Last updated: 2026-10-04 05:01 UTC
All documents
Number of pages: 175
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Le Zhang, Yu Gu, Ye Du, Xin Liu, Jikai Zhang, Junyan Guo | EasySatSim: Enabling Researchers to Build Scalable LEO Satellite Network Experimental Environments on Personal Computing Devices | 2026 | Early Access | Satellites Protocols Low earth orbit satellites Simulation Stacking Modeling Routing Timing Current Architecture LEO satellite networks experimental platform network performance evaluation simulator scenario adaptability | Global communication networks based on LEO satellite constellations are within reach, attracting the attention and efforts of many researchers. However, creating the required experimental environments under the complex and vast satellite network architecture remains a challenge. As of now, open-source experimental platforms generally face limited adaptability, high resource consumption, and difficulties in environment deployment. Therefore, this paper introduces the EasySatSim experimental platform, which allows researchers to build large-scale LEO satellite network experimental environments on personal computing devices. EasySatSim consists of three core components: entities, behaviors, and protocol stacks, and constructs a highly modular architecture through the Controller Layer, Manager Layer, Execution Layer, Global Services Layer, and API Support Layer. Researchers can configure specific tasks for individual satellites and users, and even create entities like ground stations and central servers as needed, supporting adaptability from the parameter level to the scenario level. EasySatSim also considers packet-level system overhead and provides configurable support for practical network-level performance evaluation. Finally, three cases from the distinct fields of intrusion detection, machine learning, and network routing in LEO satellite networks are used to demonstrate the flexibility of EasySatSim. | 10.1109/TNSM.2026.3739052 |
| Dhiraj Pandey, Pranav Singla, Siddharth Pal, Prasenjit Chanak, Manish Pratap Singh, Om Jee Pandey | HFSL-CUNs: A Hierarchical Federated Split Learning Framework for Cluster-Based and UAV-Assisted Edge-Fog-Cloud Networks | 2026 | Early Access | Autonomous aerial vehicles Modeling Internet of Things Filtering Filters Federated learning Privacy Clouds Optimization Training UAV-assisted edge-fog-cloud networks hierarchical split learning adaptive activation clustering spatio-temporal filtering differential privacy mobile IoT | The increasing deployment of Internet of Things (IoT) applications has created a growing need for distributed learning frameworks that can operate efficiently across resource-constrained edge environments while preserving data privacy. Federated Learning (FL) enables collaborative model training without sharing raw data. However, its communication overhead, computational burden, and limited scalability make it less suitable for large-scale hierarchical edge networks. In this paper, we propose Hierarchical Federated Split Learning (HFSL), a unified Unmanned Aerial Vehicle (UAV)-assisted edge-fog-cloud framework that combines the complementary strengths of FL and Split Learning (SL) to improve communication efficiency, scalability, and privacy. HFSL introduces activation similarity-based clustering and spatio-temporal activation filtering to reduce redundant communication, adaptive UAV altitude optimization to improve wireless connectivity under dynamic network conditions, and a privacy-preserving training strategy based on Differential Privacy (DP) and activation-level leakage mitigation. Extensive experiments across eight image and tabular benchmark datasets demonstrate that HFSL outperforms state-of-the-art FL and SL methods on the more challenging heterogeneous benchmarks, reducing energy consumption by up to 50%, training latency by 40%, and communication overhead by 35%, while improving classification accuracy by up to 6%. These results show that HFSL provides an effective and scalable distributed learning framework for next-generation UAV-assisted edge networks. | 10.1109/TNSM.2026.3738968 |
