Last updated: 2026-08-07 05:01 UTC
All documents
Number of pages: 170
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Jheng-Jia Huang, Guan-Yu Chen, Hiroaki Kikuchi, Po-Yuan Su | Full-duplex Low-latency Handover and Transmission Authentication Protocol for 6G Networks | 2026 | Early Access | Protocols Authentication Modeling Handover Security Timing Physical unclonable function Interference Clouds Architecture 6G full duplex transmission protocol low latency mutual authentication | Sixth-generation (6G) networks demand ultra-low latency, high reliability, and seamless handover. However, existing authentication and handover mechanisms, such as 3GPP 5G-AKA/EAP-AKA’ and Xn-/N2-based procedures, are based on half-duplex request–response signaling and incur sequential waiting delays. We propose a full-duplex–aware authentication and handover framework empowered by Co-frequency Co-time Full Duplex (CCFD) communication. By reorganizing 3GPP-style signaling so that authentication, key updates, and connection setup proceed in parallel between the UE, serving gNB, and target gNB, the central cloud is kept outside the real-time handover path. We formalize a game-based security model and prove mutual authentication under a pseudorandom permutation assumption. At the protocol level, we combine measured cryptographic costs with a link-delay model to compare the proposed scheme with the 3GPP baseline and representative academic protocols. The results show that full-duplex signaling can significantly reduce authentication and handover latency while preserving comparable security guarantees. | 10.1109/TNSM.2026.3720523 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| S A Harish, S Vignesh, Divya Pathak, Anil Kumar Sharma, Praveen Tammana | Anomaly Detection in In-Network Fast ReRoute Systems | 2026 | Early Access | Fluid flow Planing Delays Windows Signal detection Memory Anomaly detection Conferences Timing Testing In-network processing Anomaly detection Pro-grammable data planes Network security Software-Defined Networks P4 | High-speed programmable data planes provide opportunities to implement data-driven fast reroute systems that quickly adapt to varying network conditions (e.g., congestion, failures) and improve network performance. The core of these systems has packet-processing algorithms running in the data plane that continuously look for traffic patterns (e.g., too many retransmissions) specific to a network condition (e.g., link failure) and take appropriate action (e.g., reroute). Despite their benefits, they also increase the potential attack surface. Adversaries can generate malicious traffic patterns resembling those anticipated by a fast reroute system and trick the system. Doing so would lead to poor network performance due to incorrect reroute decisions. In this paper, we propose a mechanism to detect whether the fast reroute systems are under the influence of malicious traffic patterns. Our key idea is to model the expected behavior using benign traffic features and use the model as a reference to determine whether the system is under the influence of adversaries. Using realistic attack traces, we demonstrate attacks on two fast reroute systems and successfully detect those attacks using the proposed detection mechanism. | 10.1109/TNSM.2026.3715353 |
| Kaifei Peng, Yanbiao Li, Wenbin Li, Yuxuan Chen, Xian Yu, Xin Wang, Bo Pang, Gaogang Xie | Rethinking Virtual Network Construction for Network Emulation at Scale: Analysis, Modeling, and Optimization | 2026 | Early Access | Virtual machines Memory Timing Topology Construction Emulation Modeling Machining Costing Costs Large-scale virtual networks network emulation network namespaces network virtualization virtual machines virtual network construction | Network emulation has become an indispensable methodology for evaluating next-generation network architectures, offering a critical balance between experimental fidelity and operational scalability. However, its effectiveness is fundamentally constrained by inefficiencies in emulating large-scale networks, particularly during virtual network construction. This bottleneck arises from mandatory serialization of virtual link instantiation and operating system (OS) kernel-level notification overheads, which collectively degrade performance by orders of magnitude on 10K-node topologies. Departure from the current practice that employs a multi-machine framework for improvements, we propose SplitNN (Split Network and Namespace), a novel single-machine network emulation paradigm that breaks the serialization constraint through multi-VM (virtual machines) partitioning, and reduces notification overheads via namespace segmentation. Extensive evaluations show that SplitNN constructs 10K-node virtual networks within 1–5 minutes on a single machine, achieving a 98.5%–99.2% reduction in construction time compared to state-of-the-art emulators. While primarily a single-machine solution, SplitNN seamlessly integrates with multi-machine deployments, complementing them by enabling cumulative gains in both scalability and efficiency. | 10.1109/TNSM.2026.3715559 |
