Last updated: 2026-10-07 05:01 UTC
All documents
Number of pages: 175
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Yingjie Hu, Weiping Wang, Shigeng Zhang, Hong Song, Ziheng Huang, Song Guo | Dual-State Representation Learning for Multi-Granularity IoT Device Identification | 2026 | Early Access | Internet of Things Modeling Training Labeling Sequences Sequential analysis Testing Accuracy Contrastive learning Multitasking IoT security device identification self-supervised learning contrastive learning multi-granularity | The rapid growth of IoT devices has increased demand for traffic-based network asset management and security monitoring. Most existing methods operate in closed-set settings and may misclassify unseen devices as known models or return only an unknown label. To address this problem, this paper proposes a multi-granularity IoT device identification method based on dual-state representation learning. Device identity is modeled at three levels: type, manufacturer, and model, retaining type and manufacturer information when the device model cannot be reliably identified. The method extracts statistical, sequence, and raw-byte features and learns sequence and byte embeddings from idle and behavior traffic. Self-supervised learning and contrastive learning are used to improve the discriminative ability of representations. A state-aware gating mechanism then dynamically fuses the dual-state embeddings. Multi-task classification heads and confidence thresholds are used to support joint identification and rejection. Experiments on three public datasets show over 98% accuracy for known-device identification. The method also achieves over 97% accuracy for type and manufacturer prediction on the unknown-model test set and over 95% rejection rate for unknown models. Online deployment achieves an average latency of 3.1 ms and a throughput of 322 samples/s, demonstrating practical potential in open network environments. | 10.1109/TNSM.2026.3738728 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Haotian Lu, Yuning Dong, Guanming Lu, Pingping Tang, Jiong Jin | Federated Unknown Traffic Detection with Enhanced Contrastive Pre-training and Prototyping | 2026 | Early Access | Modeling Training Federated learning Fluid flow Prototypes Labeling Servers Signal detection Timing Indexes open-set traffic classification federated learning network traffic classification contrastive learning | With the increasing demand for privacy and distributed data compliance, federated learning (FL) has become a promising paradigm for collaborative network traffic classification (NTC) without sharing raw traffic data. However, real-world network environments are inherently open, where the emergence of new applications and unknown attacks introduces open-set challenges. To ensure service quality and network security, models need not only to classify known traffic classes accurately but also to identify unknown ones. Despite recent efforts to extend FL to Open-Set NTC (OSNTC), most current FL methods are still confined to the closed-set assumption, leaving the challenge of Federated OSNTC (FedOSNTC) largely unresolved. Therefore, this paper proposes FedUTD, a novel Federated Unknown Traffic Detection framework that introduces: (1) multi-scale prefix truncation, a customized contrastive learning strategy that leverages multi-granularity traffic characteristics to enhance feature discriminability; (2) an improved federated communication mechanism that enriches the transmitted information through pseudo-sample generation to mitigate data heterogeneity while retaining substantially lower communication cost; (3) a lightweight dual-layer OSNTC approach designed to reduce local training and inference overhead during local unknown-traffic detection. Extensive experiments on four real-world network traffic datasets demonstrate that FedUTD consistently outperforms existing methods, achieving an F1 gain of 5–21%. | 10.1109/TNSM.2026.3739767 |
| Dhiraj Pandey, Pranav Singla, Siddharth Pal, Prasenjit Chanak, Manish Pratap Singh, Om Jee Pandey | HFSL-CUNs: A Hierarchical Federated Split Learning Framework for Cluster-Based and UAV-Assisted Edge-Fog-Cloud Networks | 2026 | Early Access | Autonomous aerial vehicles Modeling Internet of Things Filtering Filters Federated learning Privacy Clouds Optimization Training UAV-assisted edge-fog-cloud networks hierarchical split learning adaptive activation clustering spatio-temporal filtering differential privacy mobile IoT | The increasing deployment of Internet of Things (IoT) applications has created a growing need for distributed learning frameworks that can operate efficiently across resource-constrained edge environments while preserving data privacy. Federated Learning (FL) enables collaborative model training without sharing raw data. However, its communication overhead, computational