Last updated: 2026-07-21 05:01 UTC
All documents
Number of pages: 169
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Zening Li, Pin-Han Ho | Topology-Constrained Generative Modeling for Performance Monitoring and Structural Anomaly Definition in Optical Transport Networks | 2026 | Early Access | Windows Modeling Semantics Aggregates Topology Propagation Observability Relays Signal detection Monitoring Optical transport networks performance monitoring partial observability anomaly detectability topology-constrained generative models window-aggregated statistics | Electrical-layer performance monitoring (PM) in optical transport networks is reported as window-aggregated counters, under which propagation delay and signal regeneration boundaries are not directly observable. Consequently, different impairment mechanisms can lead to statistically similar PM trajectories, leaving PM-only methods without a principled notion of nominal behavior or anomaly detectability. To address this limitation, this paper proposes Topology-Constrained Partially Observed Dynamical System (TC-PODS). TC-PODS defines a topology-consistent nominal predictive reference directly in PM space by introducing a latent impairment state (LAT) that enforces service-path propagation and regeneration semantics as supervisory constraints, while explicitly modeling the irreversible projection induced by windowed PM observation. This formulation disambiguates nominal variability from anomalous behavior under partial observability and defines anomalies as PM trajectories that are incompatible with any topology-consistent nominal generation. By shifting PM analysis from algorithm-centric detection toward detectability-aware inference under the deployed observation protocol, TC-PODS provides a principled framework for forecasting and anomaly interpretation under partial observability, with future applications to structure-aware failure management. | 10.1109/TNSM.2026.3715222 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Masoumeh Safkhani, Mohammad Reza Servati, Fatemeh Rezaei | HEIoT: A Novel Three-Factor Authentication Protocol for Enhanced Security in IoT and Next-Generation Networks | 2026 | Early Access | Authentication Internet of Things Protocols Security Smart devices Elliptic curve cryptography Modeling Error correction codes Biometrics Costing of Yuan et al.’s Protocol Authentication Multi-factor authentication Desynchronization attack Insider adversary Traceability attack User impersonation attack Elliptic Curve Cryptography (ECC) | The Internet has a significant impact on contemporary society, enabling a wide range of applications, including advanced cellular networks such as 4G, 5G, and 6G. Since these communications occur over shared or open channels, ensuring secure data exchange is of critical importance, as any weakness in the communication infrastructure may compromise system reliability. Device authentication in the Internet of Things (IoT) and user authentication in smart environments, such as smart homes, remain fundamental security challenges. As the first line of defense, authentication mechanisms must be robust, since vulnerabilities at this stage can expose the entire system to serious threats. To address these challenges, numerous authentication schemes based on cryptographic primitives, including Elliptic Curve Cryptography (ECC), have been proposed. In this paper, we present a comprehensive security analysis of an ECC-based three-factor authentication protocol proposed by Yuan et al. Our analysis shows that the protocol is vulnerable to desynchronization, user impersonation, traceability, and insider attacks, all of which succeed with probability 1 by exploiting at most two protocol phases. To mitigate these weaknesses, we propose an improved authentication scheme, called HEIoT. The proposed scheme is formally analyzed under the Real-or-Random (RoR) model to establish session-key security and is further verified using the Scyther tool. Moreover, a Python-based implementation is provided to demonstrate the practicality of the proposed protocol. Comparative results indicate that HEIoT achieves stronger security while maintaining acceptable communication, computational, and storage overhead. | 10.1109/TNSM.2026.3702041 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Shi-Xin Huang, Te-Chuan Chiu, Jing-Chih Lin, Cheng-Hsuan Kuo | EdgeCookie: A Mitigation Solution Against Threatening TCP DDoS Attack in Edge Cloud | 2026 | Early Access | Servers Switches TCP Floods Filtering Filters Architecture Computer architecture Security Kernel SYN Flood DRDoS Edge Computing Security | With the explosive growth of GenAI service requirements, the demand for digital infrastructure and cloud resources continues to increase. At the same time, distributed denial-of-service (DDoS) attacks – particularly TCP-based vectors such as SYN flood and emerging TCP distributed reflective denial-of-service (DRDoS) – have surged, posing a significant threat to service availability. Current mitigation strategies often fall short in effectively countering both attack types. Although the proliferation of edge computing offers