Last updated: 2026-09-14 05:01 UTC
All documents
Number of pages: 173
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Francisco Muro, Eduardo Baena, Tomaso De Cola, Sergio Fortes, Raquel Barco | AI-Driven Optimization of Virtual Network Function Allocation in 6G Non-Terrestrial Networks | 2026 | Early Access | Resource management Optimization Satellites Modeling Artificial intelligence Information rates Throughput Measurement 5G mobile communication Loading 6G Non-Terrestrial Networks O-RAN Kubernetes Virtual Network Functions VNF Allocation Machine Learning VNF Placement Gradient-Free Optimization Network Performance Resource Management | The integration of 6G technologies into Non-Terrestrial Networks (NTNs) raises a fundamental orchestration problem: how to allocate Virtual Network Functions (VNFs) across satellite and terrestrial domains under tight onboard resource constraints and a continuously changing topology. The virtualized 6G Open Radio Access Network (O-RAN) paradigm makes it possible to run 5G software stacks on Software-Defined Radios (SDRs) based on General Purpose Processors (GPPs), but it also turns VNF placement into a high-dimensional, multi-objective decision that static heuristics and model-based formulations struggle to capture. This paper addresses that gap by introducing an AI-driven VNF allocation framework for 6G-NTN environments built on an O-RAN-based distributed architecture and orchestrated on top of Kubernetes. The VNF allocation problem is formalized for a multi-domain 6G-NTN scenario with constrained satellite resources, and a measurement-based test campaign is designed to characterize the emulated platform in terms of virtual resource utilization and end-to-end performance. The framework couples tree-based machine learning predictors with a gradient-free optimizer to reach the optimal feasible allocation, outperforming two heuristic baselines drawn from the VNF placement literature by reducing the service RTT by up to 39% and delivering up to 3× higher YouTube DL throughput with respect to the best feasible heuristic. Beyond these gains, the proposed framework establishes a measurement-driven, reproducible methodology for VNF allocation in 6GNTN scenarios, demonstrating that AI-driven orchestration can systematically uncover non-obvious resource configurations that purely analytical or static approaches consistently miss. | 10.1109/TNSM.2026.3724474 |
| Xiaolong Cui, Xuebin Tang, Yuchen Wang, Xinyi Xu, Xiying Fan, Wei Huangfu | Aligning Routing with Service Intent in Logical Networks: A QoS-Driven Graph Attention Reinforcement Learning Framework | 2026 | Early Access | Routing Quality of service Optimization Measurement Delays Fluid flow Learning (artificial intelligence) Topology Modeling Jitter Logical Networks Intent-Aware Routing QoS-Aware Policies Homogeneous Traffic GAT | Network virtualization enables the creation of multiple logical networks on shared physical infrastructure, each supporting homogeneous traffic with a dedicated Quality of Service (QoS) objective. This shifts the routing problem from arbitrating among heterogeneous flows to holistically orchestrating traffic toward a single service intent. However, existing routing schemes, including those based on Deep Reinforcement Learning (DRL), lack mechanisms to align forwarding decisions with these high-level intents, leading to a performance gap. To bridge it, we propose QGARL, a QoS-driven Graph Attention Reinforcement Learning framework. Its core is an intent-conditioned attention mechanism that dynamically guides a DRL agent’s perception of the network graph based on the service’s QoS intent, enabling the learning of intent-aware routing policies without per-service algorithm redesign. Extensive experiments demonstrate that QGARL consistently outperforms state-of-the-art baselines in intent-weighted QoS utility across diverse services and topologies. This work establishes intent alignment as a guiding principle for routing in logical networks and provides a practical, learning-based framework to achieve it. | 10.1109/TNSM.2026.3731467 |
| Chenyu Zhao, Xin Li, Tianhao Liu, Shanguo Huang | Joint Design and Operation Phases Availability Evaluation for End-to-End Light-Paths in Optical Networks | 2026 | Early Access | Modeling Availability Lighting Protection Timing Design methodology Optical fiber networks Maintenance engineering Joining processes Telemetry Optical network light-path availability evaluation design and operation phases | The rapid growth of high-bandwidth services places stringent requirements on the availability of optical networks. Ensuring high availability in practice hinges on accurate and consistent evaluation of light-path availability in both the design and operation phases. To this end, this paper proposes a unified model for light-path availability evaluation in optical networks that couples an ensemble learning–based failure classifier with a Dynamic Bayesian Network (DBN). In the design