burden, and limited scalability make it less suitable for large-scale hierarchical edge networks. In this paper, we propose Hierarchical Federated Split Learning (HFSL), a unified Unmanned Aerial Vehicle (UAV)-assisted edge-fog-cloud framework that combines the complementary strengths of FL and Split Learning (SL) to improve communication efficiency, scalability, and privacy. HFSL introduces activation similarity-based clustering and spatio-temporal activation filtering to reduce redundant communication, adaptive UAV altitude optimization to improve wireless connectivity under dynamic network conditions, and a privacy-preserving training strategy based on Differential Privacy (DP) and activation-level leakage mitigation. Extensive experiments across eight image and tabular benchmark datasets demonstrate that HFSL outperforms state-of-the-art FL and SL methods on the more challenging heterogeneous benchmarks, reducing energy consumption by up to 50%, training latency by 40%, and communication overhead by 35%, while improving classification accuracy by up to 6%. These results show that HFSL provides an effective and scalable distributed learning framework for next-generation UAV-assisted edge networks. | 10.1109/TNSM.2026.3738968 |
| Mohamed Zalat, Chris Barber, Babak Esfandiari, Thomas Kunz | A Reusable Network Digital Twin Architecture for QoS-Centric Network Management | 2026 | Early Access | Modeling Fluid flow Optimization Joining processes Delays Management Topology Border Gateway Protocol Measurement Quality of service Network Digital Twins Digital Twins IGP BGP Fault Localization Networks | We propose a network digital twin approach for Quality of Service (QoS)-centric network management and demonstrate it on multiple network management problems. Our network digital twin involves running many ”what-if?” network configurations using a fast inference model for predicting network behavior, and applying the best configuration found based on the criteria of the network operator. We demonstrate the flexibility of this approach by applying it to 3 different network management problems: Interior Gateway Protocol (IGP) weight optimization, Border Gateway Protocol (BGP) route assignments, and gray fault detection and localization. We test our approach for each application on various OMNeT++ topologies and compare it to existing benchmarks in the respective literature. Our results indicate that the proposed network digital twin approach performs comparably to existing benchmarks in the network management problems explored and sometimes outperforms them in quality of service metrics. | 10.1109/TNSM.2026.3737654 |
| Messaoud Ait-Yahia, Wael Jaafar, Rami Langar | Joint Design of Blockchain-Enabled Service Placement and Task Assignment in Vehicular Fog Computing Networks | 2026 | Early Access | Delays Timing Optimization Autonomous aerial vehicles Modeling Gallium Central Processing Unit Joints Bandwidth Elementary particles Resource allocation Blockchain VNF placement task assignment vehicular fog computing PSO GA IoV | Driven by the evolution of blockchain and fog computing, vehicular networks are increasingly capable of supporting latency-sensitive applications with enhanced security and trust guarantees. However, the joint resource allocation for task offloading and blockchain services has been insufficiently investigated in existing works. To address this gap, this paper proposes a framework for jointly allocating resources of blockchain, users’ virtualized services, and Mobile Edge Computing (MEC) task assignment in Vehicular Fog Computing (VFC) networks. Specifically, we formulate the optimization problem as an integer nonlinear programming model aiming to maximize the satisfaction rate of users’ service requests while minimizing the corresponding blockchain operation time under mobility, queuing, instantiation, and resource constraints. To solve it in a timely manner, we design two-stage hierarchical low-complexity solutions, namely a Particle Swarm Optimization-based Joint Blockchain-enabled Service placement and Task Assignment algorithm (PSO-JBSTA), and a Genetic Algorithm-based approach (GA-JBSTA). Through extensive simulations, we demonstrate the effectiveness of PSO-JBSTA (resp. GA-JBSTA) and their adaptability to network conditions, achieving an average 35% (resp. 24%) improvement in users’ service satisfaction rate and 9.5% (resp. 10.2%) reduction in average blockchain validation delay compared with the baselines. | 10.1109/TNSM.2026.3737068 |