| Messaoud Ait-Yahia, Wael Jaafar, Rami Langar | Joint Design of Blockchain-Enabled Service Placement and Task Assignment in Vehicular Fog Computing Networks | 2026 | Early Access | Delays Timing Optimization Autonomous aerial vehicles Modeling Gallium Central Processing Unit Joints Bandwidth Elementary particles Resource allocation Blockchain VNF placement task assignment vehicular fog computing PSO GA IoV | Driven by the evolution of blockchain and fog computing, vehicular networks are increasingly capable of supporting latency-sensitive applications with enhanced security and trust guarantees. However, the joint resource allocation for task offloading and blockchain services has been insufficiently investigated in existing works. To address this gap, this paper proposes a framework for jointly allocating resources of blockchain, users’ virtualized services, and Mobile Edge Computing (MEC) task assignment in Vehicular Fog Computing (VFC) networks. Specifically, we formulate the optimization problem as an integer nonlinear programming model aiming to maximize the satisfaction rate of users’ service requests while minimizing the corresponding blockchain operation time under mobility, queuing, instantiation, and resource constraints. To solve it in a timely manner, we design two-stage hierarchical low-complexity solutions, namely a Particle Swarm Optimization-based Joint Blockchain-enabled Service placement and Task Assignment algorithm (PSO-JBSTA), and a Genetic Algorithm-based approach (GA-JBSTA). Through extensive simulations, we demonstrate the effectiveness of PSO-JBSTA (resp. GA-JBSTA) and their adaptability to network conditions, achieving an average 35% (resp. 24%) improvement in users’ service satisfaction rate and 9.5% (resp. 10.2%) reduction in average blockchain validation delay compared with the baselines. | 10.1109/TNSM.2026.3737068 |
| Kim Hammar, Rolf Stadler | Online Identification of IT Systems through Active Causal Learning | 2026 | Early Access | Modeling Learning (artificial intelligence) Costing Costs Measurement Timing Optimization Active learning Radio access networks Regional area networks IT system causality system identification rollout active learning cybersecurity Gaussian processes GP | Identifying a causal model of an IT system is fundamental to many branches of systems engineering and operation. Such a model can be used to predict the effects of control actions, optimize operations, diagnose failures, detect intrusions, etc., which is central to achieving the longstanding goal of automating network and system management tasks. Traditionally, causal models have been designed and maintained by domain experts. This, however, proves increasingly challenging with the growing complexity and dynamism of modern IT systems. In this paper, we present the first principled method for online, data-driven identification of an IT system in the form of a causal model. The method, which we call active causal learning, estimates causal functions that capture the dependencies among system variables in an iterative fashion using Gaussian process regression based on system measurements, which are collected through a rollout-based intervention policy. We prove that this method is optimal in the Bayesian sense and that it produces effective interventions. Experimental validation on two testbeds shows that our method enables accurate identification of a causal system model while inducing low interference with system operations. | 10.1109/TNSM.2026.3736090 |
| Kim Hammar, Neil Dhir, Rolf Stadler | Optimal Defender Strategies for CAGE-2 using Causal Modeling and Tree Search | 2026 | Early Access | Modeling Timing Trees (botanical) Vegetation Weighted sum model Conferences Silicon Games Security Algorithms Cybersecurity network security causal inference SCM APT CAGE-2 POMDP intrusion response | The CAGE-2 challenge is considered a standard benchmark to compare methods for autonomous cyber defense. Current state-of-the-art methods evaluated against this benchmark are based on model-free (offline) deep reinforcement learning techniques, which do not provide provably optimal defender strategies. We address this limitation and present a formal (causal) model of CAGE-2 together with a method that converges to a provably optimal defender strategy, which we call causal partially observable Monte-Carlo planning (C-POMCP). Our method has two novel properties. First, it incorporates the causal structure of the target system through causal relationships among the system variables. This structure allows for a significant reduction of the search space of defender strategies. Second, it is an online method that updates the defender strategy at each time step via tree search. Evaluations against the CAGE-2 benchmark show that C-POMCP achieves state-of-the-art performance with respect to effectiveness and requires two orders of magnitude less computation than the closest competitor method. | 10.1109/TNSM.2026.3735865 |
