HeteroEdge: Latency-Aware Adaptive Protocol Parsing with Digital Twin Intelligence for Heterogeneous 5G IoT Edge Networks
Abstract
1. Introduction
- We formally define the latency-aware adaptive protocol parsing (LAPP) problem for heterogeneous 5G MEC environments and derive a multi-class M/G/1 queuing model for per-protocol parsing delay (Section 3).
- We design and implement HeteroEdge, comprising the HPPL (ML-assisted multi-stage parsing pipeline with DPDK kernel-bypass packet I/O), the NDT (lightweight edge-resident IoT endpoint state tracker), the RTIE (50 ms adaptive capacity allocator), and the WIS framework (minimax-robust proactive strategy planner). DPDK acceleration and Isolation Forest anomaly detection serve as enabling implementation components within this architecture (Section 3).
- We provide corrected mathematical formulations, revised Algorithm 2 pseudocode, and a full notation table ensuring dimensional consistency throughout the model (Section 3).
- We conduct an empirical evaluation on a physical 5G MEC testbed using two workloads and four well-characterized baselines, reporting all results as mean ± standard deviation over five independent runs with 95% confidence intervals (Section 4).
2. Related Work, Background, and Motivation
2.1. Protocol Parsing in IoT Middleware
2.2. Edge Computing and 5G MEC
2.3. Stream Processing at the Edge
2.4. Network Digital Twins
2.5. Machine-Learning-Based Protocol Classification
2.6. Motivation: The Adaptive Parsing Gap
3. Heteroedge System Design and Methodology
3.1. System Architecture
3.2. Heterogeneous Protocol Parsing Layer (HPPL)
- (1)
- Protocol taxonomy
- (2)
- Formal latency model
- (3)
- Adaptive capacity allocation
- (4)
- Multi-stage parsing pipeline
| Algorithm 1: Adaptive Protocol Classification (Stage 2) | ||
| Input: Packet pkt, flow table , GBDT model M, threshold , Aho-Corasick automaton | ||
| Output: Protocol class , flow entry | ||
| 1 | tuple(pkt) | |
| 2 | if key then | |
| 3 | return p, | |
| 4 | end if | |
| 5 | f ← ExtractFeatures(pkt) // 23 handcrafted features | |
| 6 | (, q) ← M.predict(f) // GBDT inference | |
| 7 | if q ≥ θ_conf then | |
| 8 | ← , | |
| 9 | Else | |
| 10 | ← A.scan(pkt.payload) // Fallback DPI | |
| 11 | end if | |
| 12 | ← NewFlowEntry(key, ) | |
| 13 | ||
| 14 | return , e | |
- -
- MQTT: A zero-copy state machine that maintains CONNECT/SUBSCRIBE/PUBLISH state per client identifier. Variable-length encoding (MQTT remaining-length field) is handled with a 4-byte accumulator.
- -
- CoAP: An RFC 7252-compliant parser with block-wise transfer (RFC 7959) support. DTLS record layer is decapsulated inline.
- -
- HTTP/2: An HPACK-aware parser that maintains dynamic header tables per connection. Frame multiplexing across streams is managed with a per-connection stream table (max 256 entries, LRU eviction).
- -
- gRPC: Parsed as HTTP/2 with length-prefixed protobuf payloads. The HPPL parses the gRPC framing layer; application-level protobuf decoding is optional and policy-driven.
- -
- WebSockets: Mask/unmask operations are performed using SIMD instructions (AVX2 on x86-64); frame fragmentation is reassembled into logical messages before delivery.
- -
- OPC-UA (binary): The OPC Foundation binary encoding uses a type-code/length/value scheme; our parser uses a look-up table of 312 NodeIds to resolve type metadata in O(1).
- -
- Modbus/TCP: A simple fixed-header parser; function codes are mapped to handler stubs for read/write coil, register, and input operations.