| Stephen Jasina, Loqman Salamatian, Joshua Mathews, Scott Anderson, Paul Barford, Mark Crovella, Walter Willinger | Matisse: Visualizing Measured Internet Latencies as Manifolds | 2026 | Early Access | Manifolds Internet Measurement Visualization Delays Distance measurement Joining processes Surfaces Timing Europe network internet measurement curvature manifold visualization | Manifolds are complex topological spaces that can be used to represent datasets of real-world measurements. Visualizing such manifolds can help with illustrating their topological characteristics (e.g., curvature) and providing insights into important properties of the underlying data (e.g., anomalies in the measurements). In this paper, we describe a new methodology and system for generating and visualizing manifolds that are inferred from actual Internet latency measurements between different cities and are projected over a 2D Euclidean space (e.g., a geographic map). Our method leverages a series of graphs that capture critical information contained in the data, including well-defined locations (for vertices) and Ricci curvature information (for edges). Our visualization approach then generates a curved surface (manifold) in which (a) geographical locations of vertices are maintained and (b) the Ricci curvature values of the graph edges determine the curvature properties of the manifold. The resulting manifold highlights areas of critical connectivity and defines an instance of “Internet delay space” where latency measurements manifest as geodesics. We describe details of our method and its implementation in a tool, which we call Matisse, for generating, visualizing and manipulating manifolds projected onto a base map. We illustrate Matisse with three case studies: a simple example to demonstrate key concepts, and visualizations of the US and Europe public Internet to show Matisse’s utility. | 10.1109/TNSM.2026.3730274 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Ahmed Rjiba, Hicham Lakhlef, Joachim Bruneau-Queyreix, Meriem Afif | Federated Learning in Fog Computing within IoT Environments: An up-to-date and comprehensive survey | 2026 | Early Access | Federated learning Internet of Things Edge computing Modeling Clouds Security Training Surveys Privacy Timing Internet of Things (IoT) Federated Learning (FL) Fog Computing (FC) Survey Digital Twin (DT) | The Internet of Things (IoT) connects diverse, resource-constrained devices, driving innovation in domains such as healthcare, smart cities, and industrial automation. However, the exponential growth of IoT devices poses critical challenges in data processing, privacy, security, and latency. Fog Computing (FC) mitigates these issues by decentralizing computational resources, processing and storing data locally to enable low-latency, high-quality services. This makes FC an ideal platform for integrating Federated Learning (FL), a decentralized machine learning paradigm that trains models locally on IoT devices and shares only aggregated updates, preserving data privacy. Since its introduction, FL has garnered considerable attention for enabling privacy-preserving collaborative model training in distributed environments. The convergence of IoT, FC, and FL offers substantial opportunities to advance IoT system performance, but it also presents challenges in resource allocation, security, energy efficiency, computational complexity, and system heterogeneity. This survey provides a comprehensive and up-to-date analysis of the integration of FL and FC within IoT environments, exploring their synergies, challenges, and state-of-the-art advancements.We review critical aspects, including infrastructure enhancements, security mechanisms, and the emerging role of Digital Twin (DT) technology, which creates virtual replicas of IoT devices to optimize system efficiency and real-time performance. Through case studies in healthcare and smart cities, we highlight practical applications of FL-FC integration. We compare our work with existing surveys, highlight its specific focus on the FL-FC-IoT-DT convergence, and identify open challenges and future research directions toward secure, scalable, and intelligent IoT ecosystems. | 10.1109/TNSM.2026.3731410 |
| Siyu Jiang, Feng Guo, Di Chen, Yuan Liu, Ying Chen, Weijun Sun, Yu Wang, Shen Su | Smart Contract Vulnerability Detection via Mask Consistency with Dynamic Margin Adjustment | 2026 | Early Access | Labeling Modeling Smart contracts Signal detection Codes Contracts Learning (artificial intelligence) Training Educational institutions Conferences Smart contract vulnerability detection semi-supervised domain adaptation mask learning dynamic margin adjustment | With the rise of smart contract applications, new attacks that exploit contract vulnerabilities continue to emerge, and effective vulnerability detection methods are urgently needed. Deep learning-based methods have shown excellent performance. However, for new types of vulnerabilities, due to the lack of real labels to help the model learn subtle code differences, previous methods have difficulty distinguishing between vulnerable contracts and safe contracts with similar key code segments, resulting in false negatives. To address this