Last updated: 2026-09-09 05:01 UTC
All documents
Number of pages: 173
| Author(s) | Title | Year | Publication | Keywords | ||
|---|---|---|---|---|---|---|
| Wei Sai, Yihui Lu, Xin Guo | A Privacy-Preserving Security Framework for Multi-Party Data Fusion Computing Based on Homomorphic Encryption | 2026 | Early Access | Security Protocols Information rates Modeling Throughput Noise Multi-party computation Polynomials Federated learning Homomorphic encryption Homomorphic Encryption Secure Multi-Party Computation Threshold Decryption Privacy-Preserving Data Fusion Decentralized Computing Framework | To prevent plaintext exposure in multi-party collaborative computing, this paper proposes a distributed secure multi-party computation protocol based on the Cheon-Kim-Kim-Song (CKKS) homomorphic encryption scheme. Data is encoded and encrypted at the source into CKKS complex polynomial ciphertext, enabling vectorized fusion under shared evaluation keys and threshold decryption in a decentralized architecture without a trusted central authority. Experiments on heterogeneous multi-institution datasets demonstrate low numerical error (9.0×10⁻⁷ at polynomial order 2¹⁶ and depth 12), effective scalability (throughput increasing from 1.12×10⁵ to 1.32×10⁵ ops/s and latency decreasing from 56 ms to 38 ms as nodes scale from 4 to 16), and strong robustness (70% decryption success at a 60% threshold and 95% recovery under malicious interference), showing that the framework achieves efficient computation with strict privacy protection for cross-party data fusion. | 10.1109/TNSM.2026.3717343 |
| Chenyu Zhao, Xin Li, Tianhao Liu, Shanguo Huang | Joint Design and Operation Phases Availability Evaluation for End-to-End Light-Paths in Optical Networks | 2026 | Early Access | Modeling Availability Lighting Protection Timing Design methodology Optical fiber networks Maintenance engineering Joining processes Telemetry Optical network light-path availability evaluation design and operation phases | The rapid growth of high-bandwidth services places stringent requirements on the availability of optical networks. Ensuring high availability in practice hinges on accurate and consistent evaluation of light-path availability in both the design and operation phases. To this end, this paper proposes a unified model for light-path availability evaluation in optical networks that couples an ensemble learning–based failure classifier with a Dynamic Bayesian Network (DBN). In the design phase, the model functions as a model-driven DBN whose transition probabilities are parameterized by historical failure and repair rates, supporting three-state (normal, soft failure, hard failure) modeling at component and path levels under different protection schemes. During the operation phase, the same DBN structure is driven by real-time observations inferred from monitoring data (e.g., input/output optical power) using ensemble learning-based classifiers. This enables the evaluation of instantaneous availability under limited measurement conditions. Furthermore, classification results are mapped to Conditional Probability Tables (CPTs) via confusion matrices to quantify the impact of classifier uncertainty on availability evaluation. Experimental results on a Kafka-based optical-network telemetry testbed show that, under the fault-event-based chronological split, XGBoost achieves an accuracy of 93.24% and a macro-averaged F1-score of 0.8183. Case studies involving different protection schemes and three representative network topologies show how backup end-to-end light paths affect availability and demonstrate the computational feasibility of the model across different network scales. Furthermore, it supports online availability updates and the identification of critical components. This work serves as a reference for optical network management and offers significant guidance for the future design of robust optical network systems. | 10.1109/TNSM.2026.3731278 |
| Shuang Zheng, Xing Zhang, Michael Sheng, Haixu Wang, Wenbo Wang | Beam Hopping Low Earth Orbit Satellite Resource Allocation for Differentiated Services and Robustness Analysis under Model Attacks | 2026 | Early Access | Beams Satellites Resource management Modeling Optimization Schedules Scheduling Low earth orbit satellites Algorithms Bridges LEO satellite communications deep reinforcement learning digital twin resource allocation adversarial attack | Beam hopping (BH)-enabled Low Earth Orbit (LEO) satellites play a pivotal role in next-generation communication networks, providing global coverage, improving spectrum efficiency, and supporting flexible adaptation to heterogeneous service demands. To fully exploit these capabilities, artificial intelligence (AI) techniques are increasingly employed for dynamic resource