Last updated: 2026-09-10 05:01 UTC
All documents
Number of pages: 173
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Ahmed Rjiba, Hicham Lakhlef, Joachim Bruneau-Queyreix, Meriem Afif | Federated Learning in Fog Computing within IoT Environments: An up-to-date and comprehensive survey | 2026 | Early Access | Federated learning Internet of Things Edge computing Modeling Clouds Security Training Surveys Privacy Timing Internet of Things (IoT) Federated Learning (FL) Fog Computing (FC) Survey Digital Twin (DT) | The Internet of Things (IoT) connects diverse, resource-constrained devices, driving innovation in domains such as healthcare, smart cities, and industrial automation. However, the exponential growth of IoT devices poses critical challenges in data processing, privacy, security, and latency. Fog Computing (FC) mitigates these issues by decentralizing computational resources, processing and storing data locally to enable low-latency, high-quality services. This makes FC an ideal platform for integrating Federated Learning (FL), a decentralized machine learning paradigm that trains models locally on IoT devices and shares only aggregated updates, preserving data privacy. Since its introduction, FL has garnered considerable attention for enabling privacy-preserving collaborative model training in distributed environments. The convergence of IoT, FC, and FL offers substantial opportunities to advance IoT system performance, but it also presents challenges in resource allocation, security, energy efficiency, computational complexity, and system heterogeneity. This survey provides a comprehensive and up-to-date analysis of the integration of FL and FC within IoT environments, exploring their synergies, challenges, and state-of-the-art advancements.We review critical aspects, including infrastructure enhancements, security mechanisms, and the emerging role of Digital Twin (DT) technology, which creates virtual replicas of IoT devices to optimize system efficiency and real-time performance. Through case studies in healthcare and smart cities, we highlight practical applications of FL-FC integration. We compare our work with existing surveys, highlight its specific focus on the FL-FC-IoT-DT convergence, and identify open challenges and future research directions toward secure, scalable, and intelligent IoT ecosystems. | 10.1109/TNSM.2026.3731410 |
| Muhammad Muhammad Bala, Abdullahi Uwaisu Muhammad, Kamaluddeen Ibrahim Yarima, Aseel Smerat, Mulikatu Yakubu Ibrahim, Safiyanu Yahaya, Hamza Adamu | Isolation and Optimization Cost of Service-based Radio Access Network Slicing: A Smart-Contract-Based Approach | 2026 | Early Access | Network slicing Smart contracts Radio access networks Regional area networks Modeling Resource management Costing Costs Timing Joining processes Blockchain Network Slicing Service-based RAN Service-based Architecture | The service-based Radio Access Network (RAN) slicing enabled via Software Defined Networking (SDN) and Network Function Virtualization (NFV) can support diverse service requirements and address the rapid data traffic growth from both the vertical industry and the Internet of Things (IoT). However, network slice isolation and resource sharing between slices should be be improved for future wireless network requirements. Firstly, this paper address the isolation enhancement of future wireless networks through Blockchain-Smart-Contract, by creating two smart-contract-based access control to secure access to different service-based RAN applications and secure the sharing of resources. These contract are Verification and Authorization Contract (VAC), as well as Misconduct and Revocation Contract (MRC). The proposed framework is designed to support key 6G service classes, such as enhanced Mobile Broadband (eMBB) and ultra-Reliable Low-Latency Communications (uRLLC), enabling high data rates and low-latency communication. Secondly, to ensure the servicebased RAN achieves better isolation the optimization goal is to minimize the deployment cost to obtain the best deployment scheme. Hence, we divide the service-based RAN slice isolation deployment problem into two sub-problems, i.e., service-based RAN slice isolation and slice deployment problem, by formulating a Mixed Integer Linear Programming (MILP) model to minimize the deployment cost. Finally, to verify the feasibility of the design implementation an experimental platform is built and the results show the architecture achieves isolation enhancement through smart-contract and reduces the deployment cost by 78% and improve the isolation performance by 93% compared to the Blockchain-enabled Network Slice (BcNS) and the service-based RAN. | 10.1109/TNSM.2026.3732250 |