| Qing Wu, Xijia Dong, Leyou Zhang, Yue Lei, Zilong Yan | Cloud-Assisted Verifiable and Updatable Private Set Union Protocol for Enhancing Network Intrusion Detection | 2026 | Early Access | Protocols Clouds Security Privacy Cloud computing Timing Receivers Modeling IP networks Servers Network Intrusion Detection IP Blacklist Privacy Preservation Private Set Union Cloud Computing Verifiability Updatability | As network intrusion detection systems (NIDS) play an increasingly critical role in large-scale network environments, multiple organizations, Internet Service Providers (ISPs), and security service providers often maintain independent IP blacklists. Due to the dynamic nature of malicious IP addresses and their cross-organizational propagation, inter-organizational blacklist sharing is essential for improving network intrusion detection. However, traditional blacklist exchange mechanisms risk exposing participants’ complete blacklist information, and curious organizations may infer another organization’s detection strategies from the shared IP intersection, leading to privacy breaches.To address this issue, this paper proposes a Cloud-Assisted Verifiable and Updatable Private Set Union (CVU-PSU) protocol, which leverages the multi-query Reverse Private Membership Test (mq-RPMT) protocol and Oblivious Transfer (OT) technology to ensure privacy-preserving inter-organizational blacklist sharing. The protocol utilizes cloud computing to reduce the computational and communication overhead of participants in the mq-RPMT protocol while incorporating a verification mechanism to ensure the correctness of the cloud’s returned results. Furthermore, the protocol supports real-time blacklist updates, enabling adaptation to rapidly changing malicious IP addresses.Experimental results demonstrate that the proposed protocol achieves efficient inter-organizational blacklist sharing with low communication and computational costs while preserving privacy, thereby enhancing the real-time performance and accuracy of network intrusion detection systems. | 10.1109/TNSM.2026.3716071 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Masoumeh Safkhani, Mohammad Reza Servati, Fatemeh Rezaei | HEIoT: A Novel Three-Factor Authentication Protocol for Enhanced Security in IoT and Next-Generation Networks | 2026 | Early Access | Authentication Internet of Things Protocols Security Smart devices Elliptic curve cryptography Modeling Error correction codes Biometrics Costing of Yuan et al.’s Protocol Authentication Multi-factor authentication Desynchronization attack Insider adversary Traceability attack User impersonation attack Elliptic Curve Cryptography (ECC) | The Internet has a significant impact on contemporary society, enabling a wide range of applications, including advanced cellular networks such as 4G, 5G, and 6G. Since these communications occur over shared or open channels, ensuring secure data exchange is of critical importance, as any weakness in the communication infrastructure may compromise system reliability. Device authentication in the Internet of Things (IoT) and user authentication in smart environments, such as smart homes, remain fundamental security challenges. As the first line of defense, authentication mechanisms must be robust, since vulnerabilities at this stage can expose the entire system to serious threats. To address these challenges, numerous authentication schemes based on cryptographic primitives, including Elliptic Curve Cryptography (ECC), have been proposed. In this paper, we present a comprehensive security analysis of an ECC-based three-factor authentication protocol proposed by Yuan et al. Our analysis shows that the protocol is vulnerable to desynchronization, user impersonation, traceability, and insider attacks, all of which succeed with probability 1 by exploiting at most two protocol phases. To mitigate these weaknesses, we propose an improved authentication scheme, called HEIoT. The proposed scheme is formally analyzed under the Real-or-Random (RoR) model to establish session-key security and is further verified using the Scyther tool. Moreover, a Python-based implementation is provided to demonstrate the practicality of the proposed protocol. Comparative results indicate that HEIoT achieves stronger security while maintaining acceptable communication, computational, and storage overhead. | 10.1109/TNSM.2026.3702041 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Wei Sai, Yihui Lu, Xin Guo | A Privacy-Preserving Security Framework for Multi-Party Data Fusion Computing Based on Homomorphic