allocation and power management. However, limited onboard resources and potential adversarial perturbations pose challenges to both efficiency and robustness. To address these issues, we leverage digital twin technology to accurately capture the spatio-temporal dynamics of user–satellite visibility, providing precise state information for decision-making. Building on this, we formulate a joint optimization framework for BH scheduling and power allocation as a Markov Decision Process and propose the BRIDGE—BH with Reinforcement learning incorporating Integrated Dirichlet and Gumbel-TopK Exploration—which integrates a quality of service (QoS)-driven subchannel scheduling mechanism to ensure efficient and differentiated resource allocation. The model’s robustness is systematically evaluated under three classical adversarial attacks. Simulation results demonstrate that our approach achieves superior energy efficiency, service throughput, and fairness, while the robustness analysis shows stable performance under the considered bounded adversarial perturbations. | 10.1109/TNSM.2026.3710750 |
| Martine S. Lenders, Carsten Bormann, Thomas C. Schmidt, Matthias Wählisch | A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPS | 2026 | Early Access | Internet of Things Encoding Internet Arrays Gain Recording Tagging Timing HTTP Decoding CBOR World Wide Web JSON DNS application/dns+cbor Internet measurements | The Internet community has taken major efforts to decrease latency on the World Wide Web with significant improvements in accelerating content transport and in compressing static content. Less attention, however, has been dedicated to compression of dynamic content. Such content is commonly provided by JSON and DNS over HTTPS. Dynamic content objects continue to grow in size, which increases latency and fosters the digital inequality. In this paper, we propose to mitigate this increase by utilizing Concise Binary Object Representation (CBOR), a standard originally designed for the constrained Internet of Things (IoT) to restrict packet sizes and enable efficient encoding of data objects. We provide protocol design and three new data sets for the evaluation of dynamic content, DNS, and the loading of websites. Our key findings are the following: (i) Switching the data representation from JSON to CBOR reduces data by up to 80%. This size reduction can decrease loading times by up to 13.8% when downloading large objects—even in local setups. (ii) Enabling CBOR for DNS over HTTPS (DoH) and DNS over CoAP (DoC) reduces packet sizes significantly. Compressing only names combined with unpacked CBOR achieves maximum gain of 52.2%, using more complex but still lightweight Packed CBOR allows minimizing packets by up to 95.5%. Our lean decoder for name compression can fit into as little as 314 bytes of build size. Our results clearly show the potential of CBOR outside of IoT scenarios. Parts of this research have already influenced work within the IETF. | 10.1109/TNSM.2026.3722114 |
| Francisco Muro, Eduardo Baena, Tomaso De Cola, Sergio Fortes, Raquel Barco | AI-Driven Optimization of Virtual Network Function Allocation in 6G Non-Terrestrial Networks | 2026 | Early Access | Resource management Optimization Satellites Modeling Artificial intelligence Information rates Throughput Measurement 5G mobile communication Loading 6G Non-Terrestrial Networks O-RAN Kubernetes Virtual Network Functions VNF Allocation Machine Learning VNF Placement Gradient-Free Optimization Network Performance Resource Management | The integration of 6G technologies into Non-Terrestrial Networks (NTNs) raises a fundamental orchestration problem: how to allocate Virtual Network Functions (VNFs) across satellite and terrestrial domains under tight onboard resource constraints and a continuously changing topology. The virtualized 6G Open Radio Access Network (O-RAN) paradigm makes it possible to run 5G software stacks on Software-Defined Radios (SDRs) based on General Purpose Processors (GPPs), but it also turns VNF placement into a high-dimensional, multi-objective decision that static heuristics and model-based formulations struggle to capture. This paper addresses that gap by introducing an AI-driven VNF allocation framework for 6G-NTN environments built on an O-RAN-based distributed architecture and orchestrated on top of Kubernetes. The VNF allocation problem is formalized for a multi-domain 6G-NTN scenario with constrained satellite resources, and a measurement-based test campaign is designed to characterize the emulated platform in terms of virtual resource utilization and end-to-end performance. The framework couples tree-based machine learning predictors with a gradient-free optimizer to reach the optimal feasible allocation, outperforming two heuristic baselines drawn from the VNF placement literature by reducing the service RTT by up to 39% and delivering up to 3× higher YouTube DL throughput with respect to the best feasible heuristic. Beyond these gains, the proposed framework establishes a measurement-driven, reproducible methodology for VNF allocation in 6GNTN scenarios, demonstrating that AI-driven orchestration can systematically uncover non-obvious resource configurations that purely analytical or static approaches consistently miss. | 10.1109/TNSM.2026.3724474 |