| Yuqiang Wen, K. L. Eddie Law | Selected Group Broadcasting: Modeling and Applications | 2026 | Early Access | Modeling Broadcasting Timing Delays Simulation Portable document format Histograms Tail Argon Testing Traffic modeling Broadcast Overlay Network Automatic Repeat reQuest Symbolic Computation Selected Group Broadcasting (SGB) SGBs SGBp | Modern decentralized applications frequently employ one-to-many messaging over dynamic recipient groups, a paradigm we term Selected Group Broadcasting (SGB). Though one-to-one traffic models (e.g., M/M/1 queue) are well studied, traffic characterization for one-to-many connectivity remains underdeveloped. In this paper, we investigate the delay distribution of one-to-many traffic over an SGB in a wide-area communication system. Depending on the underlying network input, the SGB problem naturally decomposes into two distinct paradigms: SGBs (for Sequential inputs) and SGBp (for Parallel inputs). Asymptotic analysis reveals that SGBs and SGBp are governed by fundamentally different stochastic dynamics, necessitating dedicated modeling approaches for each. This paper focuses exclusively on the SGBs paradigm, providing a rigorous analytical treatment and establishing an operatortheoretic performance framework. For first-order statistics of SGBs, we derive exact closed-form solutions under exponential inter-ACK interval (ACK Interval) inputs. By exploiting the rational Laplace-domain structure of the forward operator, we extend the model to precisely compute output distributions for any non-negative distribution input. Furthermore, we introduce an equivalent SGBs analysis scheme via the inverse operator, enabling the transformation of continuous commit-time distributions into physically interpretable ACK Interval profiles. For second-order statistics, we establish a formalized functional hypothesis under exponential ACK Intervals, validated via simulation. We verify the derived probability density functions with simulated delays; the results are confirmed via Kolmogorov-Smirnov tests. | 10.1109/TNSM.2026.3729017 |
| Pingping Dong, Liying Chen, Xuan Yao, Kai Wang, Lianming Zhang, Jiawei Huang | Fumer: Proactive Time-Shifting for Synchronized Periodic Traffic in Distributed Training | 2026 | Early Access | Training Timing Modeling Optimization Joining processes Bandwidth Synchronization Algorithms Educational institutions Windows Data center network Distributed training traffic RDMA | The growth of distributed training models, with parameters now reaching the billion-scale, has shifted the system bottleneck from computation to communication. While Remote Direct Memory Access (RDMA) is widely deployed to improve network performance by circumventing the kernel mechanism, the synchronization-computation cycles under the synchronous parallel mode introduce a highly synchronized and periodic “on-off” bursty traffic pattern, which poses significant challenges to data center networking. Consequently, distributed training suffers from two critical bottlenecks: instantaneous congestion during communication and persistent link idleness during computation. These issues lead to severe bandwidth contention and resource underutilization, ultimately hindering overall training efficiency. To address these challenges, this paper proposes Fumer, a proactive periodic traffic optimization framework that shifts the congestion control paradigm from reactive rate adjustment to proactive time-shifting. Specifically, Fumer leverages In-band Network Telemetry (INT) and Fast Fourier Transform (FFT) with signal-wave separation to decompose interleaved traffic signals, aiming to overcome the lack of periodic awareness. Furthermore, Fumer employs an off-peak transmission optimization algorithm to calculate optimal time-shift values, thereby tackling synchronized congestion and link idleness. By executing proactive off-peak scheduling, Fumer shifts overlapping communication windows into idle periods to smooth traffic peaks in the time domain. Experimental results show that Fumer boosts average path throughput across all workloads to 86.3 Gbps, improving upon DCQCN (42.6 Gbps) by 102.6% and RECC by 22.1%. Furthermore, it reduces the average and 99.9th-percentile iteration times by up to 25.0%-45.4% and 25.5%-49.3%, respectively, demonstrating its efficacy and robustness across diverse large-scale training workloads. | 10.1109/TNSM.2026.3728016 |
