Last updated: 2026-09-15 05:01 UTC
All documents
Number of pages: 174
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Vinícius Gruske Domeles, Laura Rodrigues Soares, Jéferson Campos Nobre, Edison Pignaton De Freitas | An Energy Cost-Benefit Analysis of Client-Side VPNs on CPE Devices | 2026 | Early Access | Energy Licenses Nuclear facility regulation Protocols Virtual private networks Costing Costs Energy consumption Loading Measurement Energy Efficiency VPN Protocols Customer-Premises Equipment Network Security | The reduction of CO2 emissions and conscientious use of energy resources is one of the biggest current challenges. Computer networks and the Internet are no exception to the global necessity of reassessing current energy consumption paradigms, and security mechanisms are some of the most costly in the networking stack. In the other hand, Customer-Premises Equipment (CPE) devices at the edge of the Internet structure play a significant role in service provisioning and securing the connection of the customer. As such, the impact of standard security tools on the energy consumption profile of these devices should be studied in depth. In this context, this work evaluates the energy cost-benefit of client-side Virtual Private Networks (VPNs) implemented on commercial CPE devices. Through experimental measurement and precise instrumentation, both energy consumption and network performance across different traffic profiles are analyzed. The main finding is that the use of VPNs can reduce the energy efficiency of the CPE per megabyte transferred by half, even under moderate load, highlighting a significant energy overhead imposed by security mechanisms on edge devices. Furthermore, the study shows that the most suitable protocol depends directly on scenario-specific requirements. Finally, the study proposes comparative metrics, a device-protocol calibrated model and presents the future directions for assessing the energy impact of Software-Defined Wide Area Network (SD-WAN) architectures. | 10.1109/TNSM.2026.3733609 |
| Wei Sai, Yihui Lu, Xin Guo | A Privacy-Preserving Security Framework for Multi-Party Data Fusion Computing Based on Homomorphic Encryption | 2026 | Early Access | Security Protocols Information rates Modeling Throughput Noise Multi-party computation Polynomials Federated learning Homomorphic encryption Homomorphic Encryption Secure Multi-Party Computation Threshold Decryption Privacy-Preserving Data Fusion Decentralized Computing Framework | To prevent plaintext exposure in multi-party collaborative computing, this paper proposes a distributed secure multi-party computation protocol based on the Cheon-Kim-Kim-Song (CKKS) homomorphic encryption scheme. Data is encoded and encrypted at the source into CKKS complex polynomial ciphertext, enabling vectorized fusion under shared evaluation keys and threshold decryption in a decentralized architecture without a trusted central authority. Experiments on heterogeneous multi-institution datasets demonstrate low numerical error (9.0×10⁻⁷ at polynomial order 2¹⁶ and depth 12), effective scalability (throughput increasing from 1.12×10⁵ to 1.32×10⁵ ops/s and latency decreasing from 56 ms to 38 ms as nodes scale from 4 to 16), and strong robustness (70% decryption success at a 60% threshold and 95% recovery under malicious interference), showing that the framework achieves efficient computation with strict privacy protection for cross-party data fusion. | 10.1109/TNSM.2026.3717343 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Alexandros Zervopoulos, Konstantinos Oikonomou | Packet Delegation for Distributed Load Sharing in Service Function Chains: End-to-End Performance Analysis using Queuing Networks | 2026 | Early Access | Modeling Delays Loading Probability Simulation Algorithms Servers Fluid flow Timing Topology Network function virtualization service function chaining load sharing load balancing queuing networks | In Network Function Virtualization environments, centralized orchestration for load balancing often faces scalability limitations and high signaling overheads. To address this, packet delegation is investigated as a distributed load sharing mechanism where Virtual Network Functions (VNFs) autonomously monitor local congestion and probabilistically delegate excess traffic to peers without global coordination. While this localized decision-making enhances scalability and resilience, it introduces probabilistic and bursty traffic that challenges standard performance modeling. This paper proposes an analytical framework to estimate the end-to-end performance of Service Function Chains using queuing networks. The delegation process is modeled as a Markov-Modulated Poisson Process, and a burstiness-corrected Poisson approximation scheme is introduced to accurately capture the impact of traffic variability on downstream VNFs. Furthermore, an iterative fixed-point algorithm is developed to resolve the interdependencies between VNFs and estimate network-wide metrics. Simulation results validate the accuracy of these models, with the burstiness-corrected approximation outperforming a previously proposed Poisson approximation under certain conditions, which are investigated in this paper. The results highlight that packet delegation effectively mitigates local hotspots and improves system performance using only local state information, even when evaluated using a real network trace. | 10.1109/TNSM.2026.3733637 |
