026.3737068 |
| Mohamed Zalat, Chris Barber, Babak Esfandiari, Thomas Kunz | A Reusable Network Digital Twin Architecture for QoS-Centric Network Management | 2026 | Early Access | Modeling Fluid flow Optimization Joining processes Delays Management Topology Border Gateway Protocol Measurement Quality of service Network Digital Twins Digital Twins IGP BGP Fault Localization Networks | We propose a network digital twin approach for Quality of Service (QoS)-centric network management and demonstrate it on multiple network management problems. Our network digital twin involves running many ”what-if?” network configurations using a fast inference model for predicting network behavior, and applying the best configuration found based on the criteria of the network operator. We demonstrate the flexibility of this approach by applying it to 3 different network management problems: Interior Gateway Protocol (IGP) weight optimization, Border Gateway Protocol (BGP) route assignments, and gray fault detection and localization. We test our approach for each application on various OMNeT++ topologies and compare it to existing benchmarks in the respective literature. Our results indicate that the proposed network digital twin approach performs comparably to existing benchmarks in the network management problems explored and sometimes outperforms them in quality of service metrics. | 10.1109/TNSM.2026.3737654 |
| Nilesh Chakraborty, Petar Djukic, Burak Kantarci | Aggressive-YoYo: Exploiting Intent-Semantic Misalignment in AI-Native 6G Management Planes | 2026 | Early Access | Central Processing Unit Management Modeling Delays Aggregates Loading Memory Training Convolutional neural networks Probes AI-Native Network Intent Security Kubernetes Auto Scaling Threat Detection | Intent-Based Networking (IBN) enables operators to express high-level service objectives that are automatically translated into low-level control and orchestration policies. In AI-native 6G management planes, semantic misalignment during this translation can induce unsafe configurations that amplify conventional resource-exhaustion attacks. We investigate this vulnerability through aggressive-YoYo, a compound threat combining YoYo-style burst traffic with prematurely configured Kubernetes readiness probes. We implement an end-to-end Intent-to-Configuration pipeline that resolves natural-language service intents into structured policies, compiles them into Kubernetes probe settings, and evaluates the resulting behavior using a representative slice-assurance management function on Google Kubernetes Engine (GKE). Controlled readiness-delay experiments show that premature readiness can increase replica provisioning, aggregate CPU and memory consumption, storage activity, and request failures, while inducing non-trivial service-level tradeoffs. Similar resource amplification under a different N1-family machine type and deployment zone indicates that the effect is not specific to a single configuration.We further analyze readiness misconfiguration across multiple Kubernetes scaling mechanisms and derive service-specific safe and amplifying configuration regions. From the detection perspective, we show-case that aggressive-YoYo is detectable using fully supervised temporal classifiers evaluated with cycle-disjoint testing and feature-set ablation; the best configuration achieves an average accuracy of 92.6%. Under scarce aggressive-YoYo supervision, i.e., limited exposure to aggressive-YoYo traces, the supervised approach improves detection over the one-class setting. These results show that intent-semantic misalignment creates measurable cross-layer management risks and motivate semantic validation and telemetry-aware monitoring for trustworthy AI-native 6G orchestration. | 10.1109/TNSM.2026.3736983 |
| Junior Momo Ziazet, Brigitte Jaumard | Energy Efficient Placement of Logical Functionalities in 5G Networks | 2026 | Early Access | Energy Copper Modeling Energy consumption Joining processes Optimization 5G mobile communication Timing Delays Algorithms 5G Logical Functionalities Network Function Placement DU/CU/UPF Optimization Energy Efficiency mathematical optimization Column Generation | Although 5G networks are more efficient in terms of power consumption to traffic ratio, efforts still need to be made to further increase energy efficiency not only for the radio part, but also with respect to the growing cloud component with edge servers. Consolidation of traffic workloads onto shared infrastructures is a key feature of cloud computing to reduce energy consumption, and logical functionality placement plays a key role in this regard. Here, in the cloud RAN context, we propose a unified and energy-aware logical placement of 5G E2E functionalities, i.e., distributed units (DUs), centralized units (CUs), and user plane functions (UPFs), together with