| Guiyan Liu, Ji Li, Kaixin Qin, Songtao Guo, Liang Liu, Li Yin | AdpVDLTS: Adaptive Spatio-Temporal VNF Placement and Load Balanced Traffic Scheduling in Edge Computing Networks | 2026 | Early Access | Loading Modeling Timing Algorithms Schedules Scheduling Joining processes Load management Educational institutions Convolutional neural networks Virtual network function Service function chain Load balanced Traffic schedule Edge computing Networks | The rise of network function virtualization (NFV) technology has enabled virtual network functions (VNF) and service function chains (SFCs) to develop into standard paradigms for service delivery. The uncertain traffic brought about by edge computing has made it a key issue to figure out how to deploy VNFs for network load balancing. However, traditional methods are limited to SFC embedding solutions and resource management and pay less attention to traffic. To address the above issue, this paper takes into account the spatio-temporal characteristics of network traffic and the traffic scheduling after VNF deployment to solve the load balanced VNF deployment problem. We formalize the problem into an NP-hard nonlinear integer programming problem, which will be solved with the proposed algorithm adaptive VNF deployment and load balanced traffic scheduling (AdpVDLTS). AdpVDLTS divides network time into large and small time slots to operate on traffic and VNFs simultaneously, and achieves load balancing through traffic prediction and collaboration with VNF deployment. Compared with the excellent existing algorithms, AdpVDLTS can maintain more stable load balancing, higher throughput, lower deployment cost, and lower latency. In addition, the effectiveness of the traffic prediction algorithm is proved by ablation experiments. | 10.1109/TNSM.2026.3729261 |
| Cong T. Nguyen, Dinh Thai Hoang, Diep N. Nguyen, Hoang-Anh Pham | Generative AI Service Provision in Heterogeneous Edge Networks: A Dynamic Two-Stage Optimization Approach | 2026 | Early Access | Modeling Timing Resource management Optimization Educational institutions Extended reality Delays Servers Artificial intelligence Surveys Generative AI GAI model allocation request assignment edge computing Lyapunov optimization Benders decomposition MILP MINLP | Generative Artificial Intelligence (GAI) has been attracting a massive and rapidly expanding user base worldwide in recent years, resulting in enormous demand for inference requests that cannot be handled efficiently by centralized cloud-based architectures. Edge computing presents a promising approach to mitigate these challenges by leveraging the power of numerous edge devices to better provide GAI services to the users. In this work, we develop a novel two-stage approach to dynamically allocate GAI models and assign user requests to the best edge nodes. In the first stage, we model a joint optimization problem to minimize the expected processing time and decide the optimal model allocation based on predicted user demands. In the second stage, we develop an efficient online approach to assign requests to edge nodes when they arrive, as well as to reallocate GAI models when necessary. Moreover, to address the complexity of the optimization problems in this stage, we leverage Lyapunov optimization framework and Benders decomposition methods to efficiently solve the problems, thereby enabling the proposed approach to quickly adapt to the dynamics of the system. Extensive simulations are conducted to evaluate the performance of the proposed approach and investigate the impacts of important parameters. Simulation results show that the proposed approach can reduce the total processing time by up to 43% with very short running time. | 10.1109/TNSM.2026.3730014 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Ren-Hung Hwang, Jiao-Chuan Huang, Yuan-Cheng Lai, Ying-Dar Lin | Reinforcement Learning Meets LLM Honeypots: A MITRE Engage–Aligned Approach | 2026 | Early Access | Large language models Modeling Training Design methodology Linux Reinforcement learning Windows Learning (artificial intelligence) Art Tuning Cyber deception honeypot reinforcement learning large language models MITRE ATT&CK MITRE Engage SSH | The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A finetuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline (p < 0.001). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux (p < 0.001), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety. | 10.1109/TNSM.2026.3731455 |
