Last updated: 2026-07-22 05:01 UTC
All documents
Number of pages: 169
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Tong Li, Shicheng Wei, Wencheng Yang, Yan Li | HotPatchCaps: A Capsule Network with Runtime Hot Patching for Zero-Day API Attack Detections | 2026 | Early Access | Modeling Application programming interfaces Security Signal detection Runtime Training Poles and zeros Labeling Conferences Routing API security Runtime defence Zero-day attack detection Capsule networks Hot patching | Modern services are awash in Application Programming Interfaces (APIs), yet most security pipelines end at predeployment testing using fuzzers and scanners. This leaves a runtime gap where payload obfuscation and other evolving request-visible misuse patterns outpace static rules and slow retraining cycles. We present HotPatchCaps, an expert-in-the-loop runtime framework that closes this gap by hot patching expert knowledge into a capsule architecture without retraining. HotPatchCaps fuses Term Frequency–Inverse Document Frequency (TF–IDF) statistics on request tokens with security cues such as parameter names, encodings, and payload substrings, and employs slot-controlled routing to amplify semantically relevant evidence into interpretable capsule activations. New rules arrive as lightweight runtime patches that can be injected on the fly, aligning with operational practice while preserving the generalization of learned models. We evaluated the CSIC 2010 dataset and the ATRDF 2023 dataset in both in-distribution and zero-day settings against classical machine learning (ML) and deep baselines. Experimental results demonstrate that HotPatchCaps consistently improves accuracy and recall at competitive precision and remains robust under label noise and schema drift. By turning expert knowledge into patchable capsule priors, HotPatchCaps provides a practical path from testing to on-call defence for API-centric systems. | 10.1109/TNSM.2026.3713465 |
| Zening Li, Pin-Han Ho | Topology-Constrained Generative Modeling for Performance Monitoring and Structural Anomaly Definition in Optical Transport Networks | 2026 | Early Access | Windows Modeling Semantics Aggregates Topology Propagation Observability Relays Signal detection Monitoring Optical transport networks performance monitoring partial observability anomaly detectability topology-constrained generative models window-aggregated statistics | Electrical-layer performance monitoring (PM) in optical transport networks is reported as window-aggregated counters, under which propagation delay and signal regeneration boundaries are not directly observable. Consequently, different impairment mechanisms can lead to statistically similar PM trajectories, leaving PM-only methods without a principled notion of nominal behavior or anomaly detectability. To address this limitation, this paper proposes Topology-Constrained Partially Observed Dynamical System (TC-PODS). TC-PODS defines a topology-consistent nominal predictive reference directly in PM space by introducing a latent impairment state (LAT) that enforces service-path propagation and regeneration semantics as supervisory constraints, while explicitly modeling the irreversible projection induced by windowed PM observation. This formulation disambiguates nominal variability from anomalous behavior under partial observability and defines anomalies as PM trajectories that are incompatible with any topology-consistent nominal generation. By shifting PM analysis from algorithm-centric detection toward detectability-aware inference under the deployed observation protocol, TC-PODS provides a principled framework for forecasting and anomaly interpretation under partial observability, with future applications to structure-aware failure management. | 10.1109/TNSM.2026.3715222 |
| Abdullatif Albaseer, Elmahdi Bentafat, Mohamed Abdallah, Saif Al-Kuwari, Marwa Qaraqe | Incentive-Driven Honeypot Defense: A Multi-Agent DRL Framework for Securing Smart Grid Networks | 2026 | Early Access | Pricing Timing Learning (artificial intelligence) Modeling Optimization Resource management Costing Costs Data integrity Training Smart Grid Security Honeypots Attack Rates Defense Data Stackelberg Game Deep Reinforcement Learning | Honeypot defenses present a robust solution for securing the Advanced Metering Infrastructure (AMI) against sophisticated cyberattacks. The efficacy of AMI defenses relies on the strategic deployment of honeypots by Small-scale Power Suppliers (SPSs) and the subsequent exchange of defense data with Traditional Power Retailers (TPRs). However, existing methods are limited by their requirement for prior information exchange and their inability to specify targeted services (i.e., protocols), making them impractical for dynamic environments. In addition, previous approaches have