| Mandar Datar, Mattia Merluzzi | Balancing Costs and Utilities in Future Networks via Market Equilibrium with Externalities | 2026 | Early Access | Modeling Energy Resource management Zinc Central Processing Unit Optimization Clouds Energy consumption Costing Costs Green networking Fisher market market equilibrium Pigouvian pricing convex optimization Nash welfare | Today, wireless networks are shifting towards systems that also involve computing resources, distributed across edge and cloud facilities. As such, radio and computing aspects shall be balanced continuously, to maximize the utilities of Service Providers (SPs), users quality of experience and fairness, while guaranteeing energy and carbon footprint constraints among others. In this paper, we tackle the problem of communication and compute resource allocation under energy constraints, with multiple SPs competing to get their preferred resource bundle by spending a fictitious currency budget. We model the system as a Fisher market (FM), incorporating energy use and carbon output as market externalities. Building on this framework, we develop a low-complexity, market-equilibrium (ME) based solution that ensures high utility, meets energy constraints, and promotes fairness among providers. To make the proposed resource allocation scheme practically viable and scalable, we design an alternating direction method of multipliers (ADMM) based equilibrium learning algorithm that enables SPs to reach the ME in a decentralized fashion. Finally, we run numerical simulations to validate the effectiveness of the proposed allocation mechanism, also for a practical use case of edge image classification, as well as the convergence rates of the distributed algorithm when scaling the number of players. | 10.1109/TNSM.2026.3733169 |
| Jianer Zhou, Xinyi Qiu, Zhenyu Li, Gareth Tyson, Encheng Yu, Weichao Li, Heng Pan, Xinyi Zhang, Zhiwei Xu | Themis: An Adjustable Congestion Control Framework for Improving Video QoE | 2026 | Early Access | Quality of experience Videos Fluid flow TCP Timing TV Servers Optimization Algorithms Bandwidth Video QoE Congestion Control eBPF | Optimizing congestion control algorithms (CCAs) has the potential to enhance video quality of experience (QoE). The goal of this work is to devise a congestion control framework that (i) ensures that individual users enjoy high video QoE, while (ii) minimizing variance, such that QoE is fairly distributed across all users, especially in fluctuating network, such as cellular network. We present Themis, a video-centric congestion control framework. Themis first uses a distributed approach to allocate a fair target QoE for each client. Based on this fair QoE, Themis then selects congestion control actions to optimize for video QoE (rather than throughput) based on application-layer signals provided by the client. Thus, rather than trying to maximize a flow’s (fair) share of bandwidth, Themis optimizes a flow’s share of the QoE budget. We evaluate Themis in both emulated and production networks. We show that in cellular network Themis achieves a 12.4% QoE improvement compared with BBR, and 37.1% QoE standard deviation decrease compared with the state-of-the-art, Minerva. | 10.1109/TNSM.2026.3732350 |
| Ren-Hung Hwang, Jiao-Chuan Huang, Yuan-Cheng Lai, Ying-Dar Lin | Reinforcement Learning Meets LLM Honeypots: A MITRE Engage–Aligned Approach | 2026 | Early Access | Large language models Modeling Training Design methodology Linux Reinforcement learning Windows Learning (artificial intelligence) Art Tuning Cyber deception honeypot reinforcement learning large language models MITRE ATT&CK MITRE Engage SSH | The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A finetuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline (p < 0.001). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux (p < 0.001), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety. | 10.1109/TNSM.2026.3731455 |