| Raeed Al-Sabri, Abdullatif Albaseer, Mohamed Abdallah, Ala Al-Fuqaha | DMGCRL: Dynamic Multi-Scale Graph Contrastive Representation Learning For Network Intrusion Detection | 2026 | Early Access | Modeling Intrusion detection Labeling Timing Fluid flow Graph neural networks IP networks Learning (artificial intelligence) Telecommunication traffic Matrices Network intrusion detection systems (NIDS) Security and privacy in networks Graph neural networks (GNN) Graph contrastive learning Multiscale contrastive learning | Graph neural networks (GNNs) have recently attracted significant attention in network intrusion detection systems (NIDS) due to their ability to model network traffic as graphs and capture complex relationships within network flows. However, existing GNN-based methods face critical limitations: they rely on limited or noisy labeled data and struggle to detect threats at various scales, ranging from local anomalies (e.g., port scanning) to coordinated subnetwork attacks (e.g., botnets) and global network-wide campaigns (e.g., DDoS attacks). To bridge this gap, we propose Dynamic Multiscale Graph Contrastive Representation Learning (DMGCRL), a self-supervised framework that hierarchically models network intrusions at different levels. At the node level, DMGCRL constructs structure-aware subnetworks around individual traffic flows to capture fine-grained behavioral deviations. For subnetwork-level threats, it employs substructure-aware pooling to identify coordinated anomalies among clustered malicious nodes. Finally, at the global level, DMGCRL derives representations that reflect the holistic state of the network, enabling detection of large-scale threats, such as distributed malware propagation. DMGCRL designs a shared GNN encoder with a multi-level contrastive loss to align multiscale representations while largely eliminating label dependence. It learns discriminative features from unlabeled traffic, refines decision boundaries without supervision, and reveals anomalies by contrasting related and unrelated nodes across scales. Performance evaluation was conducted on five publicly available network traffic datasets for binary and multiclass detection. Results show that DMGCRL consistently outperforms SOTA methods, achieving an F1 score of 99.86% on NF-CSECIC-IDS2018-V2 and 96.11% on NF-UNSW-NB15-V2 under binary detection and the lowest mean false positive rates, 1.28% and 2.33% under multiclass detection on the two datasets. | 10.1109/TNSM.2026.3726282 |
| Lazaros Liatsas, Godfrey M. Kibalya, Angelos Antonopoulos | Counterfactual Autoscaling for Resource-Efficient Service Orchestration in the Cloud–Edge Continuum | 2026 | Early Access | Resource management Quality of service Clouds Central Processing Unit Costing Costs Memory Modeling Timing Nickel cloud–edge continuum counterfactual explanations orchestration service management | Cloud–edge computing enables scalable and resilient deployment of microservice-based applications, however achieving resource efficiency while ensuring stringent Quality of Service (QoS) remains challenging. The strong interdependencies among microservices and non-linear latency effects near resource saturation render conventional workload-driven autoscaling ineffective in complex distributed environments. This paper introduces CARSO (Counterfactual Autoscaling and Resource-efficient Service Orchestration), a proactive and interpretable framework that integrates eXplainable Artificial Intelligence (XAI) into the autoscaling process. CARSO employs counterfactual reasoning to derive minimal resource adjustments that proactively prevent QoS violations. The framework includes two core components: i) a Counterfactual Vertical Autoscaling (CVA) scheme that anticipates and mitigates performance degradation and ii) a Latency-Aware Resource Orchestration (LARO) policy that coordinates scaling and placement actions to balance resource efficiency and end-to-end latency across the cloud–edge continuum. Extensive experiments demonstrate that CARSO outperforms state-of-the-art proactive autoscaling frameworks in both QoS compliance and overall resource utilization. | 10.1109/TNSM.2026.3731114 |