Encryption | 2026 | Early Access | Security Protocols Information rates Modeling Throughput Noise Multi-party computation Polynomials Federated learning Homomorphic encryption Homomorphic Encryption Secure Multi-Party Computation Threshold Decryption Privacy-Preserving Data Fusion Decentralized Computing Framework | To prevent plaintext exposure in multi-party collaborative computing, this paper proposes a distributed secure multi-party computation protocol based on the Cheon-Kim-Kim-Song (CKKS) homomorphic encryption scheme. Data is encoded and encrypted at the source into CKKS complex polynomial ciphertext, enabling vectorized fusion under shared evaluation keys and threshold decryption in a decentralized architecture without a trusted central authority. Experiments on heterogeneous multi-institution datasets demonstrate low numerical error (9.0×10⁻⁷ at polynomial order 2¹⁶ and depth 12), effective scalability (throughput increasing from 1.12×10⁵ to 1.32×10⁵ ops/s and latency decreasing from 56 ms to 38 ms as nodes scale from 4 to 16), and strong robustness (70% decryption success at a 60% threshold and 95% recovery under malicious interference), showing that the framework achieves efficient computation with strict privacy protection for cross-party data fusion. | 10.1109/TNSM.2026.3717343 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 | |
| Ping He, Yu Yao, Xu Li, Yao Hu, Wei Yang | FIGAN: Diversity-Oriented Traffic Generation for Industrial Protocol Format Inference | 2026 | Early Access | Protocols Modeling Fuzzing Sequences Sequential analysis Industrial control Computers Syntactics Conferences Integrated circuits Communication system traffic Data Augmentation Generative Adversarial Networks Industrial control Inference algorithms | Protocol Format Inference is a pivotal step in the reverse engineering of proprietary protocols, yet its effectiveness is constrained by the scarcity of high-quality training data. In industrial control systems, the rigid and cyclical nature of traffic results in a "long-tail" distribution, where diverse functional scenarios are severely underrepresented. Existing generative approaches, primarily designed for fuzzing or intrusion detection, fail to resolve the intrinsic conflict between syntactic validity and semantic diversity required for protocol format inference. To bridge this gap, we propose FIGAN, a stage-wise decoupled generative framework tailored to synthesize high-fidelity traffic for protocol format inference. By isolating flexible distribution learning from rigid syntax enforcement, FIGAN liberates the generative process to extrapolate novel payload variations from a continuous latent space, effectively surmounting the limitations of sparse seed data. Specifically, the framework integrates three synergistic modules: first, heuristic pre-processing that constructs semantic templates as a prior knowledge base; second, a generative adversarial architecture optimized via discrete relaxation to explore high-dimensional payload patterns independently of syntax rules; and finally, a closed-loop verification mechanism that performs syntactic calibration and functional validation against simulated device responses. Evaluations on four real-world protocols (Modbus TCP, S7Comm, Omron FINS, and DNP3) demonstrate that FIGAN significantly outperforms state-of-the-art baselines. The source code has been open-sourced https://github.com/MissHP111/FIGAN. | 10.1109/TNSM.2026.3717268 |
| Alessandro Buratto, Marco Levorato, Leonardo Badia | DCP: a TCP-Inspired Domain Adaptation in Dynamic Data Drift | 2026 | Early Access | Modeling Timing Costing Costs TCP Internet of Things Linear approximation Q-learning Protocols Licenses Online Domain Adaptation Data Drift TCP Edge computing Internet of Things | Mobile devices are affected by computing limitations, battery life, and connectivity issues, making it difficult to execute complex machine learning models or frequently transmit data. These challenges hinder real-time adaptability in dynamic environments. To tackle these issues, we introduce a framework between mobile devices and edge servers, where the edge server assists mobile devices by continuously fine-tuning a lightweight classifier to keep up with changes in data patterns. Our approach, called the Drift Control Protocol (DCP), is inspired by how TCP manages network congestion. Just as TCP interprets packet loss as network congestion and throttles transmission, DCP treats spikes in classification error as congestion and implements an additive increase multiplicative decrease mechanism to dynamically control the frequency of model retraining, optimizing the trade-off between the classifier update rate and the communication overhead with the edge server. It dynamically adjusts the update frequency based on how the data distribution shifts and controls how many samples the mobile device sends to the edge server, while improving overall accuracy. We test different versions of DCP on both synthetic and real-world datasets. Our results show that DCP procedures obtain better tradeoffs in mean error and communication costs when compared with constant interval updates policies.We demonstrate this capability across real-world data and parametrized synthetic datasets explicitly designed to simulate both bursty and gradual drift scenarios. | 10.1109/TNSM.2026.3719234 |