| Hussein Fawaz, Jacopo Talpini, Marco Savi, Silvia Giordano, Omran Ayoub | Detecting Zero-Day Attacks via Reconstruction of Feature Influence and Model Uncertainty | 2026 | Early Access | Modeling Uncertainty Training Internet of Things Poles and zeros Radio frequency Signal detection Intrusion detection Machine learning Fluid flow Network Intrusion Detection Explainable AI Uncertainty Quantification Zero-day Attacks | In practical Network Intrusion Detection System (NIDS) deployments, detecting anomalies is only the first step, while determining the exact nature of those anomalies is equally important. Commonly, anomalous traffic is forwarded to a supervised multiclass classifier trained to identify known attack categories. While effective for known threats, this step presents a significant limitation, as zero-day attacks can be misclassified as known attacks. Therefore, there is a need for approaches that go beyond standard classification and can reliably recognize when an input does not conform to any learned attack pattern, i.e., zero-day attacks. To tackle this problem, we propose a novel detection strategy that leverages per-instance feature importance scores from an explainable Artificial Intelligence (XAI) framework and prediction uncertainty estimates derived from an ensemble classifier. To evaluate our approach, we conduct extensive experiments using a leave-one-attack-out strategy across three benchmark datasets, CICIoT2023, NF–TON–IoT, and CIC–DDoS2019, and test performance under two underlying classifiers, namely XG-Boost and Random Forest, demonstrating the model-agnostic nature of our method. Experimental results show that our approach achieves best-case AUROC gains approaching 40% and F1-score improvements of up to 73%, while maintaining positive or near-neutral worst-case performance across datasets, highlighting the effectiveness and robustness of jointly modeling explanation-driven reconstruction error and predictive uncertainty for reliable zero-day threat identification. | 10.1109/TNSM.2026.3731401 |
| Angelo Feraudo, Stefano Maxenti, Andrea Lacava, Leonardo Bonati, Paolo Bellavista, Michele Polese, Tommaso Melodia | xDevSM: An Open-Source Framework for Portable, AI-Ready xApps Across Heterogeneous O-RAN Deployments | 2026 | Early Access | Radio access networks Regional area networks Modeling Open RAN Artificial intelligence Timing Measurement Resource management Monitoring Stacking O-RAN xApp RIC Service Model 6G | Openness and programmability in the O-RAN architecture enable closed-loop control of the Radio Access Network (RAN). Artificial Intelligence (AI)-driven xApps, in the near-real-time RAN Intelligent Controller (RIC), can learn from network data, anticipate future conditions, and dynamically adapt radio configurations. However, their development and adoption are hindered by the complexity of low-level RAN control and monitoring message models exposed over the O-RAN E2 interface, limited interoperability across heterogeneous RAN software stacks, and the lack of developer-friendly frameworks. In this paper, we introduce xDevSM, a framework that significantly lowers the barrier to xApp development by unifying observability and control in O-RAN deployments. By exposing a rich set of Key Performance Measurements (KPMs) and enabling fine-grained radio resource management controls, xDevSM provides the essential foundation for practical AI-driven xApps. We validate xDevSM on real-world testbeds, leveraging Commercial Off-the-Shelf (COTS) devices together with heterogeneous RAN hardware, including Universal Software Radio Peripheral (USRP)-based Software-defined Radios (SDRs) and Foxconn radio units, and show its seamless interoperability across multiple open-source RAN software stacks. Furthermore, we discuss and evaluate the capabilities of our framework through four O-RAN-based scenarios of high interest: (i) KPM-based monitoring of network performance, (ii) slice-level Physical Resource Block (PRB) allocation control across multiple User Equipments (UEs) and slices, (iii) mobility-aware handover control, and (iv) an AI-based slice-isolation xApp that uses a LinUCB contextual bandit to tune perslice PRB quotas online, showing that xDevSM can implement intelligent closed-loop applications, laying the groundwork for learning-based optimization in heterogeneous RAN deployments. Finally, we characterize the runtime overhead of xDevSM under sustained high-rate E2 traffic, reporting indication processing latency, control round-trip time, delivery stability, and Central Processing Unit (CPU)/memory footprint of the xApp pod, and show that the framework operates well within the O-RAN Near-Real-Time (Near-RT) RIC control-loop budget. xDevSM is open source and available as a foundational tool for the research community. | 10.1109/TNSM.2026.3733344 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Rita Ingabire, Antonio Bazco-Nogueras, Vincenzo Mancuso, Luis