phase, the model functions as a model-driven DBN whose transition probabilities are parameterized by historical failure and repair rates, supporting three-state (normal, soft failure, hard failure) modeling at component and path levels under different protection schemes. During the operation phase, the same DBN structure is driven by real-time observations inferred from monitoring data (e.g., input/output optical power) using ensemble learning-based classifiers. This enables the evaluation of instantaneous availability under limited measurement conditions. Furthermore, classification results are mapped to Conditional Probability Tables (CPTs) via confusion matrices to quantify the impact of classifier uncertainty on availability evaluation. Experimental results on a Kafka-based optical-network telemetry testbed show that, under the fault-event-based chronological split, XGBoost achieves an accuracy of 93.24% and a macro-averaged F1-score of 0.8183. Case studies involving different protection schemes and three representative network topologies show how backup end-to-end light paths affect availability and demonstrate the computational feasibility of the model across different network scales. Furthermore, it supports online availability updates and the identification of critical components. This work serves as a reference for optical network management and offers significant guidance for the future design of robust optical network systems. | 10.1109/TNSM.2026.3731278 |
| Hussein Fawaz, Jacopo Talpini, Marco Savi, Silvia Giordano, Omran Ayoub | Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty | 2026 | Early Access | Modeling Uncertainty Training Internet of Things Poles and zeros Radio frequency Signal detection Intrusion detection Machine learning Fluid flow Network Intrusion Detection Explainable AI Uncertainty Quantification Zero-day Attacks | In practical Network Intrusion Detection System (NIDS) deployments, detecting anomalies is only the first step, while determining the exact nature of those anomalies is equally important. Commonly, anomalous traffic is forwarded to a supervised multiclass classifier trained to identify known attack categories. While effective for known threats, this step presents a significant limitation, as zero-day attacks can be misclassified as known attacks. Therefore, there is a need for approaches that go beyond standard classification and can reliably recognize when an input does not conform to any learned attack pattern, i.e., zero-day attacks. To tackle this problem, we propose a novel detection strategy that leverages per-instance feature importance scores from an explainable Artificial Intelligence (XAI) framework and prediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experiments using a leave-one-attack-out strategy across three benchmark datasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, and test performance under two underlying classifiers, namely XG-Boost and Random Forest, demonstrating the model-agnostic nature of our method. Experimental results show that our approach achieves best-case AUROC gains approaching 40% and F1-score improvements of up to 73%, while maintaining positive or near-neutral worst-case performance across datasets, highlighting the effectiveness and robustness of jointly modeling explanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification. | 10.1109/TNSM.2026.3731401 |
| Wei Sai, Yihui Lu, Xin Guo | A Privacy-Preserving Security Framework for Multi-Party Data Fusion Computing Based on Homomorphic Encryption | 2026 | Early Access | Security Protocols Information rates Modeling Throughput Noise Multi-party computation Polynomials Federated learning Homomorphic encryption Homomorphic Encryption Secure Multi-Party Computation Threshold Decryption Privacy-Preserving Data Fusion Decentralized Computing Framework | To prevent plaintext exposure in multi-party collaborative computing, this paper proposes a distributed secure multi-party computation protocol based on the Cheon-Kim-Kim-Song (CKKS) homomorphic encryption scheme. Data is encoded and encrypted at the source into CKKS complex polynomial ciphertext, enabling vectorized fusion under shared evaluation keys and threshold decryption in a decentralized architecture without a trusted central authority. Experiments on heterogeneous multi-institution datasets demonstrate low numerical error (9.0×10⁻⁷ at polynomial order 2¹⁶ and depth 12), effective scalability (throughput increasing from 1.12×10⁵ to 1.32×10⁵ ops/s and latency decreasing from 56 ms to 38 ms as nodes scale from 4 to 16), and strong robustness (70% decryption success at a 60% threshold and 95% recovery under malicious interference), showing that the framework achieves efficient computation with strict privacy protection for cross-party data fusion. | 10.1109/TNSM.2026.3717343 |