traffic routing. The placement problem is formulated as a large-scale integer linear program and solved using a column generation-based decomposition technique, complemented by an efficient heuristic to ensure tractability and improved scalability. The model captures key network and cloud (compute) resources, jointly optimizing the placement of DU, CU, and UPF components, along with traffic routing, to minimize energy consumption while maintaining low latency and high Quality of Service (QoS). Numerical results, based on an open Montreal traffic dataset, demonstrate that the proposed column generation algorithm achieves near-optimal solutions, while the heuristic approach offers significantly better scalability with consistently strong performance. The proposed methods reduce energy consumption by up to 14% and maintain low-latency service delivery. Furthermore, the results highlight that static, peak-time-based placement strategies can lead to inefficiencies throughout the day, emphasizing the importance of accounting for broader temporal traffic patterns. | 10.1109/TNSM.2026.3729149 |
| Hussein Fawaz, Jacopo Talpini, Marco Savi, Silvia Giordano, Omran Ayoub | Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty | 2026 | Early Access | Modeling Uncertainty Training Internet of Things Poles and zeros Radio frequency Signal detection Intrusion detection Machine learning Fluid flow Network Intrusion Detection Explainable AI Uncertainty Quantification Zero-day Attacks | In practical Network Intrusion Detection System (NIDS) deployments, detecting anomalies is only the first step, while determining the exact nature of those anomalies is equally important. Commonly, anomalous traffic is forwarded to a supervised multiclass classifier trained to identify known attack categories. While effective for known threats, this step presents a significant limitation, as zero-day attacks can be misclassified as known attacks. Therefore, there is a need for approaches that go beyond standard classification and can reliably recognize when an input does not conform to any learned attack pattern, i.e., zero-day attacks. To tackle this problem, we propose a novel detection strategy that leverages per-instance feature importance scores from an explainable Artificial Intelligence (XAI) framework and prediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experiments using a leave-one-attack-out strategy across three benchmark datasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, and test performance under two underlying classifiers, namely XG-Boost and Random Forest, demonstrating the model-agnostic nature of our method. Experimental results show that our approach achieves best-case AUROC gains approaching 40% and F1-score improvements of up to 73%, while maintaining positive or near-neutral worst-case performance across datasets, highlighting the effectiveness and robustness of jointly modeling explanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification. | 10.1109/TNSM.2026.3731401 |
| Marco Garofalo, Luca D’Agati, Laura García, Rafael Asorey-Cacheda, Antonio-Javier Garcia-Sanchez, Joan Garcia-Haro, Antonio Puliafito, Giovanni Merlino, Francesco Longo | Trustless SLA Enforcement and Roaming in LoRaWAN through Smart Contracts | 2026 | Early Access | Roaming Service level agreements LoRaWAN Internet of Things Smart contracts Contracts Radiation detectors Authorization Quality of service Containers Roaming LoRaWAN SLA QoS IoT blockchain smart contracts network management | LoRaWAN is widely used for Internet of Things (IoT) services that require long-range, low-power wireless connectivity. As deployments grow, roaming between different network operators becomes increasingly important to maintain service continuity for mobile IoT devices. In practice, however, roaming still depends on bilateral agreements and trusted intermediaries, which limit scalability and reduce transparency in multi-operator settings. This work introduces a blockchain-based roaming architecture that uses Algorand smart contracts to automate Service Level Agreement (SLA) management between providers. The system supports dynamic roaming agreements, immutable packet accounting, and transparent settlement. In our system, the enforced guarantee concerns forwarding-level service quality at the roaming interface, namely payment conditional on observed delivery ratio, rather than deterministic radio-layer latency or jitter guarantees. We implemented the full infrastructure, including a custom Gateway Bridge that extracts the Network Identifier (NetID), a blockchain service that interacts with Algorand smart contracts for SLA validation, and a decentralized provider catalog for operator discovery. We evaluated the system on a testbed with production-grade ChirpStack network servers and compared it with our previous non-blockchain implementation. Both versions achieve comparable throughput (5800–5900 packets/minute with 1000 devices) and maintain 99% packet forwarding efficiency. Blockchain integration adds measurable overhead, including a forwarding latency overhead in the 400–490 ms range for SLA validation, largely independent of the underlying network delay, but remains acceptable for delay-tolerant IoT services. Overall, the results show that decentralized LoRaWAN roaming can be implemented without breaking compatibility with existing network architectures. | 10.1109/TNSM.2026.3734694 |