predominantly overlooked critical aspects such as service allocation and competition among SPSs. To address these challenges, we propose a novel Deep Reinforcement Learning (DRL)-based Stackelberg leader-follower game framework that facilitates tailored service allocation and fosters competition among SPSs. We leverage the Multi-Agent Deep Deterministic Policy Gradient (MADDPG) algorithm, which combines centralized training and distributed execution, to enable each SPS to autonomously learn optimal strategies that consider defense data quality and attack rates, without requiring prior knowledge of deployment costs or the actions of other SPSs. This adaptability minimizes the overhead associated with information exchange and improves the defense of vulnerable services. In particular, our method operates by requiring data collection, as each SPS functions as an independent learning agent that generates its own training experiences. Extensive simulations demonstrate that our proposed DRL-driven approach significantly outperforms baseline methods in different performance metrics. It achieves higher utility for both SPSs and TPR while maintaining lower operational costs. | 10.1109/TNSM.2026.3715400 |
| S A Harish, S Vignesh, Divya Pathak, Anil Kumar Sharma, Praveen Tammana | Anomaly Detection in In-Network Fast ReRoute Systems | 2026 | Early Access | Fluid flow Planing Delays Windows Signal detection Memory Anomaly detection Conferences Timing Testing In-network processing Anomaly detection Pro-grammable data planes Network security Software-Defined Networks P4 | High-speed programmable data planes provide opportunities to implement data-driven fast reroute systems that quickly adapt to varying network conditions (e.g., congestion, failures) and improve network performance. The core of these systems has packet-processing algorithms running in the data plane that continuously look for traffic patterns (e.g., too many retransmissions) specific to a network condition (e.g., link failure) and take appropriate action (e.g., reroute). Despite their benefits, they also increase the potential attack surface. Adversaries can generate malicious traffic patterns resembling those anticipated by a fast reroute system and trick the system. Doing so would lead to poor network performance due to incorrect reroute decisions. In this paper, we propose a mechanism to detect whether the fast reroute systems are under the influence of malicious traffic patterns. Our key idea is to model the expected behavior using benign traffic features and use the model as a reference to determine whether the system is under the influence of adversaries. Using realistic attack traces, we demonstrate attacks on two fast reroute systems and successfully detect those attacks using the proposed detection mechanism. | 10.1109/TNSM.2026.3715353 |
| Abdullah Othman, Georges Kaddoum, João V. C. Evangelista, Minh Au, Basile L. Agba | Joint Digital Twin Synchronization Scheduling and Resource Allocation for Post-Disaster Wireless Networks | 2026 | Early Access | Modeling Synchronization Cells (biology) Optimization Disasters Timing Interference Resource management Scheduling Schedules Digital twin post-disaster communications synchronization scheduling resource allocation successive convex approximation localization uncertainty | Digital twins (DTs) of wireless networks rely on accurate channel information to support resource allocation decisions. In post-disaster scenarios, the physical environment changes abruptly, rendering the DT’s pre-disaster channel model obsolete. Since restoring DT accuracy requires synchronization with the physical network through costly environmental updates, a fundamental tradeoff emerges between synchronization cost and decision quality. This paper formulates the joint optimization of DT synchronization scheduling, user–base station association, and uplink power control as a mixed-integer nonlinear program that maximizes the minimum user rate subject to synchronization budget and resource constraints. We decompose the problem into three subproblems solved via successive convex approximation and prove convergence of the alternating procedure to a stationary point. For the synchronization subproblem, we propose both a model-unaware formulation based on a coverage linear program requiring only user trajectory information, and a modelaware formulation that additionally exploits post-disaster channel knowledge to optimize the sync schedule for rate maximization. To characterize the impact of positioning uncertainty on the cell-based spatial model, we derive a closed-form expression for the cell-misclassification probability and develop a semi-analytical utility model that predicts the optimal grid resolution as a function of localization accuracy. The results of our simulations based on ray-traced channel data confirm that the proposed model-unaware sync closes 64–81% of the gap to the full-knowledge oracle across a range of system parameters, while the model-aware variant achieves 79–91% when post-disaster channels are available. The model-unaware approach thus exhibits the lowest sensitivity to DT model errors among all tested methods, making it the preferred choice when channel estimates are imperfect. | 10.1109/TNSM.2026.3714917 |