| Yao Xin, Yuqiao Luo, Shufan Cao, Chongwu Dong, Qingfeng Tan | HBT: A Hybrid Bidding Tree for High-Performance Packet Classification | 2026 | Early Access | Heterojunction bipolar transistors Trees (botanical) Vegetation Memory Pediatrics Construction Information rates Throughput Indexes Indexing Decision tree packet classification performance rule partitioning | Traditional packet classification algorithms based on decision trees often rely on rule replication to increase lookup speed, which inevitably leads to memory explosion. Conversely, existing zero-replication methods frequently suffer from extreme tree depth and structural fragmentation. To address this dilemma, this paper proposes the Hybrid Bidding Tree (HBT), a high-performance architecture designed to enforce zero-replication while sustaining deterministic lookup throughput. First, HBT employs an Overlap-Aware Rule Decomposition (OARD) framework to proactively isolate topologically entangled rules, purifying the primary geometric space. Second, HBT introduces a dynamic competitive bidding mechanism for tree construction. At each node, a discrete bit-selection path and a continuous range-partitioning path compete to determine the optimal splitting strategy based on local geometric heterogeneity. Finally, to guarantee an O(N) memory boundary, unpartitionable residual rules are assigned to a single-level Onion-Peeling fallback structure, preserving linear memory growth while introducing additional sequential checks in the auxiliary path. Experimental evaluations on ClassBench-ng rulesets containing up to 256k rules demonstrate the efficacy of HBT. Compared with state-of-the-art algorithms such as PT-Tree and TupleTree, HBT achieves the highest lookup throughput across all twelve evaluated rulesets at both the 128k and 256k scales, while maintaining strong memory efficiency and highly competitive construction and update latencies. | 10.1109/TNSM.2026.3734240 |
| Siyu Jiang, Feng Guo, Di Chen, Yuan Liu, Ying Chen, Weijun Sun, Yu Wang, Shen Su | Smart Contract Vulnerability Detection via Mask Consistency with Dynamic Margin Adjustment | 2026 | Early Access | Labeling Modeling Smart contracts Signal detection Codes Contracts Learning (artificial intelligence) Training Educational institutions Conferences Smart contract vulnerability detection semi-supervised domain adaptation mask learning dynamic margin adjustment | With the rise of smart contract applications, new attacks that exploit contract vulnerabilities continue to emerge, and effective vulnerability detection methods are urgently needed. Deep learning-based methods have shown excellent performance. However, for new types of vulnerabilities, due to the lack of real labels to help the model learn subtle code differences, previous methods have difficulty distinguishing between vulnerable contracts and safe contracts with similar key code segments, resulting in false negatives. To address this problem, this paper proposes a smart contract vulnerability detection method that uses mask consistency (MC) and dynamic margin adjustment (DMA). Unlike traditional Masked Language Modeling (MLM) in CodeBERT that performs token-level reconstruction for general representation learning, our MC enforces classification-level consistency between a masked student network and an unmasked EMA teacher network at the semantic graph block level under semi-supervised domain adaptation. This enhances the model’s discriminative ability by adding contextual information of similar code segments as additional clues. Specifically, we define a student network to learn masked contracts, a teacher network to learn complete contracts, and implement few-shot learning through semi-supervised domain adaptation. In this process, the student network is helped to learn to correctly distinguish similar contracts by fusing contextual information. In order to guide students more effectively, we use DMA to screen high-quality pseudo-labels. We conduct extensive experiments on open source real-world vulnerability datasets, and the results show that our method significantly outperforms current mainstream deep learning methods in detecting six types of vulnerabilities. This approach also pioneers the application of domain adaptation and integrates MC with DMA in vulnerability detection, providing guidance for detecting different types of vulnerabilities. | 10.1109/TNSM.2026.3733072 |
| Xiaodi Wang, Yunwei Dong, Weizhi Meng, Meng Li, Yining Liu | Dropout-Tolerant Privacy-Preserving Aggregation for Federated Mobile Crowdsensing | 2026 | Early Access | Modeling Privacy Internet of Things Training Federated learning Accuracy Calcium Timing Silicon Security Mobile crowdsensing Federated learning Privacy preservation Dropout tolerance Homomorphic encryption | Federated Learning (FL) has emerged as a key enabler for privacy-preserving, decentralized sensing systems, giving rise to Federated Mobile Crowdsensing (F-MCS). A well-known bottleneck in such systems is the inefficiency of synchronous training, which stalls for all participants and is susceptible to stragglers in heterogeneous environments. Although asynchronous FL methods have been explored to alleviate this, they often introduce