| Yang Wu, Xu Cheng, Wenguang Zheng, Yingyuan Xiao | A Geo-Aware Personalized Network for User and Service Representation and Bilinear Interaction Modeling in QoS Prediction | 2026 | Early Access | Modeling Quality of service Matrices Modules (abstract algebra) Head Timing Web services Accuracy Educational institutions Learning (artificial intelligence) QoS prediction personalized representation learning bilinear interaction deep learning service recommendation | With the rapid growth of the Internet, the proliferation of functionally similar web services has made Quality of Service (QoS) prediction, which measures service performance, increasingly critical. In QoS prediction, the QoS values observed from user-service invocations are often significantly affected by their geographical location. However, existing QoS prediction methods typically assume static user and service representations, overlooking geographic differences. We argue that even the same user or service should have personalized representations based on different geographic locations. To address this, we propose GeoPerNet, a Geo-Aware Personalized Network for QoS Prediction. Specifically, we design the Geographical Aware Personalization Module, which models the geographical similarity between users and services to select the most relevant top-k neighbors for the target user or service. We then apply geographic similarity-based weighting to highlight key neighbor information. Next, we leverage the designed GeoTransformer to model the complex dependency relationships among neighbors. Finally, the refined neighbor representations are fused with the original embeddings to generate personalized user and service representations. Additionally, we design the Bilinear Interaction Module to capture fine-grained interaction relationships between users and services using a bilinear function. Experiments on the large-scale WS-DREAM dataset demonstrate that GeoPerNet outperforms state-of-the-art approaches. | 10.1109/TNSM.2026.3719697 |
| Anselme Ndikumana, Kim Khoa Nguyen, Oscar Delgado, Adel Larabi, Mohamed Cheriet | Empowering Rural Areas with Energy-Efficient 5G IAB-Based Fixed Wireless Access Network | 2026 | Early Access | Resource management 5G mobile communication Modeling Timing Rural areas Optimization Joining processes Transformers Bandwidth Energy consumption 5G fixed wireless access integrated access and backhaul energy efficiency rural areas | Fixed Wireless Access (FWA) has recently emerged as a cost-effective alternative to optical fiber in rural areas, particularly where fiber deployment is economically infeasible. To extend coverage and increase capacity, FWA networks have begun to integrate Integrated Access and Backhaul (IAB) with mid- and high-band spectrum. However, the energy consumption of multi-hop IAB networks scales significantly with the number of hops, a challenge that prior research has not adequately addressed. This paper proposes an energy-efficient framework that minimizes network energy consumption by maximizing Resource Block (RB) utilization while avoiding both over- and under-allocation in multi-hop IAB-based FWA deployments. The proposed method jointly allocates RBs and selects modulation and coding schemes across a mixed set of 5G numerologies to satisfy data rate requirements while minimizing energy consumption. The inherent dynamic interactions among IAB stations render the problem highly complex and non-convex; therefore, we design a disciplined multi-convex programming supported by dynamic programming algorithms to obtain tractable solutions. Furthermore, we introduce a transformer-based prediction to forecast RB distribution, thereby mitigating the need for frequent short-timescale coordination among IAB stations. Our simulation results demonstrate that the proposed approach achieves the required data rates while reducing energy consumption by 14%. | 10.1109/TNSM.2026.3719631 |