M. Contreras, Jesús Folgueira | Explainable AI to Understand the Latency Behavior of Public Cloud Service Platforms | 2026 | Early Access | Clouds Distance measurement Forecasting Measurement Modeling Probes Timing Cloud computing Internet Explainable AI explainability cloud latency RIPE Atlas forecasting comparative analysis measurement LIME SHAP | Cloud platforms have become a core component of the Internet because most services and products rely on them to host their backends. Estimating and understanding the latency experienced when accessing those cloud platforms is a challenge of growing importance that has not been sufficiently studied. To address this relevant matter, we conducted a three-month measurement campaign, collecting traceroute data every 30 min across 256 source–destination probe pairs. Our specific goal is to analyze whether the current network is able to provide adequate performance for emerging applications and services. We use this dataset to evaluate the performance of forecasting algorithms when predicting cloud latency from both temporal and spatial perspectives, and we leverage post-hoc explainability methods to identify the drivers affecting latency. Several prior studies provide public cloud-latency datasets, but these datasets are generally analyzed in isolation. To close this gap and provide a cross-dataset comparative analysis of cloud-latency measurements, we analyzed the related publicly available datasets and applied a common forecasting and explainability workflow to compare their findings. Our analysis reveals that operators do not require complex methods to predict latency and that distance and a few other simple features are sufficient to achieve operationally accurate predictions. We find latency to be remarkably stable from the user’s perspective, both over the duration of the campaign and across hours of the day, which contrasts with previous findings, and we show that the specific path traversed has a significant impact on latency. | 10.1109/TNSM.2026.3730351 |
| Chen Jue, Yang Tiancheng, Rao Yirui, Qiu Xihe, Yan Fengting, Chen Shanshan, Jiang Xiaoyan | Snow Ablation Optimization Tackles Controller Placement Problem: Optimizing Propagation Latency and Load Balance in SDN | 2026 | Early Access | Loading Optimization Algorithms Software defined networking Topology Load management Timing Switches Modeling Radio access networks Software-Defined Networking Controller Placement Problem Propagation Latency Load Balance Snow Ablation Optimization | The Controller Placement Problem (CPP) is critical in multi-controller Software-Defined Networking (SDN), as controller placement and switch-controller mapping directly affect propagation latency and load balance. To address this problem, this paper introduces, for the first time, Snow Ablation Optimization (SAO) into CPP and develops three specialized algorithms, namely SAO-RPL, SAO-MLB, and SAO-OMO. SAO-RPL determines controller locations to minimize controller-switch latency, SAO-MLB dynamically adjusts switch-controller mappings to balance controller loads, and SAO-OMO jointly optimizes latency and load imbalance. Experiments on real-world network topologies show that SAO-RPL obtains near-optimal solutions with a maximum error of 0.45% relative to the global optimum and exhibits stable performance over 30 independent runs. SAO-MLB reduces the difference between the maximum and minimum normalized controller loads by at least 49.53% and maintains low run-to-run variability under different numbers of controllers. SAO-OMO reduces load imbalance by up to 36.57% while limiting the maximum latency increase to 1.34%, demonstrating an effective trade-off between propagation latency and load balance. | 10.1109/TNSM.2026.3733376 |
| Mohamed Anis Sakka, Fahdah Alalyan, Wael Jaafar, Rami Langar | FML-AD: A Federated Learning Framework with Meta-Model Refinement for Cyberattack Duration Prediction in 5G O-RAN | 2026 | Early Access | Modeling 5G mobile communication Open RAN Timing Signal detection Training Federated learning Fluid flow Transformers Jamming 5G Cyberattack Duration Prediction O-RAN Federated Learning Transformer Meta-Model Refinement | The emergence of fifth-generation (5G) and open radio access network (O-RAN) architectures has expanded the attack surface for cyber threats, creating an urgent need for enhanced and proactive mitigation strategies to ensure the preservation of quality of service (QoS), network reliability, and user data privacy in highly distributed and virtualized environments. In this context, we introduce FML-AD, a federated learning framework with meta-model refinement for adaptive attack duration prediction without centralizing raw training traffic. The proposed method combines a FLAD-trained Transformer for