| Xiaolan Ji, Biao Han, Yuedong Xu, Jinshu Su | ICCP: Towards Congestion Control Agent via Controlling Logic Decoupling and Algorithm Integration | 2026 | Early Access | Algorithms Fluid flow Modeling Libraries Protocols Design methodology Information rates Throughput Stacking Kernel Congestion control Reinforcement learning Control plane Batch inference | To address the limitations of single congestion control algorithms (CCAs) in dynamic and heterogeneous network environments, selecting an appropriate algorithm from a pool of existing ones has become a widely adopted strategy. Existing mechanisms, however, are typically constrained by the Linux kernel’s unified abstractions, which limit the flexibility of selecting from a small set of in-kernel CCAs. Learning-based CCAs further increase the deployment cost because their inference logic is often compute-intensive and can block concurrent flows when executed within a synchronous control path. In this paper, we present ICCP, a unified congestion control framework that supports both heuristic and compute-intensive algorithms for concurrent flows. Rather than introducing a new reinforcement learning method, ICCP provides a three-layer, decoupled runtime framework consisting of the protocol stack, the user-space algorithm library, and the congestion control agent. ICCP uses asynchronous request handling, a shared proxy, and a “zero-copy” serialization-based RPC path to support both batch and single-inference modes with controlled communication overhead. We implement three distinct reinforcement learning-based congestion control algorithms within ICCP, including Sage, Orca, and DTCC, to evaluate the framework using representative compute-intensive CCAs. Simulations and real-world experiments demonstrate that ICCP maintains robust and efficient communication and inference performance as the number of concurrent flows increases. Overall, ICCP provides a practical runtime framework for integrating, evaluating, and deploying heterogeneous congestion control algorithms in multi-flow environments. | 10.1109/TNSM.2026.3714992 |
| Yali Yuan, Qianqi Niu, Yachao Yuan | Early-MFC: Enhanced Flow Correlation Attacks on Tor via Multi-view Triplet Networks with Early Network Traffic | 2026 | Early Access | Fluid flow Correlation Modeling Telecommunication traffic Timing Training Accuracy Modules (abstract algebra) Conferences Security Terms–flow correlation multi-view triplet network Tor | Flow correlation attacks are an efficient type of network attack, aiming to expose those who use anonymous network services, such as Tor. Conducting such attacks during the early stages of network communication is particularly critical for scenarios demanding rapid decision-making, such as cybercrime detection or financial fraud prevention. Although recent studies have made progress in flow correlation attacks techniques, research specifically addressing flow correlation with early network traffic flow remains limited. Moreover, due to factors such as model complexity, training costs, and real-time requirements, existing technologies cannot be directly applied to flow correlation with early network traffic flow. In this paper, we propose flow correlation attack with early network traffic, named Early-MFC, based on multi-view triplet networks. The proposed approach extracts multi-view traffic features from the payload at the transport layer and the Inter-Packet Delay. It then integrates multi-view flow information, converting the extracted features into shared embeddings. By leveraging techniques such as metric learning, the method optimizes the embeddings space by ensuring that similar flows are mapped closer together while dissimilar flows are positioned farther apart. Finally, Bayesian decision theory is applied to determine flow correlation, enabling high-accuracy flow correlation with early network traffic flow. Furthermore, we investigate flow correlation attacks under extra-early network traffic flow conditions. To address this challenge, we propose Early-MFC+, which utilizes payload data to construct embedded feature representations, ensuring robust performance even with minimal packet availability. Simulation results demonstrate that Early-MFC reduces packet requirements by 80% compared to the state-of-the-art DeepCoFFEA system, while Early-MFC+ maintains formidable attack efficacy even when constrained to only the first ten packets of each flow. | 10.1109/TNSM.2026.3714549 |