| Martine S. Lenders, Carsten Bormann, Thomas C. Schmidt, Matthias Wählisch | A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPS | 2026 | Early Access | Internet of Things Encoding Internet Arrays Gain Recording Tagging Timing HTTP Decoding CBOR World Wide Web JSON DNS application/dns+cbor Internet measurements | The Internet community has taken major efforts to decrease latency on the World Wide Web with significant improvements in accelerating content transport and in compressing static content. Less attention, however, has been dedicated to compression of dynamic content. Such content is commonly provided by JSON and DNS over HTTPS. Dynamic content objects continue to grow in size, which increases latency and fosters the digital inequality. In this paper, we propose to mitigate this increase by utilizing Concise Binary Object Representation (CBOR), a standard originally designed for the constrained Internet of Things (IoT) to restrict packet sizes and enable efficient encoding of data objects. We provide protocol design and three new data sets for the evaluation of dynamic content, DNS, and the loading of websites. Our key findings are the following: (i) Switching the data representation from JSON to CBOR reduces data by up to 80%. This size reduction can decrease loading times by up to 13.8% when downloading large objects—even in local setups. (ii) Enabling CBOR for DNS over HTTPS (DoH) and DNS over CoAP (DoC) reduces packet sizes significantly. Compressing only names combined with unpacked CBOR achieves maximum gain of 52.2%, using more complex but still lightweight Packed CBOR allows minimizing packets by up to 95.5%. Our lean decoder for name compression can fit into as little as 314 bytes of build size. Our results clearly show the potential of CBOR outside of IoT scenarios. Parts of this research have already influenced work within the IETF. | 10.1109/TNSM.2026.3722114 |
| Franck Messaoudi, Luhan Wang, Abdelkader Mekrache, Adlen Ksentini, Bingxuan Li, Jialei Su, Sofiane Messaoudi, Salim El Ghalbzouri | The Brewing Storm in 5G’s Data Plane: Design and Evaluation of a High-Performance eBPF/XDP-Based User Plane Function | 2026 | Early Access | Quality of service Fluid flow Kernel Information rates Throughput Planing 5G mobile communication Linux Filtering Filters 5 th Generation Mobile Networks (5G) User Plane Function (UPF) QoS Enforcement Rule (QER) Quality of Service (QoS) extended Berkeley Packet Filter (eBPF) eXpress Data Path (XDP) Traffic Control (tc) Queuing Discipline (qdisc) | This paper presents the design and implementation of a novel 5G UPF leveraging eBPF technology to meet the stringent performance and programmability requirements of emerging 6G systems. Traditional UPF implementations often struggle to balance performance, flexibility, and resource efficiency-challenges particularly critical in CPU- and I/O-constrained edge environments. The proposed eBPF-based UPF architecture mitigates these limitations by embedding core functionalities, such as packet classification, forwarding, and QoS enforcement, directly within the Linux kernel via eBPF programs attached through XDP and tc hook points. Performance evaluation using TRex demonstrates that the proposed solution achieves competitive throughput, low packet loss, and efficient CPU utilization across traffic profiles. Moreover, it maintains full compliance with 5G Core Network standards. Comparative analysis with well-established open-source UPF implementations further underscores its advantages. This work highlights the potential of eBPF as a foundational technology for building next-generation, programmable UPFs optimized for edge cloud deployments in the 6G era. | 10.1109/TNSM.2026.3720812 |
| Junior Momo Ziazet, Brigitte Jaumard | Energy Efficient Placement of Logical Functionalities in 5G Networks | 2026 | Early Access | Energy Copper Modeling Energy consumption Joining processes Optimization 5G mobile communication Timing Delays Algorithms 5G Logical Functionalities Network Function Placement DU/CU/UPF Optimization Energy Efficiency mathematical optimization Column Generation | Although 5G networks are more efficient in terms of power consumption to traffic ratio, efforts still need to be made to further increase energy efficiency not only for the radio part, but also with respect to the growing cloud component with edge servers. Consolidation of traffic workloads onto shared infrastructures is a key feature of cloud computing to reduce energy consumption, and logical functionality placement plays a key role in this regard. Here, in the cloud RAN context, we propose a unified and energy-aware