3.3. Digital Twin Modeling for Networks
- (1)
- NDT State representation
| Algorithm 2: Latency-Aware Adaptive Capacity Allocation (RTIE) | ||||
| Input: NDT snapshot , traffic counters , capacity , weights w, min allocations , latency SLAs | ||||
| Output: Updated capacity allocation | ||||
| 1 | // 87-dim state vector | |||
| 2 | ← IsolationForest.predict() // flag ∈ {0,1} | |||
| 3 | if anom = 1 then | |||
| 4 | // active protocol classes | |||
| 5 | // equal share among active | |||
| 6 | for to do | |||
| 7 | ← max( ) // floor for dormant | |||
| 8 | end for | |||
| 9 | // normalize | |||
| 10 | TriggerWIS() // schedule WIS evaluation | |||
| 11 | Return {} | |||
| 12 | end if | |||
| 13 | Solve (P1): min s.t. Equations (5)–(7) // Warm-started interior-point | |||
| 14 | ← solution of (P1) | |||
| 15 | for k = 1 to K do | |||
| 16 | if then // SLA headroom check | |||
| 17 | // Boost at-risk class 20% | |||
| 18 | Re-normalize ← project onto Equation (5) | |||
| 19 | end if | |||
| 20 | end for | |||
| 21 | // re-normalise | |||
| 22 | return {} | |||
- (2)
- NDT Update mechanism
- (3)
- NDT Compression and synchronization
3.4. Real-Time Inference Engine (RTIE)
- (1)
- Inference pipeline
- Reads the current NDT snapshot and live traffic counters from HPPL Stage 2 hardware performance counters.
- Constructs a feature vector ( features) comprising per-protocol utilizations, queue depths, recent latency percentiles, and device QoS classes.
- Runs an online lightweight anomaly detection model (Isolation Forest [44]), 50 trees) on to flag anomalous conditions.
- Solves the ACA problem Equation (4) using a warm-started interior-point solver with the previous solution as the initial point. Convergence requires 3 ms for .
- Pushes the new allocation to the HPPL worker-pool manager via a shared-memory control channel.
- (2)
- Anomaly detection and response
3.5. What-If-Simulation Framework (WIS)
- (1)
- Simulation model
- (2)
- Scenario generation
- (3)
- Strategy optimization
| Algorithm 3: Edge Inference and WIS Strategy Selection | |||
| Input: Anomaly signal, traffic history H, candidate strategies C, scenario set Σ | |||
| Output: Robust optimal strategy c* | |||
| 1 | Σ ← GenerateScenarios(H) | ||
| 2 | for each σ ∈ Σ do | ||
| 3 | for each do | ||
| 4 | Run DES for scenario σ under strategy | ||
| 5 | // Equation (11) | ||
| 6 | end for | ||
| 7 | end for | ||
| 8 | // Minimax, Equation (12) | ||
| 9 | return | ||
3.6. Implementation Details
- (1)
- Software stack
- (2)
- Deployment topology
- (3)
- Fault tolerance
4. Experimental Results
4.1. Experimental Setup
- (1)
- Hardware Testbed
- (2)
- Traffic Workloads
- (3)
- Baselines
- (4)
- Metrics
- (5)
- Machine Learning Classification Methodology
4.2. Results and Evaluation
- (1)
- Latency
- (2)
- Classification Accuracy
- (3)
- Throughput and Resource Utilization
- (4)
- SLA Violation Rate
- (5)
- WIS Effectiveness
- (6)
- NDT Synchronization Overhead
4.3. Discussion
4.4. Limitations and Future Work
5. Conclusions
Supplementary Materials
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| ACA | Adaptive Capacity Allocation |
| BF | Behavioral Fingerprinting |
| CDF | Cumulative Distribution Function |
| CoAP | Constrained Application Protocol |
| CRDT | Conflict-Free Replicated Data Type |
| DES | Discrete-Event Simulation |
| DPI | Deep Packet Inspection |
| ECDF | Empirical Cumulative Distribution Function |
| ETSI | European Telecommunications Standards Institute |
| GBDT | Gradient-Boosted Decision Tree |
| gNB | Next-Generation Node B (5G Base Station) |