| Jorge Mirande, Tijani Chahed, Salah Eddine Elayoubi | Optimal transport of multimodal visual-haptic metaverse flows in the presence of eMBB traffic | 2026 | Early Access | Metaverse Resource management Enhanced mobile broadband Visualization Optimization Modeling Fluid flow Information rates Throughput Ultra reliable low latency communication Metaverse resource allocation 5G/6G | We study resource allocation for multiple metaverse users in 5G networks and beyond. To ensure an immersive experience, one should consider the multimodal nature of the metaverse, where each user generates multiple coupled flows, e.g., visual and haptic, characterized by joint Quality of Experience (QoE) requirements, for instance in terms of subjective Just Noticeable Difference (JND) metric. These flows can be transported via 5G services, such as Ultra Reliable Low Latency Communications (URLLC) for the haptic flow and enhanced Mobile Broadband (eMBB) for the visual one. Furthermore, the metaverse users share the radio resources with classical eMBB users. We formulate an optimization problem to maximize the weighted sum of visual throughput for metaverse users and the throughput of eMBB users relative to their minimum requirements, subject to fairness and feasibility constraints. Our approach accounts for discrete Modulation and Coding Schemes (MCS) and heterogeneous radio conditions. Numerical results show that our proposed scheme effectively balances throughput, fairness, and immersive-experience requirements, avoiding the feasibility violations observed under equal allocation and reducing immersive-constraint violations by approximately 19% with respect to a non-immersive baseline. We eventually make use of real haptic traffic traces to evaluate computation time and performance under varying haptic requirements. | 10.1109/TNSM.2026.3714067 |
| Huakun Huang, Longtao Guo, Lingjun Zhao, Qinglin Yang, Wensheng Zhang | Line-level Smart Contract Vulnerability Detection via Semantic-Syntactic Feature Extraction and Global-Local Attention Network | 2026 | Early Access | Signal detection Modeling Codes Smart contracts Syntactics Contracts Educational institutions Conferences Location awareness Training Blockchain Smart Contract Vulnerability Detection Vulnerability Localization Deep Learning | Smart contracts, a core component of Ethereum, automate the execution and management of transactions. However, potential vulnerabilities in smart contracts may trigger serious financial losses or even systemic risks. While existing vulnerability detection methods have achieved certain results, they are still deficient in the precision of line-level vulnerability localization and the breadth of supported vulnerability categories. Against this challenge, this paper proposes a line-level vulnerability detection method with semantic-syntactic feature extraction and global-local attention network. The method utilizes pre-trained model and abstract syntax tree to extract semantic-syntactic features of the code lines, and constructs multiple graph structures to realize the global feature representation of the contract. Based on that, the local network is responsible for extracting line-level features, the global network extracts structured global features, and the two are effectively fused through the attention mechanism. Experimental results show that the method achieves high accuracy and good generalization in the detection of multiple vulnerability categories, with an average F1-score of more than 98% for line-level detection and more than 96% for contract-level detection. This study improves the accuracy of line-level vulnerability detection and provides a valuable technical path for smart contract security research. | 10.1109/TNSM.2026.3714059 |
| Hailey Shakespear-Miles, Sima Barzegar, Marc Ruiz, Luis Velasco | Multi-Agent Autonomous 6G Service Control with Intelligent Reconfiguration | 2026 | Early Access | Modeling Training Delays Fluid flow Long short term memory Testing Probes Routing Timing Algorithms Multi-agent systems Flow routing Quality of service 6G Mobility | Future 6G services will require strict performance guarantees, especially in terms of delay, end-to-end (e2e) across multiple network domains including packet and radio segments. While deterministic transport and slice-based capacity allocation can improve segment-level performance, ensuring e2e Network Service (NS) performance remains challenging as it requires making decisions Near–Real-Time (Near-RT) on a per-service basis, which does not fit well within the typical centralized control and orchestration hierarchy. Multi-agent systems (MAS), where a number of distributed agents collaborate, has demonstrated its capabilities for such Near-RT