logical placement of 5G E2E functionalities, i.e., distributed units (DUs), centralized units (CUs), and user plane functions (UPFs), together with traffic routing. The placement problem is formulated as a large-scale integer linear program and solved using a column generation-based decomposition technique, complemented by an efficient heuristic to ensure tractability and improved scalability. The model captures key network and cloud (compute) resources, jointly optimizing the placement of DU, CU, and UPF components, along with traffic routing, to minimize energy consumption while maintaining low latency and high Quality of Service (QoS). Numerical results, based on an open Montreal traffic dataset, demonstrate that the proposed column generation algorithm achieves near-optimal solutions, while the heuristic approach offers significantly better scalability with consistently strong performance. The proposed methods reduce energy consumption by up to 14% and maintain low-latency service delivery. Furthermore, the results highlight that static, peak-time-based placement strategies can lead to inefficiencies throughout the day, emphasizing the importance of accounting for broader temporal traffic patterns. | 10.1109/TNSM.2026.3729149 |
| Mustafa Türk, Müge Sayıt, Ali C. Begen, Andreas J. Kassler | FROG: Fast Response to Optimization Goals for HTTP Adaptive Streaming over SDN | 2026 | Early Access | Optimization Videos Servers Software defined networking Bandwidth Quality of experience Streams Switches Fluid flow Modeling HAS SDN QoE optimization multipath routing multi-server delivery CMCD CMSD | In modern video streaming systems, clients typically make independent bitrate decisions without full knowledge of network conditions, often leading to inefficient resource usage and unstable quality. Network-assisted adaptive streaming is rapidly gaining importance in Network and Service Management (NSM), as operators strive to deliver consistently high Quality of Experience (QoE) under dynamic traffic conditions. This paper introduces FROG, a novel, real-time Software-Defined Networking (SDN)-assisted framework designed to coordinate multi-server and multipath HTTP Adaptive Streaming (HAS) using standardized metrics carriage: Common Media Client Data (CMCD) and Common Media Server Data (CMSD). FROG employs an innovative two-stage optimization workflow in which an initial Linear Programming (LP) model rapidly determines feasible bandwidth bounds, server selection, and path capacities, thereby transforming the remaining optimization into a sequential layer-selection process for coordinated quality selection and flow allocation. This decomposition enables sub-second optimization at the scale of thousands of users, while buffer-aware client feedback is integrated to proactively prevent stalls and maintain system stability. Experiments on an emulated SDN testbed demonstrate that FROG achieves QoE comparable to that of the optimal MILP solution on tractable instances while virtually eliminating video stalls, and significantly reduces quality oscillations, outperforming state-of-the-art network-assisted approaches by up to 2.32× under playback-driven evaluation scenarios. Scalability experiments with up to 4,000 clients further demonstrate sub-second optimization runtimes, confirming the practicality of FROG for large-scale deployments. | 10.1109/TNSM.2026.3729597 |
| Abderrahmane Boulahdour, Miloud Bagaa, Adlen Ksentini, Ahmed Ouameur Messaoud, Daniel Massicotte | Towards Software-Defined TSN Scheduling: An eBPF Approach for Stream Processing and Delay Analysis in Industry 5.0 | 2026 | Early Access | Streams Timing Bridges Software defined networking Delays Kernel Scheduling Schedules Modeling Hardware Industrial Networks Asynchronous TSN ATS eBPF SDN | This paper presents a software-defined Time-Sensitive Networking (TSN) architecture that implements the IEEE 802.1Qcr Asynchronous Traffic Shaper (ATS) using Extended Berkeley Packet Filter (eBPF) technology within Linux-based TSN bridges. By moving traffic shaping logic to the kernel level, our solution eliminates the need for dedicated hardware and enables dynamic, programmable control of frame filtering, metering, and queuing. A Software-Defined Networking (SDN) controller complements the design, providing centralized orchestration of TSN behavior through standardized interfaces and a unified network view. We implement the ATS scheduling model to compute and enforce per-stream eligibility times, supporting time-aware scheduling of concurrent streams within the same priority class. This enables deterministic traffic delivery, which is critical for industrial automation and control. Our approach allows seamless integration into existing infrastructures and aligns with the flexibility objectives of Industry 5.0. Performance evaluations demonstrate accurate scheduling behavior under heterogeneous traffic conditions and quantify the delay introduced by a TSN bridge for multiple coexisting streams. | 10.1109/TNSM.2026.3729563 |