the critical issue of stale updates, which can degrade model convergence and accuracy. To simultaneously address the challenges of efficiency, staleness, and robustness, this paper proposes a novel Dropout-Tolerant Privacy Aggregation (DTPA) scheme for FL that operates without a trusted third party (TTP). Our solution leverages the distributed decryption feature of the lifted EC-ElGamal cryptosystem to enable secure, decentralized model aggregation. We further introduce an efficient worker selection algorithm to systematically reduce waiting time. Moreover, a dedicated dropout-tolerant mechanism is developed to maintain protocol execution even under a high rate of client failures, thereby enhancing robustness. Security analysis confirms that our scheme fulfills essential privacy and security requirements. Extensive simulations demonstrate that the proposed DTPA scheme significantly improves training efficiency and convergence stability compared to state-of-the-art methods, while remaining practical for deployment on resource-constrained mobile devices. | 10.1109/TNSM.2026.3732465 |
| Mubashir Murshed, Glaucio H. S. Carvalho, Robson E. De Grande | Holistic Intelligent Traffic Steering Management in Multi-RAT Vehicular Networks | 2026 | Early Access | Radio access technologies Rats Vehicles Modeling Long short term memory Poles and towers 5G mobile communication Joining processes Timing Received signal strength indicator Traffic Steering Multi-RAT Network Management Bi-level GCN-LSTM SARSA High-mobility Ultra-dense networks | Multiple Radio Access Technology (multi-RAT) environments provide a promising foundation for service-aware communication in intelligent transportation systems (ITS) and smart cities. However, traffic steering (TS) in highly mobile and ultra-dense vehicular networks remains challenging due to dynamic network conditions, heterogeneous RAT capabilities, varying vehicle requirements, packet loss, latency, and frequent ping-pong RAT switching. In this context, we propose Holistic Intelligent Traffic Steering (HITS), a proactive bi-level TS management framework for multi-RAT vehicular networks. HITS integrates centralized network-wide guidance with local vehicleside decision-making. At the central level, a Graph Convolutional Network–Long Short-Term Memory (GCN–LSTM) model captures holistic spatio-temporal network dynamics and evaluates RAT optimality. At the local level, a State-Action-Reward- State-Action (SARSA) reinforcement learning agent performs adaptive, vehicle-specific RAT selection using local observations and central-level optimality guidance. Results show that HITS achieves up to 6.5% higher average throughput, reduces packet loss ratio by more than 30.2%, lowers latency by nearly 12.2%, and reduces the ping-pong RAT switching rate by over 24% compared with baseline and state-of-the-art (SoTA) TS approaches. | 10.1109/TNSM.2026.3729840 |
| Martine S. Lenders, Carsten Bormann, Thomas C. Schmidt, Matthias Wählisch | A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPS | 2026 | Early Access | Internet of Things Encoding Internet Arrays Gain Recording Tagging Timing HTTP Decoding CBOR World Wide Web JSON DNS application/dns+cbor Internet measurements | The Internet community has taken major efforts to decrease latency on the World Wide Web with significant improvements in accelerating content transport and in compressing static content. Less attention, however, has been dedicated to compression of dynamic content. Such content is commonly provided by JSON and DNS over HTTPS. Dynamic content objects continue to grow in size, which increases latency and fosters the digital inequality. In this paper, we propose to mitigate this increase by utilizing Concise Binary Object Representation (CBOR), a standard originally designed for the constrained Internet of Things (IoT) to restrict packet sizes and enable efficient encoding of data objects. We provide protocol design and three new data sets for the evaluation of dynamic content, DNS, and the loading of websites. Our key findings are the following: (i) Switching the data representation from JSON to CBOR reduces data by up to 80%. This size reduction can decrease loading times by up to 13.8% when downloading large objects—even in local setups. (ii) Enabling CBOR for DNS over HTTPS (DoH) and DNS over CoAP (DoC) reduces packet sizes significantly. Compressing only names combined with unpacked CBOR achieves maximum gain of 52.2%, using more complex but still lightweight Packed CBOR allows minimizing packets by up to 95.5%. Our lean decoder for name compression can fit into as little as 314 bytes of build size. Our results clearly show the potential of CBOR outside of IoT scenarios. Parts of this research have already influenced work within the IETF. | 10.1109/TNSM.2026.3722114 |