opportunities to deploy mitigation closer to attack sources, it also introduces synchronization challenges across distributed edge servers. In this paper, we propose EdgeCookie, an edge-centric TCP flood attack mitigation architecture. EdgeCookie can mitigate TCP SYN floods, ACK floods, and emerging TCP reflection amplification attacks. Unlike existing switch-based defenses, EdgeCookie requires no specific hardware, making it suitable for running in resource-limited edge clouds. In the core mechanism, we introduce a novel HybridCookie that effectively solves synchronization challenges across distributed edge servers. Experimental results demonstrate that EdgeCookie can mitigate both TCP SYN flood and emerging TCP reflection amplification attacks without facing false positive issues, while maintaining high throughput and adding negligible latency to legitimate traffic. | 10.1109/TNSM.2026.3706627 |
| Madhura Adeppady, Yenchia Yu, Ali Rahmanian, Ahmed Ali-Eldin Hassan, Carla Fabiana Chiasserini | Efficient Management of Composite Heterogeneous Applications at the Network Edge | 2026 | Early Access | Central Processing Unit Servers Resource management Costing Costs Modeling Joining processes Timing Memory Measurement Mobile edge computing Stateless and stateful microservices Application deployment and migration Service management | Edge computing is a promising paradigm for deploying latency-sensitive applications (Apps) as it brings resources closer to end users. Edge Apps often adopt a microservice (MS) architecture, breaking monolithic Apps into lightweight, containerized MSs that can be dynamically and independently deployed. However, managing such Apps involves three key challenges: (i) optimizing the placement of MSs to reduce both response time and resource overhead, (ii) handling MS migration or relocation as users move while minimizing App service disruption (App downtime), and (iii) enabling MS sharing across Apps while ensuring performance guarantees. We formulate this as an optimization problem, named Multi-microservice Application Placement (MAP), prove its NP-hardness, and introduce STEP (State and Topology-aware Edge-MS Placement), a polynomial-time heuristic. STEP distinguishes itself from prior work by: (i) jointly considering stateful and stateless MS characteristics in deployment decisions, (ii) exploiting MS shareability to reduce resource usage, (iii) balancing response latency, App downtime, and resource utilization, and (iv) leveraging multiple versions of the same MS to adapt quality of service to available edge resources. Our results in a small-scale scenario show that STEP achieves near-optimal performance with only 7% higher CPU cost than the optimal solution. Large-scale real-time experiments on a Kubernetes cluster demonstrate that STEP consistently outperforms competing methods, achieving up to 50% lower deployment costs while delivering 50% gain in app quality and saving 15% in radio resources with over 90% request success rates. | 10.1109/TNSM.2026.3709656 |
| Yongqiang Dong, Jiangnan Sun, Jiawen Li, Yongbo Liu | Learning to Configure Like Engineers: Manual Guided Network Configuration Sketch Generation | 2026 | Early Access | Modeling Syntactics Large language models Manuals Retrieval augmented generation Optimization Generators Grounding Design methodology Joining processes Network Configuration Automation Intent-Based Networking Large Language Models Retrieval-Augmented Generation | Network configuration automation is a key component of intelligent network operations aiming to transform user intents into executable device configurations. Most existing approaches take a paradigm of parameter filling within predefined sketches, where the sketches have to be crafted manually by engineers and user intents are expressed in a specific format. Other studies follow a routine of synthesizing configurations directly from natural-language intents, taking advantage of large language models (LLMs) and retrieval augmented generation techniques. The results are yet far from satisfactory in practice due to the complexity of the network configuration requirements. A recently proposed example-driven configuration synthesis method (CEGS), attempts to learn from configuration examples provided by vendors. However, its effectiveness is bounded by example coverage, and the method struggles to generalize to new scenarios. To address this, we present LCLE, an end-to-end sketch generation framework that learns how to configure networks from device configuration guides and command references, much as human engineers do. Specifically, LCLE automatically generates configuration sketches from natural-language intents by LLMs with a structured device configuration model (DCM) extracted from vendor manuals. The DCM organizes configuration workflows, command syntax, and view hierarchies into a unified knowledge base that supports LCLE’s retrieval-augmented generation through a three-stage pipeline of intent parsing, sketch generation, and sketch optimization. Extensive experiments on Huawei and Cisco devices show that LCLE significantly improves the semantic completeness and syntactic correctness of