| Stephen Jasina, Loqman Salamatian, Joshua Mathews, Scott Anderson, Paul Barford, Mark Crovella, Walter Willinger | Matisse: Visualizing Measured Internet Latencies as Manifolds | 2026 | Early Access | Manifolds Internet Measurement Visualization Delays Distance measurement Joining processes Surfaces Timing Europe network internet measurement curvature manifold visualization | Manifolds are complex topological spaces that can be used to represent datasets of real-world measurements. Visualizing such manifolds can help with illustrating their topological characteristics (e.g., curvature) and providing insights into important properties of the underlying data (e.g., anomalies in the measurements). In this paper, we describe a new methodology and system for generating and visualizing manifolds that are inferred from actual Internet latency measurements between different cities and are projected over a 2D Euclidean space (e.g., a geographic map). Our method leverages a series of graphs that capture critical information contained in the data, including well-defined locations (for vertices) and Ricci curvature information (for edges). Our visualization approach then generates a curved surface (manifold) in which (a) geographical locations of vertices are maintained and (b) the Ricci curvature values of the graph edges determine the curvature properties of the manifold. The resulting manifold highlights areas of critical connectivity and defines an instance of “Internet delay space” where latency measurements manifest as geodesics. We describe details of our method and its implementation in a tool, which we call Matisse, for generating, visualizing and manipulating manifolds projected onto a base map. We illustrate Matisse with three case studies: a simple example to demonstrate key concepts, and visualizations of the US and Europe public Internet to show Matisse’s utility. | 10.1109/TNSM.2026.3730274 |
| Mohamed Anis Sakka, Fahdah Alalyan, Wael Jaafar, Rami Langar | FML-AD: A Federated Learning Framework with Meta-Model Refinement for Cyberattack Duration Prediction in 5G O-RAN | 2026 | Early Access | Modeling 5G mobile communication Open RAN Timing Signal detection Training Federated learning Fluid flow Transformers Jamming 5G Cyberattack Duration Prediction O-RAN Federated Learning Transformer Meta-Model Refinement | The emergence of fifth-generation (5G) and open radio access network (O-RAN) architectures has expanded the attack surface for cyber threats, creating an urgent need for enhanced and proactive mitigation strategies to ensure the preservation of quality of service (QoS), network reliability, and user data privacy in highly distributed and virtualized environments. In this context, we introduce FML-AD, a federated learning framework with meta-model refinement for adaptive attack duration prediction without centralizing raw training traffic. The proposed method combines a FLAD-trained Transformer for distributed temporal learning with an XGBoost-based second-level regression model that refines the initial predictions using controlled O-RAN testbed examples, thereby reducing prediction errors associated with the benchmark-to-deployment distribution shift. Extensive evaluation on the CICIoT2023 dataset shows that FML-AD improves prediction accuracy compared with conventional centralized and federated baselines. Furthermore, an evaluation on a controlled 5G O-RAN testbed involving ten TCP SYN and UDP flooding scenarios provides a proof-of-concept demonstration of the feasibility of the proposed post-detection prediction pipeline in the evaluated configuration. A separate exploratory transfer-learning assessment using 5G V2X radio-jamming scenarios and leave-one-scenario-out (LOSO) validation further examines whether the duration-prediction pipeline can be adapted to a different disruption mechanism under limited target-domain data. For the considered jamming configurations, several operating points in the early 3–5 sec range also produce favorable prediction results, providing preliminary evidence of transferability. | 10.1109/TNSM.2026.3731093 |