| Behrooz Farkiani, Fan Liu, Ke Yang, John DeHart, Jyoti Parwatikar, Patrick Crowley | Hermes: A General-Purpose Proxy-Enabled Networking Architecture | 2026 | Vol. 23, Issue | Tunneling HTTP Joining processes Planing IP networks Internet TCP Architecture Computer architecture Servers Overlay networking proxy HTTP architecture tunneling service delivery MASQUE NDN Envoy | We introduce Hermes, a general-purpose networking architecture that aims to improve service delivery over the Internet. Hermes delegates networking responsibilities from applications and services to proxies and is designed as a portable, adaptable solution to four fundamental challenges of efficient service delivery over the Internet: end-to-end traffic management, backward compatibility, data-plane security and privacy models, and adaptable communication layers. The design centers on an overlay of reconfigurable proxies and HTTP tunneling and proxying techniques, utilizing assisting components to extend proxy functionality when needed. Through prototyping and emulation, we demonstrate that Hermes improves key performance metrics across multiple use cases: it provides backward compatibility through protocol translation and tunneling, improves reliability by delegating retry logic to proxies, enables unified policy-based Layer 3 routing across network segments, and serves as an efficient substrate for future architectures like NDN, facilitating their operation over the Internet. Beyond evaluating Hermes across various use cases, we measured the overhead of Hermes’ HTTP tunneling and proxying mechanisms and found it to be modest, typically under 2 ms per proxy pair traversal in an isolated collocated setup. Although the HTTP proxying and tunneling techniques used by Hermes increase single-connection processing overhead, we also show that, with up to 1,000 concurrent requests, proxies can amortize connection setup time and reduce end-to-end latency by utilizing connection pooling and multiplexing. | 10.1109/TNSM.2026.3705327 |
| Mohamed Seliem, Utz Roedig, Cormac J. Sreenan, Dirk Pesch | M-FRER: A Multi-Connectivity Framework for Reliable and Deterministic 5G–TSN Integration | 2026 | Vol. 23, Issue | Legs Modeling 5G mobile communication Timing Costing Costs Correlation Probability Telemetry Planing Time-sensitive networking FRER 5G multi-connectivity deterministic wireless industrial networks | Achieving ultra-reliable communication under strict end-to-end latency constraints in integrated 5G–TSN systems requires fault-tolerant mechanisms that extend beyond single-leg wireless transmission. Existing approaches that extend IEEE 802.1CB Frame Replication and Elimination for Reliability (FRER) to 5G through redundant PDU sessions or dual connectivity remain restricted to two-leg redundancy, lack correlation awareness, and operate under static replication policies. This paper proposes M-FRER, a multi-connectivity extension of FRER that enables replication and elimination across $M$ heterogeneous connectivity legs, including multi-RAT, multi-PDU session, and non-3GPP access. M-FRER introduces (i) a correlation-aware reliability model that captures shared-risk dependencies between legs, and (ii) an adaptive replication controller that selects the active replication set while minimizing bandwidth, energy, and control overhead. Evaluations combining trace-based latency modeling with analytical reliability bounds under correlation show that M-FRER achieves five-nines on-time reliability ( ${\geq}99.999$ %) with only a modest bandwidth increase relative to dual-connectivity replication, while maintaining bounded jitter through controlled elimination windows. These results indicate that deadline-compliant communication over stochastic wireless media is achievable when redundancy and control are jointly optimized, positioning M-FRER as a scalable foundation for TSN-integrated industrial 5G deployments. | 10.1109/TNSM.2026.3705859 |
| Kai Chen, Guangjie Liu, Jiangtao Zhai, Weiwei Liu, Yuewei Dai | SSH–CAM: Fine-Grained SSH Behavior Identification in Encrypted Tunnel Traffic Using Curriculum-Adaptive Mixup | 2026 | Vol. 23, Issue | Tunneling Modeling Interference Cams Computer aided manufacturing Training Fluid flow Labeling Protocols Prototypes SSH behavior identification encrypted tunnel curriculum learning Gaussian prototype | Encrypted tunneling mechanisms are widely deployed for privacy protection and secure communication, while also obscuring application-layer semantics, making fine-grained traffic analysis more challenging. When Secure Shell (SSH) traffic is encapsulated within encrypted tunnels, multiple internal behaviors can coexist within a tunneled flow, such that traffic captured at a tunnel observation point rarely corresponds to a single behavior. Existing tunnel analysis methods focus on protocol- or application-level identification and are not designed for fine-grained SSH behavior identification under complex tunnel scenarios. We present SSH-CAM, a curriculum-guided framework for inferring the dominant SSH behavior at encrypted tunnel observation points, robust to the presence of coexisting interfering behaviors within the captured traffic. SSH-CAM constructs packet-level representations that capture both structural attributes and temporal information, followed by sequence-level feature extraction. A Curriculum-Adaptive Mixup mechanism is introduced to gradually increase training difficulty through controlled structural interpolation. The framework also imposes a learnable Gaussian prototype constraint on the latent representations, fostering intra-class compactness and greater inter-class separation under significant interference. Experiments conducted on a dataset constructed from six widely used tunneling protocols demonstrate that SSH-CAM consistently outperforms existing baselines across varying interference levels, showing robustness in highly mixed tunnel traffic scenarios. | 10.1109/TNSM.2026.3705758 |