| Sheng-Shan Chen, Ren-Hung Hwang, Ying-Dar Lin, Tun-Wen Pai, Chin-Yu Sun | Extracting Attack Pattern from WAF Logs and CTIs Using Contrastive Semantic Learning | 2026 | Early Access | Modeling Payloads Cyber threat intelligence Labeling Large language models Training Cross-site scripting Modules (abstract algebra) Signal detection Grounding Web Application Firewall (WAF) Cyber Threat Intelligence (CTI) TTP Identification Contrastive Learning Monte Carlo Tree Search (MCTS) Semantic Search | Web Application Firewalls (WAFs) are widely deployed to protect web services, but their rule-based design provides limited visibility into attacker intent. WAF logs consist primarily of low-level HTTP artifacts that lack the behavioral context required for effective threat analysis. To address this limitation, we propose the first automated framework that mapsWAF logs to MITRE ATT&CK techniques through CTI-grounded semantic learning. The approach integrates structure-aware Monte Carlo Tree Search-based payload generation, CodeBERT-driven contrastive learning for attack classification, and cyber threat intelligence (CTI) alignment for TTP retrieval. The framework is evaluated on over 714,000 WAF logs derived from validated attack payloads across eight attack types, generated within a controlled environment using ModSecurity and OWASP Core Rule Set (CRS). Experimental results demonstrate 99.38% multi-class classification F1 score and identification of 206 unique ATT&CK techniques. Compared with a Rule-ID Heuristic baseline derived from OWASP CRS rule semantics, the proposed framework identifies 7.4× more unique ATT&CK techniques and provides substantially broader TTP-level visibility. External validation on a real-world ModSecurity log dataset further demonstrates that the framework preserves reliable classification and retrieval performance beyond the controlled payload-generation setting. | 10.1109/TNSM.2026.3738730 |
| Hamidreza Mazandarani, Masoud Shokrnezhad, Tarik Taleb | A Semantic-Aware Multiple Access Scheme Leveraging Spatial Redundancy for Uplink-Dominant Network Services | 2026 | Early Access | Timing Titanium Modeling Information rates Throughput Energy efficiency Media Access Control Optimization Energy Training 6G Semantic-awareness Resource Allocation Multiple Access Medium Access Control (MAC) Wireless Spectrum Utilization Fairness Sustainability Energy Throughput Deep Q-Learning Reinforcement Learning Distributed | The transition toward semantic-aware communication offers a paradigm shift for next-generation mobile networks, promising to decouple information significance from raw data transmission. Despite advances in semantic extraction, the integration of semantic intelligence into the Medium Access Control (MAC) layer remains underexplored, particularly in exploiting spatial correlations among users. To address this, we introduce a novel multiple access scheme designed for uplink-dominant network services. This framework optimizes the trade-off between spectrum utilization and sustainability by formulating variable-packet-length access as distinct α-fairness and energy efficiency problems. A key innovation of our approach is the quantification of spatial redundancies through novel metrics of self-throughput and assisted-throughput, which account for the semantic correlation of data across user equipment. We analyze these formulations to identify optimal bounds before proposing PRISM (Protocol for Redundancy Identification in Semantic Multiple-access). Grounded in Model-free Multi-Agent Deep Reinforcement Learning (MADRL), PRISM enables devices to autonomously govern spectrum access using only local observations. Extensive evaluations demonstrate that PRISM successfully leverages redundancies to outperform semantic-oblivious schemes, achieving up to 90% of the centralized optimal benchmark and improving both objectives by up to 2× across diverse user-semantic association matrices. These results validate PRISM as a viable candidate for future distributed mobile network applications, complemented by orthogonal Multiple Access Schemes where signals are multiplexed in the semantic domain. | 10.1109/TNSM.2026.3737571 |