| Martine S. Lenders, Carsten Bormann, Thomas C. Schmidt, Matthias Wählisch | A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPS | 2026 | Early Access | Internet of Things Encoding Internet Arrays Gain Recording Tagging Timing HTTP Decoding CBOR World Wide Web JSON DNS application/dns+cbor Internet measurements | The Internet community has taken major efforts to decrease latency on the World Wide Web with significant improvements in accelerating content transport and in compressing static content. Less attention, however, has been dedicated to compression of dynamic content. Such content is commonly provided by JSON and DNS over HTTPS. Dynamic content objects continue to grow in size, which increases latency and fosters the digital inequality. In this paper, we propose to mitigate this increase by utilizing Concise Binary Object Representation (CBOR), a standard originally designed for the constrained Internet of Things (IoT) to restrict packet sizes and enable efficient encoding of data objects. We provide protocol design and three new data sets for the evaluation of dynamic content, DNS, and the loading of websites. Our key findings are the following: (i) Switching the data representation from JSON to CBOR reduces data by up to 80%. This size reduction can decrease loading times by up to 13.8% when downloading large objects—even in local setups. (ii) Enabling CBOR for DNS over HTTPS (DoH) and DNS over CoAP (DoC) reduces packet sizes significantly. Compressing only names combined with unpacked CBOR achieves maximum gain of 52.2%, using more complex but still lightweight Packed CBOR allows minimizing packets by up to 95.5%. Our lean decoder for name compression can fit into as little as 314 bytes of build size. Our results clearly show the potential of CBOR outside of IoT scenarios. Parts of this research have already influenced work within the IETF. | 10.1109/TNSM.2026.3722114 |
| Mubashir Murshed, Glaucio H. S. Carvalho, Robson E. De Grande | Holistic Intelligent Traffic Steering Management in Multi-RAT Vehicular Networks | 2026 | Early Access | Radio access technologies Rats Vehicles Modeling Long short term memory Poles and towers 5G mobile communication Joining processes Timing Received signal strength indicator Traffic Steering Multi-RAT Network Management Bi-level GCN-LSTM SARSA High-mobility Ultra-dense networks | Multiple Radio Access Technology (multi-RAT) environments provide a promising foundation for service-aware communication in intelligent transportation systems (ITS) and smart cities. However, traffic steering (TS) in highly mobile and ultra-dense vehicular networks remains challenging due to dynamic network conditions, heterogeneous RAT capabilities, varying vehicle requirements, packet loss, latency, and frequent ping-pong RAT switching. In this context, we propose Holistic Intelligent Traffic Steering (HITS), a proactive bi-level TS management framework for multi-RAT vehicular networks. HITS integrates centralized network-wide guidance with local vehicleside decision-making. At the central level, a Graph Convolutional Network–Long Short-Term Memory (GCN–LSTM) model captures holistic spatio-temporal network dynamics and evaluates RAT optimality. At the local level, a State-Action-Reward- State-Action (SARSA) reinforcement learning agent performs adaptive, vehicle-specific RAT selection using local observations and central-level optimality guidance. Results show that HITS achieves up to 6.5% higher average throughput, reduces packet loss ratio by more than 30.2%, lowers latency by nearly 12.2%, and reduces the ping-pong RAT switching rate by over 24% compared with baseline and state-of-the-art (SoTA) TS approaches. | 10.1109/TNSM.2026.3729840 |
| Stephen Jasina, Loqman Salamatian, Joshua Mathews, Scott Anderson, Paul Barford, Mark Crovella, Walter Willinger | Matisse: Visualizing Measured Internet Latencies as Manifolds | 2026 | Early Access | Manifolds Internet Measurement Visualization Delays Distance measurement Joining processes Surfaces Timing Europe network internet measurement curvature manifold visualization | Manifolds are complex topological spaces that can be used to represent datasets of real-world measurements. Visualizing such manifolds can help with illustrating their topological characteristics (e.g., curvature) and providing insights into important properties of the underlying data (e.g., anomalies in the measurements). In this paper, we describe a new methodology and system for generating and visualizing manifolds that are inferred from actual Internet latency measurements between different cities and are projected over a 2D Euclidean space (e.g., a geographic map). Our method leverages a series of graphs that capture critical information contained in the data, including well-defined locations (for vertices) and Ricci curvature information (for edges). Our visualization approach then generates a curved surface (manifold) in which (a) geographical locations of vertices are maintained and (b) the Ricci curvature values of the graph edges determine the curvature properties of the manifold. The resulting manifold highlights areas of critical connectivity and defines an instance of “Internet delay space” where latency measurements manifest as geodesics. We describe details of our method and its implementation in a tool, which we call Matisse, for generating, visualizing and manipulating manifolds projected onto a base map. We illustrate Matisse with three case studies: a simple example to demonstrate key concepts, and visualizations of the US and Europe public Internet to show Matisse’s utility. | 10.1109/TNSM.2026.3730274 |