the generated configuration sketches. In addition, the framework can be easily extended to new devices and protocols through DCM updates, promising a scalable solution for automated network configuration. | 10.1109/TNSM.2026.3710600 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Rania Farjallah, Bassant Selim, Brigitte Jaumard, Samr Ali, Georges Kaddoum, Jean-Michel Sellier | Maximum Entropy-Based Traffic Generation | 2026 | Early Access | Modeling Optimization Entropy Urban areas Machine learning Training Limiting Generative adversarial networks Timing Tuning Time Series dataset Maximum entropy principle Traffic Modeling Synthetic Traffic Generation | The development of machine learning models and algorithms for many communication network optimization problems has generated a huge need for realistic traffic data generators, as real-world traffic datasets remain very few, especially compared to their size. We therefore propose a novel traffic generation framework based on the Maximum Entropy Principle (MEP). It explicitly incorporates empirical statistical constraints, ensuring generated traffic closely mirrors the complex patterns found in real-world data. Using vehicle traffic datasets of the City of Calgary, we explore multiple distributional assumptions, namely Gaussian, exponential, and mixture models. Our results demonstrate that the Gaussian and the Gaussian mixture models consistently achieve superior performance, capturing diverse temporal fluctuations and intricate statistical behaviors inherent in urban vehicle traffic. This study not only highlights the effectiveness and flexibility of MEP-based models but also establishes them as robust, interpretable, and data-efficient alternatives to existing generative methods in traffic synthesis. | 10.1109/TNSM.2026.3712637 |
| Dev Gurung, Shiva Raj Pokhrel | LLM-QFL: Distilling Large Language Model for Quantum Federated Learning | 2026 | Early Access | Modeling Federated learning Large language models Training Tuning Optimization Convergence Servers LoRa Machine learning Quantum Federated Learning Distillation Large Language Models | As Quantum Federated Learning (QFL) scales toward distributed quantum networks, managing heterogeneous resources and communication bottlenecks becomes a critical challenge. This research proposes LLM-QFL, an adaptive network service management framework that leverages Large Language Models (LLMs) to optimize the operational efficiency of QFL systems. We introduce a federated distillation method in which locally fine-tuned LLMs serve as autonomous network agents. These agents adaptively manage service parameters by: i) dynamically adjusting local computation intensity (optimizer steps) based on loss gradients, ii) performing variance-aware client selection to minimize network-wide heterogeneity, and iii) implementing intelligent early stopping criteria to conserve bandwidth. By serving as an orchestration layer, LLM-QFL provides a synergy between LLMs and quantum networking. Our contributions include: i) Adaptive Performance and Efficiency: Reducing idle computation and significantly cutting communication overhead; ii) Theoretical Rigor: Convergence guarantees of O(1/T) for the adaptive management protocol; and iii) Scalable Deployment: Implementing PEFT (LoRA/QLoRA) for resource-constrained quantum service nodes. | 10.1109/TNSM.2026.3712394 |
| Jing-Yang Voon, Yao Chiang, Hung-Yu Wei | Resource Allocation and Container Scaling for Microservices in Multi-Cluster Edge Computing System | 2026 | Early Access | Resource management Optimization Delays Containers Modeling Edge computing Algorithms Central Processing Unit Routing Internet of Things Edge Computing Microservice Computational Offloading Resource Allocation Container Scaling | With the advent of the 6G era and the evolution of distributed systems, edge computing has become a pivotal architecture for deploying latency-sensitive, resource-efficient applications. In particular, the microservice architecture, characterized by modular and loosely coupled components, has gained significant traction for building scalable and maintainable applications at the network edge. However, deploying microservice-based applications in heterogeneous and geographically distributed Multi-Cluster Edge Computing (MCEC) environments presents critical challenges, especially in achieving efficient and scalable resource management. Although existing research has explored resource allocation and container scaling for microservice-based systems, most prior works consider container efficiency in isolation or within single-cluster or cloud-centric environments, without jointly addressing container-level efficiency, inter-cluster task offloading, and resource allocation in MCEC scenarios. To address this gap, we propose RACCOON, a request-offloading cascaded resource allocation algorithm tailored for microservice-oriented deployments in MCEC settings. RACCOON aims to minimize user-perceived service latency while optimizing overall resource utilization. Complementing this, we introduce RAS-CAL, a reinforcement learning (RL)-based container scaling mechanism that dynamically adjusts resource provisioning at the container level to further enhance system performance. Experimental evaluation shows that our approach consistently outperforms methods that address only resource allocation, only task offloading, or only container scaling, by jointly optimizing these dimensions to reduce end-to-end user-perceived latency and computational overhead. | 10.1109/TNSM.2026.3713212 |