| Lazaros Liatsas, Godfrey M. Kibalya, Angelos Antonopoulos | Counterfactual Autoscaling for Resource-Efficient Service Orchestration in the Cloud–Edge Continuum | 2026 | Early Access | Resource management Quality of service Clouds Central Processing Unit Costing Costs Memory Modeling Timing Nickel cloud–edge continuum counterfactual explanations orchestration service management | Cloud–edge computing enables scalable and resilient deployment of microservice-based applications, however achieving resource efficiency while ensuring stringent Quality of Service (QoS) remains challenging. The strong interdependencies among microservices and non-linear latency effects near resource saturation render conventional workload-driven autoscaling ineffective in complex distributed environments. This paper introduces CARSO (Counterfactual Autoscaling and Resource-efficient Service Orchestration), a proactive and interpretable framework that integrates eXplainable Artificial Intelligence (XAI) into the autoscaling process. CARSO employs counterfactual reasoning to derive minimal resource adjustments that proactively prevent QoS violations. The framework includes two core components: i) a Counterfactual Vertical Autoscaling (CVA) scheme that anticipates and mitigates performance degradation and ii) a Latency-Aware Resource Orchestration (LARO) policy that coordinates scaling and placement actions to balance resource efficiency and end-to-end latency across the cloud–edge continuum. Extensive experiments demonstrate that CARSO outperforms state-of-the-art proactive autoscaling frameworks in both QoS compliance and overall resource utilization. | 10.1109/TNSM.2026.3731114 |
| Jing Zhang, Chao Luo, Rui Shao | MTG-GAN: A Masked Temporal Graph Generative Adversarial Network for Cross-Domain System Log Anomaly Detection | 2026 | Early Access | Anomaly detection Adaptation models Generative adversarial networks Feature extraction Data models Load modeling Accuracy Robustness Contrastive learning Chaos Log Anomaly Detection Generative Adversarial Networks (GANs) Temporal Data Analysis | Anomaly detection of system logs is crucial for the service management of large-scale information systems. Nowadays, log anomaly detection faces two main challenges: 1) capturing evolving temporal dependencies between log events to adaptively tackle with emerging anomaly patterns, 2) and maintaining high detection capabilities across varies data distributions. Existing methods rely heavily on domain-specific data features, making it challenging to handle the heterogeneity and temporal dynamics of log data. This limitation restricts the deployment of anomaly detection systems in practical environments. In this article, a novel framework, Masked Temporal Graph Generative Adversarial Network (MTG-GAN), is proposed for both conventional and cross-domain log anomaly detection. The model enhances the detection capability for emerging abnormal patterns in system log data by introducing an adaptive masking mechanism that combines generative adversarial networks with graph contrastive learning. Additionally, MTG-GAN reduces dependency on specific data distribution and improves model generalization by using diffused graph adjacency information deriving from temporal relevance of event sequence, which can be conducive to improve cross-domain detection performance. Experimental results demonstrate that MTG-GAN outperforms existing methods on multiple real-world datasets in both conventional and cross-domain log anomaly detection. | 10.1109/TNSM.2026.3654642 |
| Muhammad Muhammad Bala, Abdullahi Uwaisu Muhammad, Kamaluddeen Ibrahim Yarima, Aseel Smerat, Mulikatu Yakubu Ibrahim, Safiyanu Yahaya, Hamza Adamu | Isolation and Optimization Cost of Service-based Radio Access Network Slicing: A Smart-Contract-Based Approach | 2026 | Early Access | The service-based Radio Access Network (RAN) slicing enabled via Software Defined Networking (SDN) and Network Function Virtualization (NFV) can support diverse service requirements and address the rapid data traffic growth from both the vertical industry and the Internet of Things (IoT). However, network slice isolation and resource sharing between slices should be be improved for future wireless network requirements. Firstly, this