control. Agents equipped with Deep Reinforcement Learning (DRL) engines autonomously made traffic routing decisions based on e2e telemetry measurements. In this paper, we extend such MAS solutions for NS traffic routing focused on covering several issues that appear under frequent NS reconfiguration, e.g., caused by end device mobility. In addition, we define a lifecycle for NS operation that includes the initial MAS deployment, model reconfiguration during operation, and NS reconfiguration. The proposed lifecycle requires the definition of DRL training and validation procedures to produce models ready to be deployed with guaranteed performance under certain network conditions. In addition, model selection algorithms are defined for the lifecycle scenarios. In case of NS reconfiguration, a procedure for probe testing the actual network conditions is proposed to improve model selection. Evaluation across a meaningful set of network and traffic scenarios shows that the MAS is able to maintain e2e delay guarantees under all the lifecycle scenarios. | 10.1109/TNSM.2026.3713972 |
| Mohammad Rasool Momeni, Abdollah Jabbari, Carol Fung | An Efficient, Secure, and Privacy-Preserving Communication Protocol for Drone-Assisted Disaster Management in Smart Cities | 2026 | Early Access | Drones Authentication Protocols Security Physical unclonable function Modeling Internet of Things Disasters Terminology Resistance Drone Smart City IoD-enabled Services Privacy Security Group Authentication | Drones (also referred to as unmanned aerial vehicles) have attracted significant attention within smart city ecosystems due to their ability to detect crises promptly and provide real-time support for disaster management services. However, the increasing risks of cyber and physical attacks, along with potential private data leaks, present substantial challenges to their deployment in smart city environments. In this paper, we propose a secure communication protocol that leverages a novel group authentication scheme (GAS), tailored for disaster management services in smart cities. The proposed scheme enables both group key agreement among drones and individual session key establishment between each drone and the control center (CC). Hence, our protocol preserves data confidentiality, message integrity, and data privacy, and verifies the authenticity of communicating parties. We employ physically unclonable functions (PUFs) and reverse fuzzy extractors to withstand critical threats, including physical attacks and machine learning (ML)-based modeling attacks. Our protocol also uses lightweight cryptographic primitives, such as hash-based message authentication codes (HMACs) and exclusive-OR (XOR) operations to ensure efficiency. Comprehensive security analysis using formal proofs and the Scyther tool demonstrates that the proposed scheme resists various attacks while preserving data privacy in IoD-enabled services. Ultimately, performance analysis results confirm that the proposed protocol is efficient and feasible. | 10.1109/TNSM.2026.3714291 |
| Peng Qi, Dan Tao, Ruipeng Gao | Enabling Service Monitoring in Industrial IoT: A Knowledge-Integrated Service Status Perception Framework | 2026 | Early Access | Modeling Industrial Internet of Things Evolution (biology) Modules (abstract algebra) Timing Decoding Production Topology Design methodology Knowledge graphs IIoT services service-aware IIoT Knowledge Graph service status inference model multi-scale feature embedding module multi-objective predictive-decoding module | The rapid proliferation of industrial IoT (IIoT) devices and services, driven by growing demands for smart manufacturing, has introduced unprecedented complexity in operational environments. This complexity frequently manifests as unanticipated service failures with significant economic consequences, necessitating advanced monitoring solutions. To address this challenge, we propose KISSP, a knowledge-integrated status perception framework tailored for IIoT services. First, we design a context-aware module—a service-aware IIoT Knowledge Graph—to systematically integrate both dynamic and static IIoT data. It employs an innovative three-layer architecture that hierarchically models event-service-device relationships. Then, we develop a situation inference module—a graph-based service status inference model—to capture the temporal evolution of service status. Specifically, we devise a spatio-temporal graph encoder coupled with a multi-scale feature embedding module, enabling robust extraction of spatio-temporal dependencies in service behavior. Finally, we propose a multi-objective predictive-decoding module. It consists of two parallel decoders, a next-step topology decoder for structural prediction and a next-step anomaly decoder for failure anticipation, which collectively enhances future service status monitoring. Experimental validation on datasets demonstrates the superior performance and effectiveness of our framework. | 10.1109/TNSM.2026.3713918 |