problem, this paper proposes a smart contract vulnerability detection method that uses mask consistency (MC) and dynamic margin adjustment (DMA). Unlike traditional Masked Language Modeling (MLM) in CodeBERT that performs token-level reconstruction for general representation learning, our MC enforces classification-level consistency between a masked student network and an unmasked EMA teacher network at the semantic graph block level under semi-supervised domain adaptation. This enhances the model’s discriminative ability by adding contextual information of similar code segments as additional clues. Specifically, we define a student network to learn masked contracts, a teacher network to learn complete contracts, and implement few-shot learning through semi-supervised domain adaptation. In this process, the student network is helped to learn to correctly distinguish similar contracts by fusing contextual information. In order to guide students more effectively, we use DMA to screen high-quality pseudo-labels. We conduct extensive experiments on open source real-world vulnerability datasets, and the results show that our method significantly outperforms current mainstream deep learning methods in detecting six types of vulnerabilities. This approach also pioneers the application of domain adaptation and integrates MC with DMA in vulnerability detection, providing guidance for detecting different types of vulnerabilities. | 10.1109/TNSM.2026.3733072 |
| Nilesh Chakraborty, Petar Djukic, Burak Kantarci | Aggressive-YoYo: Exploiting Intent-Semantic Misalignment in AI-Native 6G Management Planes | 2026 | Early Access | Central Processing Unit Management Modeling Delays Aggregates Loading Memory Training Convolutional neural networks Probes AI-Native Network Intent Security Kubernetes Auto Scaling Threat Detection | Intent-Based Networking (IBN) enables operators to express high-level service objectives that are automatically translated into low-level control and orchestration policies. In AI-native 6G management planes, semantic misalignment during this translation can induce unsafe configurations that amplify conventional resource-exhaustion attacks. We investigate this vulnerability through aggressive-YoYo, a compound threat combining YoYo-style burst traffic with prematurely configured Kubernetes readiness probes. We implement an end-to-end Intent-to-Configuration pipeline that resolves natural-language service intents into structured policies, compiles them into Kubernetes probe settings, and evaluates the resulting behavior using a representative slice-assurance management function on Google Kubernetes Engine (GKE). Controlled readiness-delay experiments show that premature readiness can increase replica provisioning, aggregate CPU and memory consumption, storage activity, and request failures, while inducing non-trivial service-level tradeoffs. Similar resource amplification under a different N1-family machine type and deployment zone indicates that the effect is not specific to a single configuration.We further analyze readiness misconfiguration across multiple Kubernetes scaling mechanisms and derive service-specific safe and amplifying configuration regions. From the detection perspective, we show-case that aggressive-YoYo is detectable using fully supervised temporal classifiers evaluated with cycle-disjoint testing and feature-set ablation; the best configuration achieves an average accuracy of 92.6%. Under scarce aggressive-YoYo supervision, i.e., limited exposure to aggressive-YoYo traces, the supervised approach improves detection over the one-class setting. These results show that intent-semantic misalignment creates measurable cross-layer management risks and motivate semantic validation and telemetry-aware monitoring for trustworthy AI-native 6G orchestration. | 10.1109/TNSM.2026.3736983 |
| Amr Aboeleneen, Mohamed Abdallah, Aiman Erbad, Amr Salem | CIVIC: Cooperative Immersion Via Intelligent Credit-sharing in DRL-Powered Metaverse | 2026 | Early Access | Resource management Modeling Metaverse Costing Costs Optimization Head Accuracy Synchronization Actuators Deep Reinforcement Learning Immersion Metaverse Multi Service-Provider Resource Allocation Cooperative Systems Digital Twins | The Metaverse faces complex resource allocation challenges due to diverse Virtual Environments (VEs), Digital Twins (DTs), dynamic user demands, and strict immersion needs. This paper introduces CIVIC (Cooperative Immersion Via Intelligent Credit-sharing), a novel framework optimizing service-profile provisioning and budget-credit sharing among multiple Metaverse Service Providers (MSPs) to enhance user immersion. Unlike existing methods, CIVIC integrates VE rendering, DT synchronization, credit sharing, and immersion-aware provisioning within a cooperative multi-MSP model. The resource allocation problem is formulated as two NP-hard challenges: a non-cooperative setting where MSPs operate independently and a cooperative setting utilizing a General Credit Pool (GCP) for dynamic budget support. Using Deep Reinforcement Learning (DRL) for tuning resources and managing cooperating MSPs, CIVIC achieves 12-36% higher request completion, 23-70% higher fulfillment rates, 20-60% more served clients, and up to 51% more fairly distributed requests, all with competitive costs. Extensive experiments demonstrate CIVIC’s resilience, adaptability, and robust performance under dynamic load conditions and unexpected demand surges, making it suitable for real-world distributed Metaverse infrastructures. | 10.1109/TNSM.2026.3737119 |