paper address the isolation enhancement of future wireless networks through Blockchain-Smart-Contract, by creating two smart-contract-based access control to secure access to different service-based RAN applications and secure the sharing of resources. These contract are Verification and Authorization Contract (VAC), as well as Misconduct and Revocation Contract (MRC). The proposed framework is designed to support key 6G service classes, such as enhanced Mobile Broadband (eMBB) and ultra-Reliable Low-Latency Communications (uRLLC), enabling high data rates and low-latency communication. Secondly, to ensure the servicebased RAN achieves better isolation the optimization goal is to minimize the deployment cost to obtain the best deployment scheme. Hence, we divide the service-based RAN slice isolation deployment problem into two sub-problems, i.e., service-based RAN slice isolation and slice deployment problem, by formulating a Mixed Integer Linear Programming (MILP) model to minimize the deployment cost. Finally, to verify the feasibility of the design implementation an experimental platform is built and the results show the architecture achieves isolation enhancement through smart-contract and reduces the deployment cost by 78% and improve the isolation performance by 93% compared to the Blockchain-enabled Network Slice (BcNS) and the service-based RAN. | 10.1109/TNSM.2026.3732250 | |
| Cong T. Nguyen, Dinh Thai Hoang, Diep N. Nguyen, Hoang-Anh Pham | Generative AI Service Provision in Heterogeneous Edge Networks: A Dynamic Two-Stage Optimization Approach | 2026 | Early Access | Modeling Timing Resource management Optimization Educational institutions Extended reality Delays Servers Artificial intelligence Surveys Generative AI GAI model allocation request assignment edge computing Lyapunov optimization Benders decomposition MILP MINLP | Generative Artificial Intelligence (GAI) has been attracting a massive and rapidly expanding user base worldwide in recent years, resulting in enormous demand for inference requests that cannot be handled efficiently by centralized cloud-based architectures. Edge computing presents a promising approach to mitigate these challenges by leveraging the power of numerous edge devices to better provide GAI services to the users. In this work, we develop a novel two-stage approach to dynamically allocate GAI models and assign user requests to the best edge nodes. In the first stage, we model a joint optimization problem to minimize the expected processing time and decide the optimal model allocation based on predicted user demands. In the second stage, we develop an efficient online approach to assign requests to edge nodes when they arrive, as well as to reallocate GAI models when necessary. Moreover, to address the complexity of the optimization problems in this stage, we leverage Lyapunov optimization framework and Benders decomposition methods to efficiently solve the problems, thereby enabling the proposed approach to quickly adapt to the dynamics of the system. Extensive simulations are conducted to evaluate the performance of the proposed approach and investigate the impacts of important parameters. Simulation results show that the proposed approach can reduce the total processing time by up to 43% with very short running time. | 10.1109/TNSM.2026.3730014 |
| Jesús F. Cevallos-Moreno, Alessandra Rizzardi, Sabrina Sicari, Alberto Coen-Porisini | TIGER: an open-source cyber-Threat Intelligence Game Environment for Reinforcement learning | 2026 | Early Access | Open-source testbeds for intrusion detection and mitigation enable benchmarking the efficacy of machine-learningbased cyber-defensive systems under increasingly realistic, heterogeneous network scenarios. In this context, the open-world nature of network intrusion detection requires defences to use continual learning strategies to adapt pattern-matching to new attack classes. The cost of periodically fine-tuning pre-trained detectors is not only computational but also encompasses the broader Cyber Threat Intelligence (CTI) life-cycle, which involves collecting, analyzing, and processing raw data into actionable insights. For ML-driven defensive systems, such actionable CTI ultimately takes the form of curated, labelled traffic traces of novel attacks. However, the concurrent optimisation of these intelligence-gathering costs and defence effectiveness has received little attention from the research community. In this respect, this work presents TIGER, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyberdefence life-cycles. TIGER uses realistic network simulation software to model an active-learning game in which an agent learns to timely purchase CTI—abstracted in our environment as labelled samples of Zero-day attacks— to retrain its intrusion detection machinery on new attack patterns, while considering a constrained resource availability scenario. | 10.1109/TNSM.2026.3732249 | |