distributed temporal learning with an XGBoost-based second-level regression model that refines the initial predictions using controlled O-RAN testbed examples, thereby reducing prediction errors associated with the benchmark-to-deployment distribution shift. Extensive evaluation on the CICIoT2023 dataset shows that FML-AD improves prediction accuracy compared with conventional centralized and federated baselines. Furthermore, an evaluation on a controlled 5G O-RAN testbed involving ten TCP SYN and UDP flooding scenarios provides a proof-of-concept demonstration of the feasibility of the proposed post-detection prediction pipeline in the evaluated configuration. A separate exploratory transfer-learning assessment using 5G V2X radio-jamming scenarios and leave-one-scenario-out (LOSO) validation further examines whether the duration-prediction pipeline can be adapted to a different disruption mechanism under limited target-domain data. For the considered jamming configurations, several operating points in the early 3–5 sec range also produce favorable prediction results, providing preliminary evidence of transferability. | 10.1109/TNSM.2026.3731093 |
| Jesús F. Cevallos-Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini | TIGER: an open-source cyber-Threat Intelligence Game Environment for Reinforcement learning | 2026 | Early Access | Cyber threat intelligence Labeling Training Learning (artificial intelligence) Modeling Modules (abstract algebra) Timing Instant messaging Costing Costs Automated Cyber-Threat Intelligence Deep Reinforcement Learning Continual Learning Network Intrusion Detection | Open-source testbeds for intrusion detection and mitigation enable benchmarking the efficacy of machine-learningbased cyber-defensive systems under increasingly realistic, heterogeneous network scenarios. In this context, the open-world nature of network intrusion detection requires defences to use continual learning strategies to adapt pattern-matching to new attack classes. The cost of periodically fine-tuning pre-trained detectors is not only computational but also encompasses the broader Cyber Threat Intelligence (CTI) life-cycle, which involves collecting, analyzing, and processing raw data into actionable insights. For ML-driven defensive systems, such actionable CTI ultimately takes the form of curated, labelled traffic traces of novel attacks. However, the concurrent optimisation of these intelligence-gathering costs and defence effectiveness has received little attention from the research community. In this respect, this work presents TIGER, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyberdefence life-cycles. TIGER uses realistic network simulation software to model an active-learning game in which an agent learns to timely purchase CTI—abstracted in our environment as labelled samples of Zero-day attacks— to retrain its intrusion detection machinery on new attack patterns, while considering a constrained resource availability scenario. | 10.1109/TNSM.2026.3732249 |
| Xiaodi Wang, Yunwei Dong, Weizhi Meng, Meng Li, Yining Liu | Dropout-Tolerant Privacy-Preserving Aggregation for Federated Mobile Crowdsensing | 2026 | Early Access | Modeling Privacy Internet of Things Training Federated learning Accuracy Calcium Timing Silicon Security Mobile crowdsensing Federated learning Privacy preservation Dropout tolerance Homomorphic encryption | Federated Learning (FL) has emerged as a key enabler for privacy-preserving, decentralized sensing systems, giving rise to Federated Mobile Crowdsensing (F-MCS). A well-known bottleneck in such systems is the inefficiency of synchronous training, which stalls for all participants and is susceptible to stragglers in heterogeneous environments. Although asynchronous FL methods have been explored to alleviate this, they often introduce the critical issue of stale updates, which can degrade model convergence and accuracy. To simultaneously address the challenges of efficiency, staleness, and robustness, this paper proposes a novel Dropout-Tolerant Privacy Aggregation (DTPA) scheme for FL that operates without a trusted third party (TTP). Our solution leverages the distributed decryption feature of the lifted EC-ElGamal cryptosystem to enable secure, decentralized model aggregation. We further introduce an efficient worker selection algorithm to systematically reduce waiting time. Moreover, a dedicated dropout-tolerant mechanism is developed to maintain protocol execution even under a high rate of client failures, thereby enhancing robustness. Security analysis confirms that our scheme fulfills essential privacy and security requirements. Extensive simulations demonstrate that the proposed DTPA scheme significantly improves training efficiency and convergence stability compared to state-of-the-art methods, while remaining practical for deployment on resource-constrained mobile devices. | 10.1109/TNSM.2026.3732465 |