| Minhyeok Jang, Jalel Ben-Othman, Hyunchae Chun, Sungrae Cho, Hyunbum Kim | Multi-Agent Network Management with Dynamic Entropy-Driven Logistic Trust Aggregation | 2026 | Early Access | Entropy Modeling Management Detectors Labeling Learning (artificial intelligence) Poles and zeros Stability Accuracy Error analysis network management distributed intrusion detection multi-agent trust aggregation concept drift stability-agility trade-off entropy-driven adaptation | Autonomous network management increasingly fuses multiple heterogeneous detectors—such as the intrusion detectors that monitor different traffic planes for 6G and IoT security—through adaptive trust-weighted consensus. When trust is updated online, however, such systems face a fundamental stability-agility trade-off: they are either calm but slow to react to novel threats, or fast but erratic under routine noise. We identify and formalize the resulting failure modes of trust collapse and blind conformity, and propose DELTA (Dynamic Entropy-driven Logistic Trust Aggregation), a self-regulating trust-management framework. DELTA couples a Fixed-Share Redistribution regularizer, which guarantees a minimum trust quota for every detector, with an entropy-amplified logistic controller whose learning rate is driven by the current leader’s error rate and amplified by the ensemble’s structural entropy; this keeps the system quiescent under normal traffic yet triggers a rapid, bounded re-calibration the moment the trusted detector begins to fail. We prove that DELTA enforces a strictly positive diversity floor—making trust collapse provably impossible—and derive bounds on its transition latency and stationary volatility. Across an extensive evaluation—including robustness to delayed, missing, and adversarial feedback, comparison against expert-advice, Bayesian, and change-point baselines with confidence intervals, and validation on the real UNSW-NB15 intrusion dataset—DELTA recovers from zero-day regime shifts where naive baselines collapse below chance, while remaining an order of magnitude more stable than aggressive adaptive methods, all at O(N) computational and communication cost. | 10.1109/TNSM.2026.3731203 |
| Jindian Liu, Zhuo Li, Hao Xun, Yu Zhang, Peng Luo, Qiang Li, Kaihua Liu | FSD-GCN: Fast Network-wide Sketch Deployment via Graph Convolution Network | 2026 | Early Access | Fluid flow Topology Measurement Measurement units Bipartite graph Joining processes Timing Modeling Educational institutions Radiation detectors Network Measurement Sketch Network-wide Sketch Deployment | Sketches have been widely used in network measurement thanks to their low resource overheads. Network-wide sketch deployment is essential for measuring flows across the entire network to enable comprehensive monitoring and decision-making. Most frameworks for network-wide sketch deployment formulate it as a mixed integer linear programming (MILP) problem and utilize commercial solvers such as Gurobi to produce the optimal nodes deployed with sketches. However, the network topology changes frequently. When the topology changes, it is necessary to reconstruct the MILP and re-solve it. Due to the NP hardness, the solvers have to handle a substantial number of variables and constraints, and iteratively converge to the optimal nodes, which is too time-consuming to adapt to frequent topology changes. To this end, a framework for fast network-wide sketch deployment via graph convolution network called FSD-GCN is proposed. Unlike the solvers that gradually converge to the optimal nodes, FSD-GCN transforms the MILP derived from the network-wide sketch deployment problem into a graph-structured representation, and utilizes a graph convolution network to directly obtain the probability of deploying sketches at each node. Meanwhile, an integer linear programming model called NCR is proposed to be used in FSD-GCN, which can achieve maximum flow cover rate with minimum redundant measurement while requiring the fewest deployed nodes. The experimental results show that NCR solved by FSD-GCN can reduce the number of deployed nodes and redundant measurement, while achieving the highest flow cover rate. Meanwhile, compared with the state-of-the-art frameworks using Gurobi, NCR solved by FSD-GCN reduces solving time more than 90%. | 10.1109/TNSM.2026.3731617 |