| Huixiang Zhang, Faria Khandaker, Mahzabeen Emu | A Topology-Aware LLM-Augmented Digital Twin Framework for Scalable IoT Device Management | 2026 | Early Access | Internet of Things Topology Management Modeling Grounding Ciphers Context Training Optimization Large language models Large Language Models Digital Twins IoT | The growing scale and dynamic nature of Internet of Things (IoT) deployments demand management approaches that can maintain accurate system awareness. Existing large language models (LLMs) can reduce the interface burden of network management. However, without explicit grounding in the physical system state, they may generate nonexistent devices, incorrect topological relations, or non-executable management actions. To address this problem, this paper proposes a digital twin (DT) grounded LLM augmented management framework for IoT device management. The framework uses the DT as a structured state source, allowing the model to access topology consistent device, connection, and status information before generating management responses. A topology importance driven adapter training method, implemented through Hierarchical Importance Organizer (HIO), is further developed to encode hierarchical paths and critical nodes into training samples. We further characterize how grounded management degrades as the DT drifts from the physical topology, isolating the robustness contribution of topology-aware adaptation. Across 34,200 completed per-sample model outputs, including a 7,200-output main benchmark and a 27,000-output topology-drift sweep, HIO is evaluated against schema-only prompting, a base plus DT model, and a GenTwin-like adapter. On the 1,800-sample main benchmark, HIO achieves 0.869 Direct F1, improving over the GenTwin-like adapter by 3.3 points and over the base plus DT model by 29.1 points. HIO also improves Exact Match from 0.753 to 0.827. The gain is most pronounced in topology-sensitive impact analysis, where HIO improves Direct F1 from 0.784 to 0.918. HIO has positive gains in all nine topology–scale cells, with 95% confidence intervals excluding zero in seven cells. Under DT topology drift, HIO consistently outperforms the GenTwin-like adapter over δ ∈ [0, 0.20] and degrades more slowly, with Direct F1 degradation slopes of −0.157 versus −0.189. | 10.1109/TNSM.2026.3736467 |
| Abdul Samim, Attiq Ur Rehman, KyungHi Chang | Intelligent Handover Management for 6G LEO Satellite Constellations: A Predictive Multi-Agent PPO Approach | 2026 | Early Access | Satellites Handover Loading Low earth orbit satellites Modeling Optimization Signal to noise ratio 3GPP Management Timing 6G networks LEO satellites handover management multi-agent reinforcement learning proximal policy optimization predictive algorithms load balancing | The integration of Low Earth Orbit (LEO) satellite constellations into 6G networks promises ubiquitous connectivity, yet poses unprecedented challenges for handover management due to rapid orbital motion and dynamic channel conditions. Traditional reactive handover algorithms, designed for quasistatic terrestrial networks, fail to address the multi-dimensional optimization requirements of LEO systems where satellites move at velocities exceeding 7 km/s and user-satellite connections last only 2-4 minutes. This paper proposes a Predictive Multi-Agent Proximal Policy Optimization (PMA-PPO) framework for SNR-aware load-balanced handover management in dual-layer LEO satellite networks. The framework integrates three core components: Gated Recurrent Unit (GRU) networks for temporal forecasting of channel conditions and satellite loads, distributed PPO agents for autonomous handover decision-making, and a coordination mechanism that balances signal quality with load distribution. Through comprehensive simulations of a realistic dual-layer constellation, PMA-PPO achieves significant performance improvements: up to 77.7% reduction in handover failure rates, 74.06% reduction in satellite overload duration, 35.13% improvement in throughput fairness, and ping-pong handover rates consistently below the practical 5% threshold across all load conditions, compared to state-of-the-art base-line approaches. The proposed approach achieves polynomial computational complexity versus exponential cost for exhaustive optimization, making it suitable for real-time deployment in large-scale LEO constellations. | 10.1109/TNSM.2026.3735527 |
| Awais Bilal, Kashif Sharif, Liehuang Zhu, Fan Li, Chang Xu | SLA-Aware RSU-Edge Delegate Orchestration for IoV Consensus | 2026 | Early Access | Modeling Information rates Throughput Internet of Vehicles Timing Management Telemetry Tail Churn Entropy Internet of Vehicles Delegated Proof-of-Stake Reinforcement learning QoS-aware orchestration Mobility-aware networking | Ensuring reliable and timely consensus among Internet of Vehicles (IoV) nodes is critical for safety and operational efficiency, particularly under high mobility and dynamic network conditions. Traditional consensus protocols, however, do not explicitly incorporate service-level objectives (SLOs) such as commit latency, tail latency, or delegate-set diversity, limiting their applicability in real-world deployments. In this paper, we present a service-level agreement (SLA)-aware road-side unit (RSU)-edge orchestration framework for IoV consensus delegate selection, which