| Liwei Zhang, Tong Zhang, Xiaoqin Feng, Wenxue Wu, Hao Yang, Ping Liu, Yanying Ma, Fengyuan Ren | Leveraging Hot Standby Routing to Improve Reliability in TSN | 2026 | Early Access | Fluid flow Timing Joining processes Bandwidth Routing Switches Ports (computers) Delays Schedules Topology Time-Sensitive Networking Link Failure Reliability Reroute Hot Standby Routing | Time-Sensitive Networking (TSN) is widely deployed in industrial networks because it can provide deterministic transmission services for Time-Triggered (TT) flows. Link failures pose severe threats to the reliability of TT flows. Frame Replication and Elimination for Reliability (FRER) defined by IEEE 802.1 CB tolerates such failures by transmitting the same frames via disjoint paths, but this introduces excessive bandwidth overhead. To this end, we present a Hot Standby Routing (HSR) mechanism tailored for TSN to ensure the reliability of TT flows while minimizing bandwidth usage. Unlike FRER, HSR can locally reroute a single frame to achieve tolerance to link failures. Specifically, the primary and secondary paths are computed hop-by-hop for each TT flow and installed on the switches in the network. Under normal conditions, the secondary path is in a silent standby state. If the primary path fails, the affected TT flow will be seamlessly rerouted to the secondary path by the local switch for transmission. The simulation results show that HSR can provide highly reliable transmission for TT flows while significantly reducing bandwidth consumption. Furthermore, HSR exhibits stronger robustness in large-scale networks. | 10.1109/TNSM.2026.3733170 |
| Siyu Jiang, Feng Guo, Di Chen, Yuan Liu, Ying Chen, Weijun Sun, Yu Wang, Shen Su | Smart Contract Vulnerability Detection via Mask Consistency with Dynamic Margin Adjustment | 2026 | Early Access | Labeling Modeling Smart contracts Signal detection Codes Contracts Learning (artificial intelligence) Training Educational institutions Conferences Smart contract vulnerability detection semi-supervised domain adaptation mask learning dynamic margin adjustment | With the rise of smart contract applications, new attacks that exploit contract vulnerabilities continue to emerge, and effective vulnerability detection methods are urgently needed. Deep learning-based methods have shown excellent performance. However, for new types of vulnerabilities, due to the lack of real labels to help the model learn subtle code differences, previous methods have difficulty distinguishing between vulnerable contracts and safe contracts with similar key code segments, resulting in false negatives. To address this problem, this paper proposes a smart contract vulnerability detection method that uses mask consistency (MC) and dynamic margin adjustment (DMA). Unlike traditional Masked Language Modeling (MLM) in CodeBERT that performs token-level reconstruction for general representation learning, our MC enforces classification-level consistency between a masked student network and an unmasked EMA teacher network at the semantic graph block level under semi-supervised domain adaptation. This enhances the model’s discriminative ability by adding contextual information of similar code segments as additional clues. Specifically, we define a student network to learn masked contracts, a teacher network to learn complete contracts, and implement few-shot learning through semi-supervised domain adaptation. In this process, the student network is helped to learn to correctly distinguish similar contracts by fusing contextual information. In order to guide students more effectively, we use DMA to screen high-quality pseudo-labels. We conduct extensive experiments on open source real-world vulnerability datasets, and the results show that our method significantly outperforms current mainstream deep learning methods in detecting six types of vulnerabilities. This approach also pioneers the application of domain adaptation and integrates MC with DMA in vulnerability detection, providing guidance for detecting different types of vulnerabilities. | 10.1109/TNSM.2026.3733072 |