| gRPC | Google Remote Procedure Call |
| HPPL | Heterogeneous Protocol Parsing Layer |
| HTTP | Hypertext Transfer Protocol |
| IoT | Internet of Things |
| JA3 | TLS Client Fingerprinting Method |
| LwM2M | Lightweight Machine-to-Machine |
| MEC | Multi-access Edge Computing |
| ML | Machine Learning |
| MQTT | Message Queuing Telemetry Transport |
| NDT | Network Digital Twin |
| NR | New Radio (5G Air Interface) |
| OPC-UA | Open Platform Communications Unified Architecture |
| PIM | Protocol-Independent Message |
| PLC | Programmable Logic Controller |
| QoS | Quality of Service |
| QUIC | Quick UDP Internet Connections |
| RAN | Radio Access Network |
| RDMA | Remote Direct Memory Access |
| RoCE | RDMA over Converged Ethernet |
| RTIE | Real-Time Inference Engine |
| SLA | Service Level Agreement |
| TCP | Transmission Control Protocol |
| TLS | Transport Layer Security |
| URLLC | Ultra-Reliable Low-Latency Communications |
| WIS | What-If Simulation |
Appendix A
| Symbol | Definition | Units |
|---|---|---|
| Number of protocol classes | dimensionless | |
| Number of MEC nodes | dimensionless | |
| Arrival rate of protocol-k flows at time slot t | flows | |
| Parsing capacity allocated to protocol k on node n at time t | CPU cycles | |
| Mean per-packet parsing cost for protocol k | cycles | |
| Variance of per-packet service time for protocol k | ||
| Effective service rate | ||
| Per-class | dimensionless | |
| Total | dimensionless | |
| Mean parsing delay for protocol k at node | s | |
| Aggregate mean weighted parsing delay | s | |
| SLA-defined priority weight for protocol k | dimensionless | |
| Maximum allowable EPL for protocol k | s | |
| Total parsing throughput budget of node n | CPU cycles | |
| Anti-starvation minimum allocation for protocol k | CPU cycles | |
| Full end-to-end latency for flow (Equation (3)) | s | |
| 5G NR air-interface latency | s | |
| Back-haul transmission latency | s | |
| EWMA decay factor for NDT arrival-rate estimation | dimensionless | |
| Expected weighted latency under strategy in scenario | s |
References
- Kołaczek, G. Internet of Things (Iot) Technologies in Cybersecurity: Challenges and Opportunities. Appl. Sci. 2025, 15, 2935. [Google Scholar] [CrossRef] [Scilit]
- Jiang, W.; Han, B. Evolution to Fifth-Generation (5G) Mobile Cellular Communications. In Cellular Communication Networks and Standards: The Evolution from 1G to 6G; Springer: Berlin/Heidelberg, Germany, 2024; pp. 149–168. [Google Scholar]
- Kiruthiga Devi, M.; Padma Priya, M. Evolution of next Generation Networks and Its Contribution towards Industry 5.0. In Resource Management in Advanced Wireless Networks; Wiley: Hoboken, NJ, USA, 2025; pp. 45–80. [Google Scholar]
- Ericsson Ericsson Mobility Report. Ericsson, Tech. Rep., November 2025. Available online: https://img.corrierecomunicazioni.it/wp-content/uploads/2025/11/19180335/EMR-November-2025_report_web.pdf (accessed on 30 June 2026).
- Khattak, M.I.; Yuan, H.; Khan, A.; Ahmad, A.; Ullah, I.; Ahmed, M. Evolving Multi-Access Edge Computing (MEC) for Diverse Ubiquitous Resources Utilization: A Survey. Telecommun. Syst. 2025, 88, 71. [Google Scholar] [CrossRef] [Scilit]
- Adu, E.; Lee, Y.; Moon, J.; Jang, S.; Bang, I.; Kim, T. Decentralized Computation Offloading Strategy via Multi-Agent Deep Reinforcement Learning for Multi-Access Edge Computing Systems. Sensors 2026, 26, 914. [Google Scholar] [PubMed]