| Siyu Jiang, Feng Guo, Di Chen, Yuan Liu, Ying Chen, Weijun Sun, Yu Wang, Shen Su | Smart Contract Vulnerability Detection via Mask Consistency with Dynamic Margin Adjustment | 2026 | Early Access | Labeling Modeling Smart contracts Signal detection Codes Contracts Learning (artificial intelligence) Training Educational institutions Conferences Smart contract vulnerability detection semi-supervised domain adaptation mask learning dynamic margin adjustment | With the rise of smart contract applications, new attacks that exploit contract vulnerabilities continue to emerge, and effective vulnerability detection methods are urgently needed. Deep learning-based methods have shown excellent performance. However, for new types of vulnerabilities, due to the lack of real labels to help the model learn subtle code differences, previous methods have difficulty distinguishing between vulnerable contracts and safe contracts with similar key code segments, resulting in false negatives. To address this problem, this paper proposes a smart contract vulnerability detection method that uses mask consistency (MC) and dynamic margin adjustment (DMA). Unlike traditional Masked Language Modeling (MLM) in CodeBERT that performs token-level reconstruction for general representation learning, our MC enforces classification-level consistency between a masked student network and an unmasked EMA teacher network at the semantic graph block level under semi-supervised domain adaptation. This enhances the model’s discriminative ability by adding contextual information of similar code segments as additional clues. Specifically, we define a student network to learn masked contracts, a teacher network to learn complete contracts, and implement few-shot learning through semi-supervised domain adaptation. In this process, the student network is helped to learn to correctly distinguish similar contracts by fusing contextual information. In order to guide students more effectively, we use DMA to screen high-quality pseudo-labels. We conduct extensive experiments on open source real-world vulnerability datasets, and the results show that our method significantly outperforms current mainstream deep learning methods in detecting six types of vulnerabilities. This approach also pioneers the application of domain adaptation and integrates MC with DMA in vulnerability detection, providing guidance for detecting different types of vulnerabilities. | 10.1109/TNSM.2026.3733072 |
| Wei Zhang, Shiyun Xiong, Yixin Li, Yan Lei, Hongyi Li | TCAA: An Efficient Blockchain Consensus Based on Transaction Collector and Address Aggregation for UAV Ad Hoc Networks | 2026 | Early Access | Synchronization Probability Autonomous aerial vehicles Algorithms Timing Receivers Proposals Nickel Complexity theory Bandwidth Blockchain UAV ad hoc networks consensus mechanism performance optimization | Blockchain technology provides a promising solution to data security and trust challenges in UAV ad hoc networks. However, conventional consensus mechanisms suffer from notable inefficiencies in resource-constrained environments, characterized by high computational and communication overhead, and prolonged consensus latency. To address these limitations, this paper proposes a blockchain consensus mechanism based on Transaction Collector and Address Aggregation (TCAA) for UAV ad hoc networks. We introduce a block proposal algorithm using a transaction collector, which dynamically assigns block proposal rights through a difficulty threshold. This threshold is defined by transaction types and quantities, thereby eliminating dependence on hash competition or voting verification. The block proposal algorithm operates in parallel with the gossip protocol, ensuring randomness in mempool transactions and unpredictability in proposer selection. Moreover, TCAA incorporates an encrypted address aggregation and recognition scheme to accelerate block synchronization. This scheme allows the block sender to proactively discern the state of the receiver’s mempool, which substantially reduces communication rounds and message redundancy across the network. We model the message synchronization process using a two-dimensional Markov chain and derive closed-form expressions for the end-to-end latency, bandwidth consumption, consensus latency, and transaction collection rounds. Experimental results demonstrate that for a block containing 1000 transactions and a RTT of 50 ms, TCAA reduces the end-to-end latency by 29.7%, 25.3%, and 22.9% compared to Compact, Graphene, and XThin, respectively, while achieving a communication complexity of 2n. | 10.1109/TNSM.2026.3732846 |