leverages reinforcement learning (RL) to optimize committee composition while preserving quorum safety. Our approach embeds SLO metrics directly into the proximal policy optimization (PPO) reward function, enabling the RSU-edge to adapt delegate selection online under varying vehicle densities, speeds, and network conditions. A shortlist-based candidate reduction mechanism reduces computational overhead, while certificate-governed reconfiguration and state transfer support safe committee activation and recovery. Extensive simulations across multiple scenarios, including burst losses and mobility-induced churn, demonstrate that our method reduces median and tail commit latency, increases throughput, and maintains higher delegate-set diversity than baseline heuristics and the adapted BFTBrain-style service comparator. Under the simulator reference configuration, the modeled proposal-construction components yield a component-wise tail budget of 18.8 ms, excluding governance certification and state synchronization. The framework provides a practical blueprint for service-level-aware management of IoV consensus, bridging the gap between protocol-level designs and operational network management. Within the controlled service-level simulation scope, the study demonstrates the feasibility, robustness, and performance advantages of RL-driven RSU-edge orchestration. Packet-level and field deployment validation remain future work. | 10.1109/TNSM.2026.3739347 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Yingjie Hu, Weiping Wang, Shigeng Zhang, Hong Song, Ziheng Huang, Song Guo | Dual-State Representation Learning for Multi-Granularity IoT Device Identification | 2026 | Early Access | Internet of Things Modeling Training Labeling Sequences Sequential analysis Testing Accuracy Contrastive learning Multitasking IoT security device identification self-supervised learning contrastive learning multi-granularity | The rapid growth of IoT devices has increased demand for traffic-based network asset management and security monitoring. Most existing methods operate in closed-set settings and may misclassify unseen devices as known models or return only an unknown label. To address this problem, this paper proposes a multi-granularity IoT device identification method based on dual-state representation learning. Device identity is modeled at three levels: type, manufacturer, and model, retaining type and manufacturer information when the device model cannot be reliably identified. The method extracts statistical, sequence, and raw-byte features and learns sequence and byte embeddings from idle and behavior traffic. Self-supervised learning and contrastive learning are used to improve the discriminative ability of representations. A state-aware gating mechanism then dynamically fuses the dual-state embeddings. Multi-task classification heads and confidence thresholds are used to support joint identification and rejection. Experiments on three public datasets show over 98% accuracy for known-device identification. The method also achieves over 97% accuracy for type and manufacturer prediction on the unknown-model test set and over 95% rejection rate for unknown models. Online deployment achieves an average latency of 3.1 ms and a throughput of 322 samples/s, demonstrating practical potential in open network environments. | 10.1109/TNSM.2026.3738728 |
| Mohamed Zalat, Chris Barber, Babak Esfandiari, Thomas Kunz | A Reusable Network Digital Twin Architecture for QoS-Centric Network Management | 2026 | Early Access | Modeling Fluid flow Optimization Joining processes Delays Management Topology Border Gateway Protocol Measurement Quality of service Network Digital Twins Digital Twins IGP BGP Fault Localization Networks | We propose a network digital twin approach for Quality of Service (QoS)-centric network management and demonstrate it on multiple network management problems. Our network digital twin involves running many ”what-if?” network configurations using a fast inference model for predicting network behavior, and applying the best configuration found based on the criteria of the network operator. We demonstrate the flexibility of this approach by applying it to 3 different network management problems: Interior Gateway Protocol (IGP) weight optimization, Border Gateway Protocol (BGP) route assignments, and gray fault detection and localization. We test our approach for each application on various OMNeT++ topologies and compare it to existing benchmarks in the respective literature. Our results indicate that the proposed network digital twin approach performs comparably to existing benchmarks in the network management problems explored and sometimes outperforms them in quality of service metrics. | 10.1109/TNSM.2026.3737654 |