| Matheus Dória, Ricardo Silva, Carlos Lima, Daniel Luna, Allan Martins, Paulo Eduardo, Augusto Neto, Vicente Sousa | Open RAN KPI Monitoring: a Dynamic Energy-Aware Framework | 2026 | Early Access | Monitoring Open RAN Central Processing Unit Accuracy Measurement Key performance indicator 5G mobile communication Frequency Signal to noise ratio Optimization 5G Open RAN xApp E2 Energy saving | Open RAN emerged to break out of vendor lock-in constraints, enabling specialized control-plane applications with well-defined open and standardized interfaces. In a monitoring-oriented Real-Time Radio Access Network Intelligent Controller, xApps typically collect Key Performance Indicators (KPIs) at fixed intervals, which can overload the system when very frequent reporting is required. This paper introduces a new Open RAN KPI monitoring framework that outperforms fixed-interval solutions by dynamically adjusting the KPI collection timescale at runtime, using Risk Analysis of monitored KPI accuracy loss to balance monitoring needs and resource usage. A prototype built with OpenAirInterface and FlexRIC shows reduced E2 signaling overhead and significant energy savings. Extrapolating to large-scale scenarios, the framework demonstrates potential savings of up to 608.48 kWh per day (18,254.4 kWh per month), equivalent to an estimated reduction of 0.99 tons of CO2 emissions. | 10.1109/TNSM.2026.3713811 |
| Sanku Kumar Roy, Mohamed Samshad, Ketan Rajawat | UNet: A Generic and Reliable Multi-UAV Communication and Networking System Architecture for Heterogeneous Applications | 2026 | Early Access | Autonomous aerial vehicles Architecture Computer architecture Modules (abstract algebra) Protocols Joining processes Delays Distance measurement Timing Design methodology FANET Unmanned Aerial Vehicle UAV Communication Architecture Generic Heterogeneous Applications ad hoc Mesh Networking | The rapid growth of UAV applications necessitates a robust communication and networking system architecture capable of addressing the diverse requirements of various applications concurrently, rather than relying on applicationspecific solutions. This paper proposes a generic and reliable multi-UAV communication and networking system architecture designed to support the varying demands of heterogeneous applications, including short-range and long-range communication, star and mesh topologies, different data rates, and multiple wireless standards. Our architecture is designed for both ad hoc and infrastructure networks, ensuring seamless connectivity throughout the network. Additionally, we present the design of a multi-protocol UAV gateway that enables interoperability among various communication protocols to enhance connectivity. Furthermore, we introduce a data processing and service layer framework with a graphical user interface of a ground control station that facilitates remote control and monitoring from any location at any time. We practically implemented the proposed architecture and evaluated its performance using different metrics, demonstrating its effectiveness. | 10.1109/TNSM.2026.3715386 |
| Ci-Yi Hung, Li-Yu Yang, Li-Der Chou | LMM: A Reinforcement-Learning-Based Mitigation Mechanism of Lateral Movement in Kubernetes | 2026 | Early Access | Modeling Advanced driver assistance systems Containers Timing Probability Learning (artificial intelligence) Security Sequences Sequential analysis Training Lateral Movement Kubernetes Security Reinforcement Learning Markov Chain Event Tracking Dynamic Defense | With the growing adoption of microservices architecture, Kubernetes—while offering a variety of built-in security modules—remains vulnerable to lateral movement due to its highly interconnected network architecture and frequent misconfigurations in permission settings. This study proposes the Lateral Movement Mitigation (LMM) mechanism, which integrates event tracking, risk assessment, and reinforcement learning (RL) to enhance Kubernetes' defense against lateral movement. LMM leverages Falco with custom rules to capture container-level events and utilizes a high-order Markov chain to construct a transition probability matrix for estimating the likelihood of command sequences. These transition probabilities are then used for risk assessment and provided as input states to the RL agent. The RL agent selects mitigation actions based on recommendations from the MITRE ATT&CK framework, thereby dynamically strengthening Kubernetes' native security modules. Experiments show that LMM improves accuracy by 17.00% over Warp and F1-score by 23.30% over ADA in Kubernetes namespace bypass. In the Role-Based Access Control (RBAC) misconfiguration, LMM outperforms Warp by 18.53% in accuracy and 28.27% in F1-score. In terms of mitigation latency, LMM achieves up to 98.54% and 98.38% faster response times compared to Warp and ADA, respectively, demonstrating its effectiveness and real-time responsiveness. In summary, LMM combines monitoring, risk modeling, and automated decision-making to deliver an efficient and accurate proactive solution against lateral movement in Kubernetes. | 10.1109/TNSM.2026.3713179 |