| João Gabriel Pazinato De Bittencourt, Fábio Gonçalves De Oliveira, Edson José Pacheco, Carlos Marcelo Pedroso | Packet-Level Causal Certification of Tail-Latency and Reliability Control in O-RAN Slicing | 2026 | Early Access | Radio access networks Regional area networks Context Modeling Ultra reliable low latency communication Tail Poles and zeros Arm Open RAN Resource management O-RAN network slicing URLLC tail latency reliability causal inference certification RAN Intelligent Controller | An O-RAN slice controller holds two levers, the resource-block budget and the scheduling discipline, and reads an aggregate proxy that can pass a slice dropping packets or overrunning its latency bound. A lever that correlates with a key performance indicator need not control it. We answer, at the packet level, which lever an operator may act on. We evaluate compliance over every generated packet and lower-bound the probability that a lever both achieved compliance and was necessary for it. The bound carries information only when computed within each operating context and then standardized. The other order reduces to the average treatment effect, and the two coincide whenever the lever effect keeps its sign. A zero-sum allocation lever breaks that condition: the budget it grants one slice is taken from another. Over 3,720 runs one lever effect reverses from +0.32 to −0.66 with the neighbour’s load while averaging −0.008, so the pooled bound is zero and the stratified bound 0.156. Two contrasts on that lever, averaging −0.008 and 0.000, certify at 0.156 and at zero, which the pooled average effect cannot separate. The error guarantee covers false declarations of an effect, not the safety of acting on one. | 10.1109/TNSM.2026.3740306 |
| Mohammad Khosravi, Setareh Maghsudi | A Robust Optimization Approach for Regenerator Placement in Fault-Tolerant Networks Under Discrete Cost Uncertainty | 2026 | Early Access | IP networks Costing Costs Timing Modeling Optimization Uncertainty Joining processes Fluid flow Distance measurement Survivable networks robust optimization regenerator placement integer programming | We focus on robust, survivable communication networks, where network links and nodes are affected by an uncertainty set. In this sense, any network links might fail. Besides, a signal can only travel a maximum distance before its quality falls below a certain threshold, necessitating its regeneration by regenerators installed at network nodes. In addition, the price of installing and maintaining regenerators belongs to a discrete uncertainty set. Robust optimization seeks a solution with guaranteed performance against all scenarios modeled in an uncertainty set. Thus, the problem is to find a subset of nodes with minimum cost for the placement of the regenerator, ensuring that all nodes can communicate even if a subset of network links fails. To solve the problem optimally, we propose two solution approaches, including one flow-based and one cut-based integer programming formulation, as well as their iterative exact method. Our theoretical and experimental results show the effectiveness of our methods. | 10.1109/TNSM.2026.3740028 |
| Sheng-Shan Chen, Ren-Hung Hwang, Ying-Dar Lin, Tun-Wen Pai, Chin-Yu Sun | Extracting Attack Pattern from WAF Logs and CTIs Using Contrastive Semantic Learning | 2026 | Early Access | Modeling Payloads Cyber threat intelligence Labeling Large language models Training Cross-site scripting Modules (abstract algebra) Signal detection Grounding Web Application Firewall (WAF) Cyber Threat Intelligence (CTI) TTP Identification Contrastive Learning Monte Carlo Tree Search (MCTS) Semantic Search | Web Application Firewalls (WAFs) are widely deployed to protect web services, but their rule-based design provides limited visibility into attacker intent. WAF logs consist primarily of low-level HTTP artifacts that lack the behavioral context required for effective threat analysis. To address this limitation, we propose the first automated framework that mapsWAF logs to MITRE ATT&CK techniques through CTI-grounded semantic learning. The approach integrates structure-aware Monte Carlo Tree