| Lu Wei, Yong Yu, Jie Cui, Xianfeng Xie, Jing Zhang, Irina Bolodurina, Hong Zhong | Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing | 2026 | Early Access | Vehicles Delays Stability Optimization Modeling Resource management Clouds Edge computing Equations Timing vehicular edge computing deep reinforcement learning Lyapunov optimization task offloading | With the rapid growth of Vehicular Edge Computing (VEC) and Mobile Edge Computing, efficient task offloading is essential for enhancing the computing and communication capabilities in vehicular networks. However, many existing methods suffer from slow convergence, load imbalance, and instability in dynamic, latency-sensitive environments. To address these challenges, we propose MAPPO-Lyapunov (MAPPO-L), a multi-agent offloading framework that integrates Multi-Agent Proximal Policy Optimization (MAPPO) with Lyapunov optimization. MAPPO-L enables distributed coordination among vehicles, roadside units (RSUs), and cloud servers, minimizing delay, improving resource utilization, and ensuring long-term stability. Lyapunov theory transforms long-term stability into per-slot optimizations, while MAPPO ensures efficient policy learning. An adaptive exploration mechanism dynamically adjusts exploration rates based on network dynamics, accelerating convergence and stabilizing training. Extensive simulations with real-world data show that MAPPO-L maintains task completion rates above 80%, converges 25%–37.5% faster than baselines, and reduces training fluctuations to 2.3%. Ablation studies confirm the critical roles of location, channel, and queue information, validating the robustness of MAPPO-L in practical VEC environments. | 10.1109/TNSM.2026.3713305 |
| Weilin Wang, Xiaojing Fan, Huachun Zhou, Jingfu Yan, Aoran Huang | A Collaborative Mechanism for Edge-Offloading and Intelligent Intrusion Detection Services | 2026 | Early Access | Algorithms Security Training Timing Modeling Signal detection Resource management Servers Delays Learning (artificial intelligence) Mobile edge computing service collaboration intrusion detection deep reinforcement learning | Mobile edge computing (MEC) is a promising technology for supporting computing-intensive and delay-sensitive applications. The network operator can enhance users’ personalized service experiences by implementing advanced offloading solutions. However, existing schemes often overlook security risks posed by malicious users, and struggle to balance quality of service (QoS) and security capabilities. To this end, we propose a collaborative mechanism for edge offloading and intelligent intrusion detection services to optimize personalized service experiences for normal users at the task level. First, we introduce a new optimization model, Collaboration of Edge Offloading and Intelligent Intrusion Detection Services (CEOI2DS), tailored for MEC environments with malicious users, considering security decisions, resource allocation, and function placement decision-making steps. It aims to maximize the operator’s average long-term revenue while meeting QoS requirements and resource constraints, encouraging the operator to deliver optimal security capabilities while ensuring personalized QoS for users. Then, to tackle this problem, we design a Collaborative Three-Agent Deep Reinforcement Learning (CTADRL) algorithm. Three agents conduct collaborative training and decision-making by interacting with the MEC environment. They comprehensively analyze user requirements, risk probabilities, and network resource status to formulate optimal service policies, enhancing the overall experience for normal users. Experimental results demonstrate that under different user risk probabilities and computing resources, the proposed mechanism and algorithm exhibit better adaptability and stability regarding processing success rate and revenue. | 10.1109/TNSM.2026.3713143 |
| Ci-Yi Hung, Li-Yu Yang, Li-Der Chou | LMM: A Reinforcement-Learning-Based Mitigation Mechanism of Lateral Movement in Kubernetes | 2026 | Early Access | Modeling Advanced driver assistance systems Containers Timing Probability Learning (artificial intelligence) Security Sequences Sequential analysis Training Lateral Movement Kubernetes Security Reinforcement Learning Markov Chain Event Tracking Dynamic Defense | With the growing adoption of microservices architecture, Kubernetes—while offering a variety of built-in security modules—remains vulnerable to lateral movement due to its highly interconnected network architecture and frequent misconfigurations in permission settings. This study proposes the Lateral Movement Mitigation (LMM) mechanism, which integrates event tracking, risk assessment, and reinforcement learning (RL) to enhance Kubernetes' defense against