| Yuya Miyaoka, Masaki Inoue, Kengo Urata, Shigeaki Harada | Chat-Driven Optimal Management for Virtual Network Services | 2026 | Early Access | Modeling Large language models Central Processing Unit Virtual machines Resource management Program processors Routing Timing Optimization Conferences Natural language processing Intent-based networking Virtual network allocation Optimization | This paper proposes a chat-driven network management framework that integrates natural language processing (NLP) with optimization-based virtual network allocation, enabling intuitive and reliable reconfiguration of virtual network services. Conventional intent-based networking (IBN) methods depend on statistical language models to interpret user intent, but cannot guarantee the feasibility of generated configurations. To overcome this, we develop a two-stage framework consisting of an Interpreter, which extracts intent from natural language prompts using NLP, and an Optimizer, which computes feasible virtual machine (VM) placement and routing via integer linear programming. In particular, the Interpreter translates user chats into update directions, i.e., whether to increase, decrease, or maintain parameters such as CPU demand and latency bounds, thereby enabling iterative refinement of the network configuration. In this paper, two distinct Interpreter implementations are introduced: a Sentence-BERT model with support vector machine (SVM) classifiers and a large language model (LLM). Experiments in single-user and multi-user settings show that the framework dynamically updates VM placement and routing while preserving feasibility. The LLM-based approach achieves higher accuracy with fewer labeled samples, whereas the Sentence-BERT with SVM classifiers provides significantly lower latency suitable for real-time operation. We also compare our cascade structure method with an end-to-end LLM approach, highlighting our proposed method’s high level of reliability. | 10.1109/TNSM.2026.3726950 |
| Jindian Liu, Zhuo Li, Hao Xun, Yu Zhang, Peng Luo, Qiang Li, Kaihua Liu | FSD-GCN: Fast Network-wide Sketch Deployment via Graph Convolution Network | 2026 | Early Access | Sketches have been widely used in network measurement thanks to their low resource overheads. Network-wide sketch deployment is essential for measuring flows across the entire network to enable comprehensive monitoring and decision-making. Most frameworks for network-wide sketch deployment formulate it as a mixed integer linear programming (MILP) problem and utilize commercial solvers such as Gurobi to produce the optimal nodes deployed with sketches. However, the network topology changes frequently. When the topology changes, it is necessary to reconstruct the MILP and re-solve it. Due to the NP hardness, the solvers have to handle a substantial number of variables and constraints, and iteratively converge to the optimal nodes, which is too time-consuming to adapt to frequent topology changes. To this end, a framework for fast network-wide sketch deployment via graph convolution network called FSD-GCN is proposed. Unlike the solvers that gradually converge to the optimal nodes, FSD-GCN transforms the MILP derived from the network-wide sketch deployment problem into a graph-structured representation, and utilizes a graph convolution network to directly obtain the probability of deploying sketches at each node. Meanwhile, an integer linear programming model called NCR is proposed to be used in FSD-GCN, which can achieve maximum flow cover rate with minimum redundant measurement while requiring the fewest deployed nodes. The experimental results show that NCR solved by FSD-GCN can reduce the number of deployed nodes and redundant measurement, while achieving the highest flow cover rate. Meanwhile, compared with the state-of-the-art frameworks using Gurobi, NCR solved by FSD-GCN reduces solving time more than 90%. | 10.1109/TNSM.2026.3731617 | |