Search-based payload generation, CodeBERT-driven contrastive learning for attack classification, and cyber threat intelligence (CTI) alignment for TTP retrieval. The framework is evaluated on over 714,000 WAF logs derived from validated attack payloads across eight attack types, generated within a controlled environment using ModSecurity and OWASP Core Rule Set (CRS). Experimental results demonstrate 99.38% multi-class classification F1 score and identification of 206 unique ATT&CK techniques. Compared with a Rule-ID Heuristic baseline derived from OWASP CRS rule semantics, the proposed framework identifies 7.4× more unique ATT&CK techniques and provides substantially broader TTP-level visibility. External validation on a real-world ModSecurity log dataset further demonstrates that the framework preserves reliable classification and retrieval performance beyond the controlled payload-generation setting. | 10.1109/TNSM.2026.3738730 |
| Heng He, Qin Xu, Hai Yu, Lei Nie, Jianfeng Lu | LFNC: A Lightweight and Fine-Grained Two-Stage Network Flow Classification Framework with Programmable Data Planes | 2026 | Early Access | Fluid flow Planing Modeling Switches Accuracy Internet of Things Filtering Filters Encoding Trees (botanical) Programmable data planes flow classification P4 decision tree cuckoo filter | Flow classification is a crucial component of network intrusion detection systems. Existing approaches mainly fall into two categories: in-network classification and control-data plane collaborative classification. The former is constrained by the computing and memory resources of programmable switches, often sacrificing classification accuracy and efficiency. The latter requires transmitting large volumes of packets to the control plane, leading to high processing latency, excessive control-channel overhead, and limited flow coverage. To address these challenges, we propose LFNC, a Lightweight and Fine-grained two-stage Network flow Classification framework with programmable data planes. In the first stage, LFNC introduces a Decision Tree Segmentation (DTS) algorithm to train resource-aware models in the control plane. The trained DTS models are converted into switch-compatible matching rules and deployed in the data plane to perform line-rate binary classification for preliminary anomaly detection. In the second stage, LFNC employs a cuckoo filter together with dual circular queues to selectively buffer essential packet features of preliminarily anomalous flows in the data plane and efficiently transfer them to the control plane. A multi-class energy-based flow classifier is then applied in the control plane to achieve accurate and fine-grained classification of anomalous flows. Experimental results on the Tofino hardware switch demonstrate that LFNC outperforms eight state-of-the-art baselines, improving flow collection rate by 1.07% and classification accuracy by 3.34%, while significantly reducing hardware resource consumption and maintaining low packet processing latency. | 10.1109/TNSM.2026.3738578 |
| Amr Aboeleneen, Mohamed Abdallah, Aiman Erbad, Amr Mohamed | ZTCI: Zero-Touch Cooperative Immersion, a Plug-and-Deploy Deep Reinforcement Learning-Based Framework for Resource Allocation and Cooperation in the Metaverse | 2026 | Early Access | Resource management Modeling Metaverse Training Costing Costs Optimization Learning (artificial intelligence) Timing Rendering (computer graphics) Deep Reinforcement Learning Immersion Metaverse Multi-provider systems Cooperative resource allocation Digital twins Position-aware set encoders | The Metaverse requires edge providers, termed Metaverse Service Stations (MSSs), to provision high-quality virtual environments (VEs) and faithful digital twins (DTs) for heterogeneous virtual venues under tight compute and network budgets. In multi-MSS deployments, localized demand surges can overwhelm one station while neighboring stations remain underutilized. Cooperation is therefore essential but challenging because venue requirements are heterogeneous, demand is bursty, and proximity-based neighborhood sets change over time. These dynamics motivate zero-touch operation that requires neither retraining nor reconfiguration at deployment. We introduce the General Optimized Agent (GOA), a plug-and- deploy Deep Reinforcement Learning (DRL) agent that jointly optimizes per-venue VE/DT service levels and inter- MSS resource sharing. GOA is trained through staged curriculum learning and uses a position-aware set encoder with learned positional embeddings and attention-based pooling to map variable-size neighbor sets to fixed-dimensional representations. This design yields a single policy that generalizes across MSS types, budget levels, and dynamic team sizes. Extensive evaluation shows that GOA improves request satisfaction, load balancing, and cost efficiency over representative baselines, supporting scalable, zero-touch Metaverse cooperation under realistic infrastructure constraints. | 10.1109/TNSM.2026.3737187 |