| Weilin Wang, Xiaojing Fan, Huachun Zhou, Jingfu Yan, Aoran Huang | A Collaborative Mechanism for Edge-Offloading and Intelligent Intrusion Detection Services | 2026 | Early Access | Algorithms Security Training Timing Modeling Signal detection Resource management Servers Delays Learning (artificial intelligence) Mobile edge computing service collaboration intrusion detection deep reinforcement learning | Mobile edge computing (MEC) is a promising technology for supporting computing-intensive and delay-sensitive applications. The network operator can enhance users’ personalized service experiences by implementing advanced offloading solutions. However, existing schemes often overlook security risks posed by malicious users, and struggle to balance quality of service (QoS) and security capabilities. To this end, we propose a collaborative mechanism for edge offloading and intelligent intrusion detection services to optimize personalized service experiences for normal users at the task level. First, we introduce a new optimization model, Collaboration of Edge Offloading and Intelligent Intrusion Detection Services (CEOI2DS), tailored for MEC environments with malicious users, considering security decisions, resource allocation, and function placement decision-making steps. It aims to maximize the operator’s average long-term revenue while meeting QoS requirements and resource constraints, encouraging the operator to deliver optimal security capabilities while ensuring personalized QoS for users. Then, to tackle this problem, we design a Collaborative Three-Agent Deep Reinforcement Learning (CTADRL) algorithm. Three agents conduct collaborative training and decision-making by interacting with the MEC environment. They comprehensively analyze user requirements, risk probabilities, and network resource status to formulate optimal service policies, enhancing the overall experience for normal users. Experimental results demonstrate that under different user risk probabilities and computing resources, the proposed mechanism and algorithm exhibit better adaptability and stability regarding processing success rate and revenue. | 10.1109/TNSM.2026.3713143 |
| Lu Wei, Yong Yu, Jie Cui, Xianfeng Xie, Jing Zhang, Irina Bolodurina, Hong Zhong | Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing | 2026 | Early Access | Vehicles Delays Stability Optimization Modeling Resource management Clouds Edge computing Equations Timing vehicular edge computing deep reinforcement learning Lyapunov optimization task offloading | With the rapid growth of Vehicular Edge Computing (VEC) and Mobile Edge Computing, efficient task offloading is essential for enhancing the computing and communication capabilities in vehicular networks. However, many existing methods suffer from slow convergence, load imbalance, and instability in dynamic, latency-sensitive environments. To address these challenges, we propose MAPPO-Lyapunov (MAPPO-L), a multi-agent offloading framework that integrates Multi-Agent Proximal Policy Optimization (MAPPO) with Lyapunov optimization. MAPPO-L enables distributed coordination among vehicles, roadside units (RSUs), and cloud servers, minimizing delay, improving resource utilization, and ensuring long-term stability. Lyapunov theory transforms long-term stability into per-slot optimizations, while MAPPO ensures efficient policy learning. An adaptive exploration mechanism dynamically adjusts exploration rates based on network dynamics, accelerating convergence and stabilizing training. Extensive simulations with real-world data show that MAPPO-L maintains task completion rates above 80%, converges 25%–37.5% faster than baselines, and reduces training fluctuations to 2.3%. Ablation studies confirm the critical roles of location, channel, and queue information, validating the robustness of MAPPO-L in practical VEC environments. | 10.1109/TNSM.2026.3713305 |