| Deemah H. Tashman, Soumaya Cherkaoui | Trustworthy AI-Driven Dynamic Hybrid RIS: Joint Optimization and Reward Poisoning-Resilient Control in Cognitive MISO Networks | 2026 | Early Access | Reconfigurable intelligent surfaces Reliability Optimization Security MISO Array signal processing Vectors Satellites Reflection Interference Beamforming cascaded channels cognitive radio networks deep reinforcement learning dynamic hybrid reconfigurable intelligent surfaces energy harvesting poisoning attacks | Cognitive radio networks (CRNs) are a key mechanism for alleviating spectrum scarcity by enabling secondary users (SUs) to opportunistically access licensed frequency bands without harmful interference to primary users (PUs). To address unreliable direct SU links and energy constraints common in next-generation wireless networks, this work introduces an adaptive, energy-aware hybrid reconfigurable intelligent surface (RIS) for underlay multiple-input single-output (MISO) CRNs. Distinct from prior approaches relying on static RIS architectures, our proposed RIS dynamically alternates between passive and active operation modes in real time according to harvested energy availability. We also model our scenario under practical hardware impairments and cascaded fading channels. We formulate and solve a joint transmit beamforming and RIS phase optimization problem via the soft actor-critic (SAC) deep reinforcement learning (DRL) method, leveraging its robustness in continuous and highly dynamic environments. Notably, we conduct the first systematic study of reward poisoning attacks on DRL agents in RIS-enhanced CRNs, and propose a lightweight, real-time defense based on reward clipping and statistical anomaly filtering. Numerical results demonstrate that the SAC-based approach consistently outperforms established DRL base-lines, and that the dynamic hybrid RIS strikes a superior trade-off between throughput and energy consumption compared to fully passive and fully active alternatives. We further show the effectiveness of our defense in maintaining SU performance even under adversarial conditions. Our results advance the practical and secure deployment of RIS-assisted CRNs, and highlight crucial design insights for energy-constrained wireless systems. | 10.1109/TNSM.2026.3660728 |
| Soonbeom Kwon, Yusu Noh, Youngwoo Jang, Illyoung Choi, Byungchul Tak, In-geol Chun, Young-Kyoon Suh | Scalable and Robust Resource Provisioning via Adaptive Task Scheduling for Edge Devices | 2026 | Early Access | Schedules Scheduling Cloning Timing Educational institutions Computers Transcoding Videos Tail Edge computing Edge devices Edge server Resource augmentation Task distribution Kubernetes | Edge devices, such as wearables, drones, and CCTV systems, are vital for real-time data collection in urban intelligence. However, their limited computational and storage capacities pose significant challenges. While offloading to public clouds offers scalability, it often incurs high latency and operational costs. Conversely, centralizing workloads on edge servers may result in the underutilization of high-performance edge devices. To address these limitations, we introduce ERPF, a Kubernetes-based Edge Resource Provisioning Framework that augments the capabilities of heterogeneous edge environments. ERPF orchestrates dynamic volume provisioning, GPU-aware resource allocation, execution context migration, and adaptive task distribution to improve system flexibility and efficiency. Building on this, we propose a novel adaptive task scheduling technique, termed eATS, composed of three key mechanisms: (i) Partition Smoothing Scheme for stable task granularity control, (ii) Resilient Edge Reintegration for failure detection and task reassignment, and (iii) Competitive Task Cloning for speculative execution with fastest-result commitment. The proposed eATS scheme reduces task execution time by up to 27.6%, lowers partition size variability by 8.7×, and improves scheduling robustness across heterogeneous edge devices over the baseline. | 10.1109/TNSM.2026.3694238 |
| Ren-Hung Hwang, Jiao-Chuan Huang, Yuan-Cheng Lai, Ying-Dar Lin | Reinforcement Learning Meets LLM Honeypots: A MITRE Engage–Aligned Approach | 2026 | Early Access | Large language models Modeling Training Design methodology Linux Reinforcement learning Windows Learning (artificial intelligence) Art Tuning Cyber deception honeypot reinforcement learning large language models MITRE ATT&CK MITRE Engage SSH | The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A finetuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline (p < 0.001). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux (p < 0.001), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety. | 10.1109/TNSM.2026.3731455 |
| Ahmed Rjiba, Hicham Lakhlef, Joachim Bruneau-Queyreix, Meriem Afif | Federated Learning in Fog Computing within IoT Environments: An up-to-date and comprehensive survey | 2026 | Early Access | Federated learning Internet of Things Edge computing Modeling Clouds Security Training Surveys Privacy Timing Internet of Things (IoT) Federated Learning (FL) Fog Computing (FC) Survey Digital Twin (DT) | The Internet of Things (IoT) connects diverse, resource-constrained devices, driving innovation in domains such as healthcare, smart cities, and industrial automation. However, the exponential growth of IoT devices poses critical challenges in data processing, privacy, security, and latency. Fog Computing (FC) mitigates these issues