| Rita Ingabire, Antonio Bazco-Nogueras, Vincenzo Mancuso, Luis M. Contreras, Jesús Folgueira | Explainable AI to Understand the Latency Behavior of Public Cloud Service Platforms | 2026 | Early Access | Clouds Distance measurement Forecasting Measurement Modeling Probes Timing Cloud computing Internet Explainable AI explainability cloud latency RIPE Atlas forecasting comparative analysis measurement LIME SHAP | Cloud platforms have become a core component of the Internet because most services and products rely on them to host their backends. Estimating and understanding the latency experienced when accessing those cloud platforms is a challenge of growing importance that has not been sufficiently studied. To address this relevant matter, we conducted a three-month measurement campaign, collecting traceroute data every 30 min across 256 source–destination probe pairs. Our specific goal is to analyze whether the current network is able to provide adequate performance for emerging applications and services. We use this dataset to evaluate the performance of forecasting algorithms when predicting cloud latency from both temporal and spatial perspectives, and we leverage post-hoc explainability methods to identify the drivers affecting latency. Several prior studies provide public cloud-latency datasets, but these datasets are generally analyzed in isolation. To close this gap and provide a cross-dataset comparative analysis of cloud-latency measurements, we analyzed the related publicly available datasets and applied a common forecasting and explainability workflow to compare their findings. Our analysis reveals that operators do not require complex methods to predict latency and that distance and a few other simple features are sufficient to achieve operationally accurate predictions. We find latency to be remarkably stable from the user’s perspective, both over the duration of the campaign and across hours of the day, which contrasts with previous findings, and we show that the specific path traversed has a significant impact on latency. | 10.1109/TNSM.2026.3730351 |
| Bita Fatemipour, Zhe Zhang, Marc St-Hilaire | Adaptive Routing Optimization with Cost and Deadline Awareness Using Hierarchical Deep Reinforcement Learning | 2026 | Early Access | Costing Costs Routing Optimization Graph neural networks Timing Topology Joining processes Training Learning (artificial intelligence) Deep Reinforcement Learning Graph Neural Networks Optimization Traffic Engineering Wide-Area Networks Hierarchical RL Adaptive Routing | Timely and cost-efficient data transfers in large-scale networks remain challenging due to diverse topologies, non-uniform pricing models, and variable traffic demands. Existing literature often relies on multi-objective optimization, employing heuristic methods to reduce computational complexity; however, these approaches typically assume stable or predictable demand and struggle to scale effectively. Reinforcement Learning (RL) has been explored for its adaptability, yet many RL-based methods remain single-objective or topology-agnostic. This paper introduces CD-DRL, a hierarchical Deep RL framework that jointly optimizes transmission cost and deadline satisfaction, two objectives that often conflict in large-scale networks, through two cooperative agents. A routing agent, built on a Graph Neural Network, selects paths over a structured, multi-binary action space, enabling topology-aware routing across varying network scales and demand patterns. An adaptive tuning agent observes network state and recent performance to dynamically adjust the cost-deadline tradeoff to best fit current conditions. This hierarchical design allows CD-DRL to respond to dynamic network events such as congestion and bandwidth fluctuations, where no single fixed tradeoff remains optimal. We validate CD-DRL through extensive experiments on diverse backbone topologies and request distributions under static and time-varying network conditions. Compared with a state-of-the-art GNN-based RL method and traditional heuristics, CD-DRL improves the deadline-met ratio by up to 25% while maintaining competitive total cost and demonstrating strong scalability. Additionally, CD-DRL achieves faster execution time than mathematical optimization baselines, enabling high-throughput, latency-sensitive routing in dynamic environments. | 10.1109/TNSM.2026.3731031 |