lateral movement. LMM leverages Falco with custom rules to capture container-level events and utilizes a high-order Markov chain to construct a transition probability matrix for estimating the likelihood of command sequences. These transition probabilities are then used for risk assessment and provided as input states to the RL agent. The RL agent selects mitigation actions based on recommendations from the MITRE ATT&CK framework, thereby dynamically strengthening Kubernetes' native security modules. Experiments show that LMM improves accuracy by 17.00% over Warp and F1-score by 23.30% over ADA in Kubernetes namespace bypass. In the Role-Based Access Control (RBAC) misconfiguration, LMM outperforms Warp by 18.53% in accuracy and 28.27% in F1-score. In terms of mitigation latency, LMM achieves up to 98.54% and 98.38% faster response times compared to Warp and ADA, respectively, demonstrating its effectiveness and real-time responsiveness. In summary, LMM combines monitoring, risk modeling, and automated decision-making to deliver an efficient and accurate proactive solution against lateral movement in Kubernetes. | 10.1109/TNSM.2026.3713179 |
| Tong Li, Shicheng Wei, Wencheng Yang, Yan Li | HotPatchCaps: A Capsule Network with Runtime Hot Patching for Zero-Day API Attack Detections | 2026 | Early Access | Modeling Application programming interfaces Security Signal detection Runtime Training Poles and zeros Labeling Conferences Routing API security Runtime defence Zero-day attack detection Capsule networks Hot patching | Modern services are awash in Application Programming Interfaces (APIs), yet most security pipelines end at predeployment testing using fuzzers and scanners. This leaves a runtime gap where payload obfuscation and other evolving request-visible misuse patterns outpace static rules and slow retraining cycles. We present HotPatchCaps, an expert-in-the-loop runtime framework that closes this gap by hot patching expert knowledge into a capsule architecture without retraining. HotPatchCaps fuses Term Frequency–Inverse Document Frequency (TF–IDF) statistics on request tokens with security cues such as parameter names, encodings, and payload substrings, and employs slot-controlled routing to amplify semantically relevant evidence into interpretable capsule activations. New rules arrive as lightweight runtime patches that can be injected on the fly, aligning with operational practice while preserving the generalization of learned models. We evaluated the CSIC 2010 dataset and the ATRDF 2023 dataset in both in-distribution and zero-day settings against classical machine learning (ML) and deep baselines. Experimental results demonstrate that HotPatchCaps consistently improves accuracy and recall at competitive precision and remains robust under label noise and schema drift. By turning expert knowledge into patchable capsule priors, HotPatchCaps provides a practical path from testing to on-call defence for API-centric systems. | 10.1109/TNSM.2026.3713465 |
| Antonio Iacobelli, Giorgio Franceschelli, Lorenzo Rinieri, Mirco Musolesi, Marco Prandini, Franco Callegati | SIP-Classifier: Unsupervised Classification of SIP-IMS Signaling with Transformer and Clustering | 2026 | Early Access | Ensuring the reliability of voice services in 5G networks requires effective detection of anomalies in IMS signaling. However, this task remains challenging due to the architectural complexity of IMS and the large volume of signaling data. In this paper, we propose SIP-Classifier, an unsupervised methodology that combines Transformer-based representation learning with clustering to identify anomalous SIP sequences. The approach encodes SIP messages through protocol-aware tokenization, learns latent representations via an autoregressive Transformer, and clusters them to distinguish valid from anomalous flows. We evaluate the method on real-world IMS data collected from operational 5G networks. It achieves 98% accuracy, 98% precision, 95% recall, and a 96% F1-score, significantly outperforming state-of-the-art approaches. | 10.1109/TNSM.2026.3715301 | |
| Abdullah Othman, Georges Kaddoum, João V. C. Evangelista, Minh Au, Basile L. Agba | Joint Digital Twin Synchronization Scheduling and Resource Allocation for Post-Disaster Wireless Networks | 2026 | Early Access | Modeling Synchronization Cells (biology) Optimization Disasters Timing Interference Resource management Scheduling Schedules Digital twin post-disaster communications synchronization scheduling resource allocation successive convex approximation localization uncertainty | Digital twins (DTs) of wireless networks rely on accurate channel information to support resource allocation decisions. In post-disaster scenarios, the physical environment changes abruptly, rendering the DT’s pre-disaster channel model obsolete. Since restoring DT accuracy requires synchronization with the physical network through costly environmental updates, a fundamental tradeoff emerges between synchronization cost and decision quality. This paper formulates the joint optimization of DT synchronization scheduling, user–base station association, and uplink power control as a