| Serkut Ayvaşık, Alba Jano, Fidan Mehmeti, Wolfgang Kellerer | Sentinel: Vision-Based Signaling-Free SNR Prediction for Proactive 5G Resource Management | 2026 | Early Access | Resource management 5G mobile communication Convolutional neural networks Modeling Signal to noise ratio Feedback Long short term memory 3GPP Measurement Visual systems 5G Radio Resource Management Link Adaptation Deep Learning Computer Vision Environment-Aware Communications Channel Prediction Channel State Information SNR CQI | Reliable and efficient radio resource management in 5G systems critically depends on accurate Channel State Information (CSI) availability at the base stations. Traditionally, base stations perform scheduling, resource allocation, and link adaptation using the Channel Quality Indicator (CQI), either computed directly for uplink or obtained via CSI feedback reports for downlink. Both uplink and downlink procedures rely on frequent pilot and feedback transmissions, introducing significant overhead that challenges scalability and ultra-reliable communication demands. In this work, we introduce Sentinel, a vision-based machine learning system that leverages grayscale image sequences from an indoor environment to predict the SNR between user equipment and base station with a foresight window of 200 ms. Sentinel’s SNR prediction enables flexible CQI acquisition, allowing different SNR-to-CQI mappings without modifying the system, and eliminates the need for CQI-related pilot or feedback signaling. The proposed system is evaluated in a dynamic multi-user scenario comprising three heterogeneous 5QI service profiles across 40 users. Sentinel demonstrates superior CQI prediction performance, achieving substantial to near-perfect agreement with true CQI labels, as measured by the quadratic weighted kappa, and outperforming benchmark foresight-based CQI prediction models in both CQI classification and resource management effectiveness. Proactive resource management evaluations show that Sentinel meets the strict reliability targets of mission-critical 5QI services, achieving packet error rates below 10−4, and approaching 10−5 when integrated with signaling. Furthermore, Sentinel reduces total radio resource usage by up to 24% in the 40-user scenario by eliminating CQI-related signaling overhead. | 10.1109/TNSM.2026.3735937 |
| Jianer Zhou, Xinyi Qiu, Zhenyu Li, Gareth Tyson, Encheng Yu, Weichao Li, Heng Pan, Xinyi Zhang, Zhiwei Xu | Themis: An Adjustable Congestion Control Framework for Improving Video QoE | 2026 | Early Access | Quality of experience Videos Fluid flow TCP Timing TV Servers Optimization Algorithms Bandwidth Video QoE Congestion Control eBPF | Optimizing congestion control algorithms (CCAs) has the potential to enhance video quality of experience (QoE). The goal of this work is to devise a congestion control framework that (i) ensures that individual users enjoy high video QoE, while (ii) minimizing variance, such that QoE is fairly distributed across all users, especially in fluctuating network, such as cellular network. We present Themis, a video-centric congestion control framework. Themis first uses a distributed approach to allocate a fair target QoE for each client. Based on this fair QoE, Themis then selects congestion control actions to optimize for video QoE (rather than throughput) based on application-layer signals provided by the client. Thus, rather than trying to maximize a flow’s (fair) share of bandwidth, Themis optimizes a flow’s share of the QoE budget. We evaluate Themis in both emulated and production networks. We show that in cellular network Themis achieves a 12.4% QoE improvement compared with BBR, and 37.1% QoE standard deviation decrease compared with the state-of-the-art, Minerva. | 10.1109/TNSM.2026.3732350 |
| Muhammad Muhammad Bala, Abdullahi Uwaisu Muhammad, Kamaluddeen Ibrahim Yarima, Aseel Smerat, Mulikatu Yakubu Ibrahim, Safiyanu Yahaya, Hamza Adamu | Isolation and Optimization Cost of Service-based Radio Access Network Slicing: A Smart-Contract-Based Approach | 2026 | Early Access | Network slicing Smart contracts Radio access networks Regional area networks Modeling Resource management Costing Costs Timing Joining processes Blockchain Network Slicing Service-based RAN Service-based Architecture | The service-based Radio Access Network (RAN) slicing enabled via Software Defined Networking (SDN) and Network Function Virtualization (NFV) can support diverse service requirements and address the rapid data traffic growth from both the vertical industry and the Internet of Things (IoT). However, network slice isolation and resource sharing between slices should be be improved for future wireless network requirements. Firstly, this paper address the isolation enhancement of future wireless networks through Blockchain-Smart-Contract, by creating two smart-contract-based access control to secure access to different service-based RAN applications and secure the sharing of resources. These contract are Verification and Authorization Contract (VAC), as well as Misconduct