| Pingping Dong, Liying Chen, Xuan Yao, Kai Wang, Lianming Zhang, Jiawei Huang | Fumer: Proactive Time-Shifting for Synchronized Periodic Traffic in Distributed Training | 2026 | Early Access | Training Timing Modeling Optimization Joining processes Bandwidth Synchronization Algorithms Educational institutions Windows Data center network Distributed training traffic RDMA | The growth of distributed training models, with parameters now reaching the billion-scale, has shifted the system bottleneck from computation to communication. While Remote Direct Memory Access (RDMA) is widely deployed to improve network performance by circumventing the kernel mechanism, the synchronization-computation cycles under the synchronous parallel mode introduce a highly synchronized and periodic “on-off” bursty traffic pattern, which poses significant challenges to data center networking. Consequently, distributed training suffers from two critical bottlenecks: instantaneous congestion during communication and persistent link idleness during computation. These issues lead to severe bandwidth contention and resource underutilization, ultimately hindering overall training efficiency. To address these challenges, this paper proposes Fumer, a proactive periodic traffic optimization framework that shifts the congestion control paradigm from reactive rate adjustment to proactive time-shifting. Specifically, Fumer leverages In-band Network Telemetry (INT) and Fast Fourier Transform (FFT) with signal-wave separation to decompose interleaved traffic signals, aiming to overcome the lack of periodic awareness. Furthermore, Fumer employs an off-peak transmission optimization algorithm to calculate optimal time-shift values, thereby tackling synchronized congestion and link idleness. By executing proactive off-peak scheduling, Fumer shifts overlapping communication windows into idle periods to smooth traffic peaks in the time domain. Experimental results show that Fumer boosts average path throughput across all workloads to 86.3 Gbps, improving upon DCQCN (42.6 Gbps) by 102.6% and RECC by 22.1%. Furthermore, it reduces the average and 99.9th-percentile iteration times by up to 25.0%-45.4% and 25.5%-49.3%, respectively, demonstrating its efficacy and robustness across diverse large-scale training workloads. | 10.1109/TNSM.2026.3728016 |
| Ren-Hung Hwang, Jiao-Chuan Huang, Yuan-Cheng Lai, Ying-Dar Lin | Reinforcement Learning Meets LLM Honeypots: A MITRE Engage–Aligned Approach | 2026 | Early Access | Large language models Modeling Training Design methodology Linux Reinforcement learning Windows Learning (artificial intelligence) Art Tuning Cyber deception honeypot reinforcement learning large language models MITRE ATT&CK MITRE Engage SSH | The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A finetuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline (p < 0.001). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux (p < 0.001), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety. | 10.1109/TNSM.2026.3731455 |
| Minhyeok Jang, Jalel Ben-Othman, Hyunchae Chun, Sungrae Cho, Hyunbum Kim | Multi-Agent Network Management with Dynamic Entropy-Driven Logistic Trust Aggregation | 2026 | Early Access | Entropy Modeling Management Detectors Labeling Learning (artificial intelligence) Poles and zeros Stability Accuracy Error analysis network management distributed intrusion detection multi-agent trust aggregation concept drift stability-agility trade-off entropy-driven adaptation | Autonomous network management increasingly fuses multiple heterogeneous detectors—such as the intrusion detectors that monitor different traffic planes for 6G and IoT security—through adaptive trust-weighted consensus. When trust is updated online, however, such systems face a fundamental stability-agility trade-off: they are either calm but slow to react to novel threats, or fast but erratic under routine noise. We identify and formalize the resulting failure modes of trust collapse and blind conformity, and propose DELTA (Dynamic Entropy-driven Logistic Trust Aggregation), a self-regulating trust-management framework. DELTA couples a Fixed-Share Redistribution regularizer, which guarantees a minimum trust quota for every detector, with an entropy-amplified logistic controller whose learning rate is driven by the current leader’s error rate and amplified by the ensemble’s structural entropy; this keeps the system quiescent under normal traffic yet triggers a rapid, bounded re-calibration the moment the trusted detector begins to fail. We prove that DELTA enforces a strictly positive diversity floor—making trust collapse provably impossible—and derive bounds on its transition latency and stationary volatility. Across an extensive evaluation—including robustness to delayed, missing, and adversarial feedback, comparison against expert-advice, Bayesian, and change-point baselines with confidence intervals, and validation on the real UNSW-NB15 intrusion dataset—DELTA recovers from zero-day regime shifts where naive baselines collapse below chance, while remaining an order of magnitude more stable than aggressive adaptive methods, all at O(N) computational and communication cost. | 10.1109/TNSM.2026.3731203 |