mixed-integer nonlinear program that maximizes the minimum user rate subject to synchronization budget and resource constraints. We decompose the problem into three subproblems solved via successive convex approximation and prove convergence of the alternating procedure to a stationary point. For the synchronization subproblem, we propose both a model-unaware formulation based on a coverage linear program requiring only user trajectory information, and a modelaware formulation that additionally exploits post-disaster channel knowledge to optimize the sync schedule for rate maximization. To characterize the impact of positioning uncertainty on the cell-based spatial model, we derive a closed-form expression for the cell-misclassification probability and develop a semi-analytical utility model that predicts the optimal grid resolution as a function of localization accuracy. The results of our simulations based on ray-traced channel data confirm that the proposed model-unaware sync closes 64–81% of the gap to the full-knowledge oracle across a range of system parameters, while the model-aware variant achieves 79–91% when post-disaster channels are available. The model-unaware approach thus exhibits the lowest sensitivity to DT model errors among all tested methods, making it the preferred choice when channel estimates are imperfect. | 10.1109/TNSM.2026.3714917 |
| Xiaolan Ji, Biao Han, Yuedong Xu, Jinshu Su | ICCP: Towards Congestion Control Agent via Controlling Logic Decoupling and Algorithm Integration | 2026 | Early Access | Algorithms Fluid flow Modeling Libraries Protocols Design methodology Information rates Throughput Stacking Kernel Congestion control Reinforcement learning Control plane Batch inference | To address the limitations of single congestion control algorithms (CCAs) in dynamic and heterogeneous network environments, selecting an appropriate algorithm from a pool of existing ones has become a widely adopted strategy. Existing mechanisms, however, are typically constrained by the Linux kernel’s unified abstractions, which limit the flexibility of selecting from a small set of in-kernel CCAs. Learning-based CCAs further increase the deployment cost because their inference logic is often compute-intensive and can block concurrent flows when executed within a synchronous control path. In this paper, we present ICCP, a unified congestion control framework that supports both heuristic and compute-intensive algorithms for concurrent flows. Rather than introducing a new reinforcement learning method, ICCP provides a three-layer, decoupled runtime framework consisting of the protocol stack, the user-space algorithm library, and the congestion control agent. ICCP uses asynchronous request handling, a shared proxy, and a “zero-copy” serialization-based RPC path to support both batch and single-inference modes with controlled communication overhead. We implement three distinct reinforcement learning-based congestion control algorithms within ICCP, including Sage, Orca, and DTCC, to evaluate the framework using representative compute-intensive CCAs. Simulations and real-world experiments demonstrate that ICCP maintains robust and efficient communication and inference performance as the number of concurrent flows increases. Overall, ICCP provides a practical runtime framework for integrating, evaluating, and deploying heterogeneous congestion control algorithms in multi-flow environments. | 10.1109/TNSM.2026.3714992 |
| Sanku Kumar Roy, Mohamed Samshad, Ketan Rajawat | UNet: A Generic and Reliable Multi-UAV Communication and Networking System Architecture for Heterogeneous Applications | 2026 | Early Access | Autonomous aerial vehicles Architecture Computer architecture Modules (abstract algebra) Protocols Joining processes Delays Distance measurement Timing Design methodology FANET Unmanned Aerial Vehicle UAV Communication Architecture Generic Heterogeneous Applications ad hoc Mesh Networking | The rapid growth of UAV applications necessitates a robust communication and networking system architecture capable of addressing the diverse requirements of various applications concurrently, rather than relying on applicationspecific solutions. This paper proposes a generic and reliable multi-UAV communication and networking system architecture designed to support the varying demands of heterogeneous applications, including short-range and long-range communication, star and mesh topologies, different data rates, and multiple wireless standards. Our architecture is designed for both ad hoc and infrastructure networks, ensuring seamless connectivity throughout the network. Additionally, we present the design of a multi-protocol UAV gateway that enables interoperability among various communication protocols to enhance connectivity. Furthermore, we introduce a data processing and service layer framework with a graphical user interface of a ground control station that facilitates remote control and monitoring from any location at any time. We practically implemented the proposed architecture and evaluated its performance using different metrics, demonstrating its effectiveness. | 10.1109/TNSM.2026.3715386 |