| Huixiang Zhang, Faria Khandaker, Mahzabeen Emu | A Topology-Aware LLM-Augmented Digital Twin Framework for Scalable IoT Device Management | 2026 | Early Access | Internet of Things Topology Management Modeling Grounding Ciphers Context Training Optimization Large language models Large Language Models Digital Twins IoT | The growing scale and dynamic nature of Internet of Things (IoT) deployments demand management approaches that can maintain accurate system awareness. Existing large language models (LLMs) can reduce the interface burden of network management. However, without explicit grounding in the physical system state, they may generate nonexistent devices, incorrect topological relations, or non-executable management actions. To address this problem, this paper proposes a digital twin (DT) grounded LLM augmented management framework for IoT device management. The framework uses the DT as a structured state source, allowing the model to access topology consistent device, connection, and status information before generating management responses. A topology importance driven adapter training method, implemented through Hierarchical Importance Organizer (HIO), is further developed to encode hierarchical paths and critical nodes into training samples. We further characterize how grounded management degrades as the DT drifts from the physical topology, isolating the robustness contribution of topology-aware adaptation. Across 34,200 completed per-sample model outputs, including a 7,200-output main benchmark and a 27,000-output topology-drift sweep, HIO is evaluated against schema-only prompting, a base plus DT model, and a GenTwin-like adapter. On the 1,800-sample main benchmark, HIO achieves 0.869 Direct F1, improving over the GenTwin-like adapter by 3.3 points and over the base plus DT model by 29.1 points. HIO also improves Exact Match from 0.753 to 0.827. The gain is most pronounced in topology-sensitive impact analysis, where HIO improves Direct F1 from 0.784 to 0.918. HIO has positive gains in all nine topology–scale cells, with 95% confidence intervals excluding zero in seven cells. Under DT topology drift, HIO consistently outperforms the GenTwin-like adapter over δ ∈ [0, 0.20] and degrades more slowly, with Direct F1 degradation slopes of −0.157 versus −0.189. | 10.1109/TNSM.2026.3736467 |
| Marco Garofalo, Luca D’Agati, Laura García, Rafael Asorey-Cacheda, Antonio-Javier Garcia-Sanchez, Joan Garcia-Haro, Antonio Puliafito, Giovanni Merlino, Francesco Longo | Trustless SLA Enforcement and Roaming in LoRaWAN through Smart Contracts | 2026 | Early Access | Roaming Service level agreements LoRaWAN Internet of Things Smart contracts Contracts Radiation detectors Authorization Quality of service Containers Roaming LoRaWAN SLA QoS IoT blockchain smart contracts network management | LoRaWAN is widely used for Internet of Things (IoT) services that require long-range, low-power wireless connectivity. As deployments grow, roaming between different network operators becomes increasingly important to maintain service continuity for mobile IoT devices. In practice, however, roaming still depends on bilateral agreements and trusted intermediaries, which limit scalability and reduce transparency in multi-operator settings. This work introduces a blockchain-based roaming architecture that uses Algorand smart contracts to automate Service Level Agreement (SLA) management between providers. The system supports dynamic roaming agreements, immutable packet accounting, and transparent settlement. In our system, the enforced guarantee concerns forwarding-level service quality at the roaming interface, namely payment conditional on observed delivery ratio, rather than deterministic radio-layer latency or jitter guarantees. We implemented the full infrastructure, including a custom Gateway Bridge that extracts the Network Identifier (NetID), a blockchain service that interacts with Algorand smart contracts for SLA validation, and a decentralized provider catalog for operator discovery. We evaluated the system on a testbed with production-grade ChirpStack network servers and compared it with our previous non-blockchain implementation. Both versions achieve comparable throughput (5800–5900 packets/minute with 1000 devices) and maintain 99% packet forwarding efficiency. Blockchain integration adds measurable overhead, including a forwarding latency overhead in the 400–490 ms range for SLA validation, largely independent of the underlying network delay, but remains acceptable for delay-tolerant IoT services. Overall, the results show that decentralized LoRaWAN roaming can be implemented without breaking compatibility with existing network architectures. | 10.1109/TNSM.2026.3734694 |