| Jing-Yang Voon, Yao Chiang, Hung-Yu Wei | Resource Allocation and Container Scaling for Microservices in Multi-Cluster Edge Computing System | 2026 | Early Access | Resource management Optimization Delays Containers Modeling Edge computing Algorithms Central Processing Unit Routing Internet of Things Edge Computing Microservice Computational Offloading Resource Allocation Container Scaling | With the advent of the 6G era and the evolution of distributed systems, edge computing has become a pivotal architecture for deploying latency-sensitive, resource-efficient applications. In particular, the microservice architecture, characterized by modular and loosely coupled components, has gained significant traction for building scalable and maintainable applications at the network edge. However, deploying microservice-based applications in heterogeneous and geographically distributed Multi-Cluster Edge Computing (MCEC) environments presents critical challenges, especially in achieving efficient and scalable resource management. Although existing research has explored resource allocation and container scaling for microservice-based systems, most prior works consider container efficiency in isolation or within single-cluster or cloud-centric environments, without jointly addressing container-level efficiency, inter-cluster task offloading, and resource allocation in MCEC scenarios. To address this gap, we propose RACCOON, a request-offloading cascaded resource allocation algorithm tailored for microservice-oriented deployments in MCEC settings. RACCOON aims to minimize user-perceived service latency while optimizing overall resource utilization. Complementing this, we introduce RAS-CAL, a reinforcement learning (RL)-based container scaling mechanism that dynamically adjusts resource provisioning at the container level to further enhance system performance. Experimental evaluation shows that our approach consistently outperforms methods that address only resource allocation, only task offloading, or only container scaling, by jointly optimizing these dimensions to reduce end-to-end user-perceived latency and computational overhead. | 10.1109/TNSM.2026.3713212 |
| Dev Gurung, Shiva Raj Pokhrel | LLM-QFL: Distilling Large Language Model for Quantum Federated Learning | 2026 | Early Access | Modeling Federated learning Large language models Training Tuning Optimization Convergence Servers LoRa Machine learning Quantum Federated Learning Distillation Large Language Models | As Quantum Federated Learning (QFL) scales toward distributed quantum networks, managing heterogeneous resources and communication bottlenecks becomes a critical challenge. This research proposes LLM-QFL, an adaptive network service management framework that leverages Large Language Models (LLMs) to optimize the operational efficiency of QFL systems. We introduce a federated distillation method in which locally fine-tuned LLMs serve as autonomous network agents. These agents adaptively manage service parameters by: i) dynamically adjusting local computation intensity (optimizer steps) based on loss gradients, ii) performing variance-aware client selection to minimize network-wide heterogeneity, and iii) implementing intelligent early stopping criteria to conserve bandwidth. By serving as an orchestration layer, LLM-QFL provides a synergy between LLMs and quantum networking. Our contributions include: i) Adaptive Performance and Efficiency: Reducing idle computation and significantly cutting communication overhead; ii) Theoretical Rigor: Convergence guarantees of O(1/T) for the adaptive management protocol; and iii) Scalable Deployment: Implementing PEFT (LoRA/QLoRA) for resource-constrained quantum service nodes. | 10.1109/TNSM.2026.3712394 |
| Rania Farjallah, Bassant Selim, Brigitte Jaumard, Samr Ali, Georges Kaddoum, Jean-Michel Sellier | Maximum Entropy-Based Traffic Generation | 2026 | Early Access | Modeling Optimization Entropy Urban areas Machine learning Training Limiting Generative adversarial networks Timing Tuning Time Series dataset Maximum entropy principle Traffic Modeling Synthetic Traffic Generation | The development of machine learning models and algorithms for many communication network optimization problems has generated a huge need for realistic traffic data generators, as real-world traffic datasets remain very few, especially compared to their size. We therefore propose a novel traffic generation framework based on the Maximum Entropy Principle (MEP). It explicitly incorporates empirical statistical constraints, ensuring generated traffic closely mirrors the complex patterns found in real-world data. Using vehicle traffic datasets of the City of Calgary, we explore multiple distributional assumptions, namely Gaussian, exponential, and mixture models. Our results demonstrate that the Gaussian and the Gaussian mixture models consistently achieve superior performance, capturing diverse temporal fluctuations and intricate statistical behaviors inherent in urban vehicle traffic. This study not only highlights the effectiveness and flexibility of MEP-based models but also establishes them as robust, interpretable, and data-efficient alternatives to existing generative methods in traffic synthesis. | 10.1109/TNSM.2026.3712637 |