| Dhiraj Bhattacharjee, Pablo G. Madoery, Abhishek Naik, Halim Yanikomerglu, Güneş Karabulut Kurt, Stéphane Martel | SQ-ROQ: A Scalable Framework for QoS-Aware Joint Routing and Queue Management in Satellite Mega-Constellations | 2026 | Vol. 23, Issue | Fluid flow Quality of service Satellites Routing Timing Aggregates Optimization Bandwidth Algorithms Joining processes Fairness low earth orbit Monte Carlo tree search queue management QoE QoS routing satellite mega-constellations | The modern Internet accommodates a wide range of applications with heterogeneous quality of service (QoS) requirements across multiple network performance metrics. Low Earth orbit (LEO) satellite constellations have emerged as a promising solution to support these diverse services, not only in rural and remote areas but also in urban environments as a complement to terrestrial networks. Ensuring QoS compliance in such networks necessitates the joint optimization of routing and queue management, as effective traffic handling is critical to maintaining performance guarantees across multiple flows. In this paper, we formulate a joint routing and queue management problem in which QoS requirements are treated as soft constraints, with the objective of maximizing end-user experience while maintaining fairness among competing traffic flows. Given the combinatorial and NP-hard nature of the problem, we propose SQ-ROQ, a computationally efficient framework that decomposes the network into multiple domains and employs a Monte Carlo tree search (MCTS)-based optimization strategy to jointly determine routing and queue management decisions. Using the Starlink Phase 1 Version 2 constellation as a case study, we conduct a comparative analysis of end-user experience and fairness. The proposed algorithm shows higher and stable end-user experience and fairness served to multiple traffic flows as compared to the benchmarks. Building on this, we further investigate the inherent trade-off between optimizing user experience and ensuring fairness, as well as the impact of varying traffic loads on the proposed algorithm and the benchmark schemes. Finally, we demonstrate the scalability of SQ-ROQ through a comparative evaluation of both theoretical time complexity and measured average computation time. | 10.1109/TNSM.2026.3705946 |
| Elie Inaty, Charbel Maroun, Ghattas Akkad, Ali Mansour, Martin Maier | A 6G-Driven Multiclass Power-Efficient Dynamic Bandwidth Allocation (MPE-DBA) Scheme for Passive Optical Network (PON) | 2026 | Vol. 23, Issue | Costing Costs Algorithms Bandwidth Optical network units Timing Delays Passive optical networks Schedules Scheduling DBA PON fuzzy logic multiclass traffic delay jitter power | The latest ITU IMT-2030 recommendations for sixth generation (6G) networks have imposed strict specifications on communication systems. Some of these requirements include increased throughput, ultra-low delay and jitter, differentiated services, and energy efficiency. Current dynamic bandwidth allocation (DBA) schemes for passive optical networks (PON) may meet some of these requirements, yet they fail to fulfill other recommendations, especially energy efficiency. Therefore, we propose a new PON architecture, whose objective is to offer flexibility in meeting the IMT-2030 recommendations. It uses a multiclass power efficient dynamic bandwidth allocation (MPE-DBA) scheme that helps achieving both differentiated services and sustainability in terms of energy and cost. For computational efficiency, we propose a two stages Mamdani Fuzzy Inference System (FIS). The inputs of the first FIS are the latency and cost of the 6G traffic, whereas the latency and cost of the non-6G (N6G) traffic are the inputs of the second FIS stage. Both FISs use the variation in the number of channels as output. The proposed algorithm achieves less than $100~\mu $ s delay, less than $10~\mu $ s jitter and high aggregate throughput for the 6G packets. In addition, it reduces the power consumption by three times and the cost of traffic transmission by four times as compared to the state-of-the art solution. | 10.1109/TNSM.2026.3694150 |