| Raeed Al-Sabri, Abdullatif Albaseer, Mohamed Abdallah, Ala Al-Fuqaha | DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning For Network Intrusion Detection | 2026 | Early Access | Modeling Intrusion detection Labeling Timing Fluid flow Graph neural networks IP networks Learning (artificial intelligence) Telecommunication traffic Matrices Network intrusion detection systems (NIDS) Security and privacy in networks Graph neural networks (GNN) Graph contrastive learning Multiscale contrastive learning | Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or noisy labeled data and struggle to detect threats at various scales, ranging from local anomalies (e.g., port scanning) to coordinated subnetwork attacks (e.g., botnets) and global network-wide campaigns (e.g., DDoS attacks). To bridge this gap, we propose Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels. At the node level, DMGCRL constructs structure-aware subnetworks around individual traffic flows to capture fine-grained behavioral deviations. For subnetwork-level threats, it employs substructure-aware pooling to identify coordinated anomalies among clustered malicious nodes. Finally, at the global level, DMGCRL derives representations that reflect the holistic state of the network, enabling detection of large-scale threats, such as distributed malware propagation. DMGCRL designs a shared GNN encoder with a multi-level contrastive loss to align multiscale representations while largely eliminating label dependence. It learns discriminative features from unlabeled traffic, refines decision boundaries without supervision, and reveals anomalies by contrasting related and unrelated nodes across scales. Performance evaluation was conducted on five publicly available network traffic datasets for binary and multiclass detection. Results show that DMGCRL consistently outperforms SOTA methods, achieving an F1 score of 99.86% on NF-CSECIC-IDS2018-V2 and 96.11% on NF-UNSW-NB15-V2 under binary detection and the lowest mean false positive rates, 1.28% and 2.33% under multiclass detection on the two datasets. | 10.1109/TNSM.2026.3726282 |
| Muhammad Muhammad Bala, Abdullahi Uwaisu Muhammad, Kamaluddeen Ibrahim Yarima, Aseel Smerat, Mulikatu Yakubu Ibrahim, Safiyanu Yahaya, Hamza Adamu | Isolation and Optimization Cost of Service-based Radio Access Network Slicing: A Smart-Contract-Based Approach | 2026 | Early Access | Network slicing Smart contracts Radio access networks Regional area networks Modeling Resource management Costing Costs Timing Joining processes Blockchain Network Slicing Service-based RAN Service-based Architecture | The service-based Radio Access Network (RAN) slicing enabled via Software Defined Networking (SDN) and Network Function Virtualization (NFV) can support diverse service requirements and address the rapid data traffic growth from both the vertical industry and the Internet of Things (IoT). However, network slice isolation and resource sharing between slices should be be improved for future wireless network requirements. Firstly, this paper address the isolation enhancement of future wireless networks through Blockchain-Smart-Contract, by creating two smart-contract-based access control to secure access to different service-based RAN applications and secure the sharing of resources. These contract are Verification and Authorization Contract (VAC), as well as Misconduct and Revocation Contract (MRC). The proposed framework is designed to support key 6G service classes, such as enhanced Mobile Broadband (eMBB) and ultra-Reliable Low-Latency Communications (uRLLC), enabling high data rates and low-latency communication. Secondly, to ensure the servicebased RAN achieves better isolation the optimization goal is to minimize the deployment cost to obtain the best deployment scheme. Hence, we divide the service-based RAN slice isolation deployment problem into two sub-problems, i.e., service-based RAN slice isolation and slice deployment problem, by formulating a Mixed Integer Linear Programming (MILP) model to minimize the deployment cost. Finally, to verify the feasibility of the design implementation an experimental platform is built and the results show the architecture achieves isolation enhancement through smart-contract and reduces the deployment cost by 78% and improve the isolation performance by 93% compared to the Blockchain-enabled Network Slice (BcNS) and the service-based RAN. | 10.1109/TNSM.2026.3732250 |