and Revocation Contract (MRC). The proposed framework is designed to support key 6G service classes, such as enhanced Mobile Broadband (eMBB) and ultra-Reliable Low-Latency Communications (uRLLC), enabling high data rates and low-latency communication. Secondly, to ensure the servicebased RAN achieves better isolation the optimization goal is to minimize the deployment cost to obtain the best deployment scheme. Hence, we divide the service-based RAN slice isolation deployment problem into two sub-problems, i.e., service-based RAN slice isolation and slice deployment problem, by formulating a Mixed Integer Linear Programming (MILP) model to minimize the deployment cost. Finally, to verify the feasibility of the design implementation an experimental platform is built and the results show the architecture achieves isolation enhancement through smart-contract and reduces the deployment cost by 78% and improve the isolation performance by 93% compared to the Blockchain-enabled Network Slice (BcNS) and the service-based RAN. | 10.1109/TNSM.2026.3732250 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Yao Xin, Yuqiao Luo, Shufan Cao, Chongwu Dong, Qingfeng Tan | HBT: A Hybrid Bidding Tree for High-Performance Packet Classification | 2026 | Early Access | Heterojunction bipolar transistors Trees (botanical) Vegetation Memory Pediatrics Construction Information rates Throughput Indexes Indexing Decision tree packet classification performance rule partitioning | Traditional packet classification algorithms based on decision trees often rely on rule replication to increase lookup speed, which inevitably leads to memory explosion. Conversely, existing zero-replication methods frequently suffer from extreme tree depth and structural fragmentation. To address this dilemma, this paper proposes the Hybrid Bidding Tree (HBT), a high-performance architecture designed to enforce zero-replication while sustaining deterministic lookup throughput. First, HBT employs an Overlap-Aware Rule Decomposition (OARD) framework to proactively isolate topologically entangled rules, purifying the primary geometric space. Second, HBT introduces a dynamic competitive bidding mechanism for tree construction. At each node, a discrete bit-selection path and a continuous range-partitioning path compete to determine the optimal splitting strategy based on local geometric heterogeneity. Finally, to guarantee an O(N) memory boundary, unpartitionable residual rules are assigned to a single-level Onion-Peeling fallback structure, preserving linear memory growth while introducing additional sequential checks in the auxiliary path. Experimental evaluations on ClassBench-ng rulesets containing up to 256k rules demonstrate the efficacy of HBT. Compared with state-of-the-art algorithms such as PT-Tree and TupleTree, HBT achieves the highest lookup throughput across all twelve evaluated rulesets at both the 128k and 256k scales, while maintaining strong memory efficiency and highly competitive construction and update latencies. | 10.1109/TNSM.2026.3734240 |
| Mubashir Murshed, Glaucio H. S. Carvalho, Robson E. De Grande | Holistic Intelligent Traffic Steering Management in Multi-RAT Vehicular Networks | 2026 | Early Access | Radio access technologies Rats Vehicles Modeling Long short term memory Poles and towers 5G mobile communication Joining processes Timing Received signal strength indicator Traffic Steering Multi-RAT Network Management Bi-level GCN-LSTM SARSA High-mobility Ultra-dense networks | Multiple Radio Access Technology (multi-RAT) environments provide a promising foundation for service-aware communication in intelligent transportation systems (ITS) and smart cities. However, traffic steering (TS) in highly mobile and ultra-dense vehicular networks remains challenging due to dynamic network conditions, heterogeneous RAT capabilities, varying vehicle requirements, packet loss, latency, and frequent ping-pong RAT switching. In this context, we propose Holistic Intelligent Traffic Steering (HITS), a proactive bi-level TS management framework for multi-RAT vehicular networks. HITS integrates centralized network-wide guidance with local vehicleside decision-making. At the central level, a Graph Convolutional Network–Long Short-Term Memory (GCN–LSTM) model captures holistic spatio-temporal network dynamics and evaluates RAT optimality. At the local level, a State-Action-Reward- State-Action (SARSA) reinforcement learning agent performs adaptive, vehicle-specific RAT selection using local observations and central-level optimality guidance. Results show that HITS achieves up to 6.5% higher average throughput, reduces packet loss ratio by more than 30.2%, lowers latency by nearly 12.2%, and reduces the ping-pong RAT switching rate by over 24% compared with baseline and state-of-the-art (SoTA) TS approaches. | 10.1109/TNSM.2026.3729840 |