by decentralizing computational resources, processing and storing data locally to enable low-latency, high-quality services. This makes FC an ideal platform for integrating Federated Learning (FL), a decentralized machine learning paradigm that trains models locally on IoT devices and shares only aggregated updates, preserving data privacy. Since its introduction, FL has garnered considerable attention for enabling privacy-preserving collaborative model training in distributed environments. The convergence of IoT, FC, and FL offers substantial opportunities to advance IoT system performance, but it also presents challenges in resource allocation, security, energy efficiency, computational complexity, and system heterogeneity. This survey provides a comprehensive and up-to-date analysis of the integration of FL and FC within IoT environments, exploring their synergies, challenges, and state-of-the-art advancements.We review critical aspects, including infrastructure enhancements, security mechanisms, and the emerging role of Digital Twin (DT) technology, which creates virtual replicas of IoT devices to optimize system efficiency and real-time performance. Through case studies in healthcare and smart cities, we highlight practical applications of FL-FC integration. We compare our work with existing surveys, highlight its specific focus on the FL-FC-IoT-DT convergence, and identify open challenges and future research directions toward secure, scalable, and intelligent IoT ecosystems. | 10.1109/TNSM.2026.3731410 |
| Vishnu Prakash, Shrinivas Petale, Reshma Rastogi, Suresh Subramaniam, Bijoy Chand Chatterjee | DRLF: Deep Reinforcement Learning-Based Fragmentation-Aware Routing and Spectrum Allocation in Elastic Optical Networks | 2026 | Early Access | Resource management Elastic optical networks Training Probability Routing Optimization Joining processes Learning (artificial intelligence) Machine learning Educational institutions Elastic optical networks deep reinforcement learning optimization fragmentation | Fragmentation poses a significant challenge in elastic optical networks (EONs) and diminishes resource utilization. While various research efforts have attempted to address the fragmentation issue, they often rely on rule-based strategies. Although these strategies encode valuable knowledge, they may not fully capture the dynamic and multifaceted behaviors of EONs. This limitation impedes adaptive service provisioning to mitigate fragmentation. To enhance network performance, this paper proposes a deep reinforcement learning-based fragmentationaware routing and spectrum allocation, named DRLF, which employs deep neural networks (DNNs) to learn fragmentation-aware routing and spectrum allocation (RSA) within the intricate EON state spaces. Through the utilization of the deep Q-network (DQN) algorithm, DNN parameters are updated to facilitate episode-based training of DRLF. The RSA training process is segmented into episodes, each comprising a fixed number of lightpath requests, with a primary focus on optimizing network resource utilization while minimizing fragmentation. Unlike previous approaches, DRLF implements a continuous reward policy tied to path fragmentation, where rewards are inversely correlated with fragmentation levels. Additionally, the agent receives a bonus reward for successfully achieving the blocking probability under the threshold value in each episode. DRLF incorporates fragmentation as heuristic information in the reward function, and the action space is designed to train the agent to find a suitable spectrum allocation so that the fragmentation increase can be minimized. Consequently, the DRLF agent is trained to prioritize paths and spectrum slots with lower fragmentation levels, thereby accommodating more lightpath requests in future scenarios. Numerical evaluations demonstrate that DRLF surpasses existing DRL-based approaches, such as DeepRMSA and HeuDRL, as well as heuristic rule-based allocation strategies, particularly in terms of blocking performance. | 10.1109/TNSM.2026.3731113 |
| Koffka Khan | CAREM: Counterfactual Action Reduction and Evaluation for Concurrent Live Virtual Machine Migration in Cloud Data Centers | 2026 | Early Access | Data centers Virtual machines Software defined networking Joining processes Schedules Scheduling Liver Management Modeling Textile fibers live virtual machine migration network and service management software-defined networking cloud data centers uncertainty-aware scheduling federated learning | Concurrent live virtual-machine (VM) migration is a network and service management problem: the controller must decide not only which VM should move, but also the path, reserved bandwidth rate, and migration mode used while other migrations consume the same hosts, links, and