| Jianer Zhou, Xinyi Qiu, Zhenyu Li, Gareth Tyson, Encheng Yu, Weichao Li, Heng Pan, Xinyi Zhang, Zhiwei Xu | Themis: An Adjustable Congestion Control Framework for Improving Video QoE | 2026 | Early Access | Quality of experience Videos Fluid flow TCP Timing TV Servers Optimization Algorithms Bandwidth Video QoE Congestion Control eBPF | Optimizing congestion control algorithms (CCAs) has the potential to enhance video quality of experience (QoE). The goal of this work is to devise a congestion control framework that (i) ensures that individual users enjoy high video QoE, while (ii) minimizing variance, such that QoE is fairly distributed across all users, especially in fluctuating network, such as cellular network. We present Themis, a video-centric congestion control framework. Themis first uses a distributed approach to allocate a fair target QoE for each client. Based on this fair QoE, Themis then selects congestion control actions to optimize for video QoE (rather than throughput) based on application-layer signals provided by the client. Thus, rather than trying to maximize a flow’s (fair) share of bandwidth, Themis optimizes a flow’s share of the QoE budget. We evaluate Themis in both emulated and production networks. We show that in cellular network Themis achieves a 12.4% QoE improvement compared with BBR, and 37.1% QoE standard deviation decrease compared with the state-of-the-art, Minerva. | 10.1109/TNSM.2026.3732350 |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Yali Yuan, Yu Huang, Xingjian Zeng, Hantao Mei, Guang Cheng | M3S-UPD: Efficient Multi-Stage Self-Supervised Learning for Fine-Grained Encrypted Traffic Classification with Unknown Pattern Discovery | 2026 | Early Access | Labeling Modeling Electronic mail Training Peer-to-peer computing Timing Limiting Fluid flow Videos Conferences Encrypted network traffic multistage self-supervised learning unknown pattern discovery | The growing complexity of encrypted network traffic presents dual challenges for modern network management: accurate multiclass classification of known applications and reliable discovery of unknown traffic patterns. Although deep learning models show promise in controlled environments, their real-world deployment is hindered by data scarcity, concept drift, and operational constraints. This paper proposes M3S-UPD, a novel Multi-Stage Self-Supervised learning framework for encrypted traffic classification and unknown pattern discovery that synergistically integrates semi-supervised learning with representation analysis. Our approach provides a unified framework for known-class classification and unknown pattern discovery through a four-phase iterative process: 1) probabilistic embedding generation, 2) clustering-based structure discovery, 3) distribution-aligned outlier identification, and 4) confidence-aware model updating. Key innovations include a self-supervised mechanism for unknown pattern discovery that requires neither synthetic samples nor prior knowledge, and a continuous learning framework designed for reliable model updating. Experimental results show that M3S-UPD not only outperforms existing methods on the few-shot encrypted traffic classification task, but also simultaneously achieves competitive performance on the zero-shot unknown pattern discovery task. The code is available at https://github.com/fatmo666/M3S-UPD/. | 10.1109/TNSM.2026.3729337 |
| Deepak Kanneganti, Sajib Mistry, Sheik Mohammad Mostakim Fattah, Erik Elmroth, Aneesh Krishna, Monowar Bhuyan | Performance Drift Detection in Machine Learning as a Service (MLaaS) for IoT Environments | 2026 | Early Access | Modeling Signal detection Internet of Things Accuracy Monitoring Machine learning Human activity recognition Streams Training Electricity Machine Learning as a Service IoT Performance Drift Drift Detection Model Monitoring | Machine Learning as a Service (MLaaS) is a powerful cloud paradigm enabling data-driven intelligent applications in Internet of Things (IoT) environments, widely adopted across healthcare, smart homes, and industry due to its costeff-ectiveness. However, the dynamic nature of IoT frequently alters data distributions, affecting MLaaS stability, while periodic MLaaS updates further introduce performance drift. Unlike traditional ML systems, MLaaS clients operate as black-box users without access to internal data or parameters, making drift detection particularly challenging. To address this, we propose a novel MLaaS Performance Drift Detection framework for IoT environments. The framework first employs an MLaaS extraction model that learns service behavior from input–output pairs and identifies prediction-influenced features. Building on this, the proposed MLaaS Performance Drift Detection (MPDD) model jointly captures variations in input data and MLaaS behavior.We further design an Adaptive-Temporal Performance Drift Detection Mechanism (APDDM) that dynamically adjusts monitoring frequency based on behavioral and data variations, enabling timely drift detection for effective service management. Extensive experiments on real-world datasets demonstrate that MPDD achieves up to 22–25% accuracy improvement over baseline drift detection methods. APDDM provides an average accuracy gain of approximately 4% and reduces the miss detection rate by around 9% compared to fixed-interval monitoring. | 10.1109/TNSM.2026.3732372 |