switch queues. This paper presents CAREM, Counterfactual Action Reduction and Evaluation for Migration. CAREM expands each pending VM-to-destination request into feasible path/rate/mode actions, predicts migration time, downtime, energy, and SLA risk with calibrated uncertainty, removes only same-request actions that are certifiably dominated, and passes the retained actions to a residual-state global scheduler. The analysis shows why request-level scoring collapses within-request control structure, when set-wise certified reduction is locally admissible under coverage and measurement-error assumptions, and why fiber-collapsed baselines can incur continuation regret when local choices affect later scheduling. In a 128-host fat-tree simulator, CAREM improves the scalar objective by 22% over the matched collapsed baseline, reducing makespan by 17%, downtime-tail risk by 24%, and energy by 6%. Under common-testbed comparisons with representative SDN, concurrency-aware, SLA-aware, policy-aware, hybrid-mode, and adaptive-placement baselines, CAREM achieves the lowest scalar objective while retaining compatibility with recent hybrid RL/ML mode-selection and placement layers. A 32-host KVM/Open vSwitch prototype confirms lower migration time and downtime with control-loop latency inside the planning interval. | 10.1109/TNSM.2026.3730960 |
| Abderrahmane Boulahdour, Miloud Bagaa, Adlen Ksentini, Ahmed Ouameur Messaoud, Daniel Massicotte | Towards Software-Defined TSN Scheduling: An eBPF Approach for Stream Processing and Delay Analysis in Industry 5.0 | 2026 | Early Access | Streams Timing Bridges Software defined networking Delays Kernel Scheduling Schedules Modeling Hardware Industrial Networks Asynchronous TSN ATS eBPF SDN | This paper presents a software-defined Time-Sensitive Networking (TSN) architecture that implements the IEEE 802.1Qcr Asynchronous Traffic Shaper (ATS) using Extended Berkeley Packet Filter (eBPF) technology within Linux-based TSN bridges. By moving traffic shaping logic to the kernel level, our solution eliminates the need for dedicated hardware and enables dynamic, programmable control of frame filtering, metering, and queuing. A Software-Defined Networking (SDN) controller complements the design, providing centralized orchestration of TSN behavior through standardized interfaces and a unified network view. We implement the ATS scheduling model to compute and enforce per-stream eligibility times, supporting time-aware scheduling of concurrent streams within the same priority class. This enables deterministic traffic delivery, which is critical for industrial automation and control. Our approach allows seamless integration into existing infrastructures and aligns with the flexibility objectives of Industry 5.0. Performance evaluations demonstrate accurate scheduling behavior under heterogeneous traffic conditions and quantify the delay introduced by a TSN bridge for multiple coexisting streams. | 10.1109/TNSM.2026.3729563 |
| Mubashir Murshed, Glaucio H. S. Carvalho, Robson E. De Grande | Holistic Intelligent Traffic Steering Management in Multi-RAT Vehicular Networks | 2026 | Early Access | Radio access technologies Rats Vehicles Modeling Long short term memory Poles and towers 5G mobile communication Joining processes Timing Received signal strength indicator Traffic Steering Multi-RAT Network Management Bi-level GCN-LSTM SARSA High-mobility Ultra-dense networks | Multiple Radio Access Technology (multi-RAT) environments provide a promising foundation for service-aware communication in intelligent transportation systems (ITS) and smart cities. However, traffic steering (TS) in highly mobile and ultra-dense vehicular networks remains challenging due to dynamic network conditions, heterogeneous RAT capabilities, varying vehicle requirements, packet loss, latency, and frequent ping-pong RAT switching. In this context, we propose Holistic Intelligent Traffic Steering (HITS), a proactive bi-level TS management framework for multi-RAT vehicular networks. HITS integrates centralized network-wide guidance with local vehicleside decision-making. At the central level, a Graph Convolutional Network–Long Short-Term Memory (GCN–LSTM) model captures holistic spatio-temporal network dynamics and evaluates RAT optimality. At the local level, a State-Action-Reward- State-Action (SARSA) reinforcement learning agent performs adaptive, vehicle-specific RAT selection using local observations and central-level optimality guidance. Results show that HITS achieves up to 6.5% higher average throughput, reduces packet loss ratio by more than 30.2%, lowers latency by nearly 12.2%, and reduces the ping-pong RAT switching rate by over 24% compared with baseline and state-of-the-art (SoTA) TS approaches. | 10.1109/TNSM.2026.3729840 |