- Zhu, J.; Yuan, J.; Ye, F.; Nguyen, T.T.; Wang, R.; Zeng, W.; Liu, C.-C. Traffic Prediction Using an Active Causality Recurrent Graph Convolutional Network. Expert Syst. Appl. 2025, 298, 129506. [Google Scholar] [CrossRef] [Scilit]
- Nguyen, T.-T.; Ngo, T.-G.; Chu, S.-C.; Dao, T.-K.; Nguyen, T.-T.-T. Recent Digital Systems Information Hiding Techniques via Internet Technology: A Review. J. Internet Technol. 2025, 26, 641–652. [Google Scholar] [CrossRef] [Scilit]
- Lin, D.; Gong, X.; Liu, X.; Chen, L.; Xu, Z.; Dong, P. Dynamic Protocol Parse Based on a General Protocol Description Language. Electronics 2026, 15, 270. [Google Scholar] [CrossRef] [Scilit]
- Sriram, A.; Manikandan, D.; Venketesan, R.; Ramaswamy, K. Optimized IoT Protocol Stack for Seamless Smart Home Communication Using Random Forest-Based Interoperability Analysis. Sci. Rep. 2025, 15, 40092. [Google Scholar] [PubMed]
- Jesus, B.; Lins, F.; Laranjeiro, N. An Approach to Assess Robustness of MQTT-Based IoT Systems. Internet Things 2025, 31, 101590. [Google Scholar] [CrossRef] [Scilit]
- Maracine, N.-A.; Tranca, D.-C.; Rughinis, R.-V.; Sava, L. Heterogeneous Communications in Industrial IoT: Trends, Challenges, and Opportunities. In Proceedings of the 2025 24th RoEduNet Conference: Networking in Education and Research (RoEduNet), Chisinau, Moldova, 17–20 September 2025; pp. 1–6. [Google Scholar]
- 3GPP. System Architecture for the 5G System (5GS); Stage 2. 2022. Available online: https://www.3gpp.org/technologies/5g-system-overview (accessed on 30 June 2026).
- Petrescu, I.; Niculae, E.; Vulturescu, V.; Dimitrescu, A.; Ungureanu, L.M. Transport and Application Layer Protocols for IoT: Comprehensive Review. Technologies 2025, 13, 583. [Google Scholar] [CrossRef] [Scilit]
- ETSI. Multi-Access Edge Computing (MEC) Framework and Reference Architecture; ETSI GS MEC: Sophia Antipolis, France, 2020. [Google Scholar]
- Bartoli, C.; Bonanni, M.; Chiti, F.; Pierucci, L. The Alliance of SDN and MQTT for the Web of Industrial Things. IEEE Trans. Ind. Inform. 2025, 21, 4367–4376. [Google Scholar] [CrossRef] [Scilit]
- Ke, H.; Wang, H.; Sun, W.; Sun, H. Adaptive Computation Offloading Policy for Multi-Access Edge Computing in Heterogeneous Wireless Networks. IEEE Trans. Netw. Serv. Manag. 2021, 19, 289–305. [Google Scholar] [CrossRef] [Scilit]
- Bosshart, P.; Daly, D.; Gibb, G.; Izzard, M.; McKeown, N.; Rexford, J.; Schlesinger, C.; Talayco, D.; Vahdat, A.; Varghese, G.; et al. P4: Programming Protocol-Independent Packet Processors. In Proceedings of the ACM SIGCOMM Computer Communication Review; ACM: New York, NY, USA, 2014; Volume 44, pp. 87–95. [Google Scholar]
- Ravulavaru, A. Enterprise Internet of Things Handbook: Build End-to-End IoT Solutions Using Popular IoT Platforms; Packt Publishing Ltd.: Birmingham, UK, 2018; Available online: https://books.google.com.tw/books?id=jPBZDwAAQBAJ (accessed on 30 June 2026).
- Pfaff, B.; Pettit, J.; Koponen, T.; Jackson, E.; Zhou, A.; Rajahalme, J.; Gross, J.; Wang, A.; Stringer, J.; Shelar, P.; et al. The Design and Implementation of Open {vSwitch}. In Proceedings of the 12th USENIX Symposium on Networked Systems Design and Implementation (NSDI), Oakland, CA, USA, 4–6 May 2015; pp. 117–130. [Google Scholar]
- Mao, Y.; You, C.; Zhang, J.; Huang, K.; Letaief, K.B. A Survey on Mobile Edge Computing: The Communication Perspective. IEEE Commun. Surv. Tutor. 2017, 19, 2322–2358. [Google Scholar] [CrossRef] [Scilit]
- Shi, W.; Cao, J.; Zhang, Q.; Li, Y.; Xu, L. Edge Computing: Vision and Challenges. IEEE Internet Things J. 2016, 3, 637–646. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Jiao, L.; Li, W.; Fu, X. Efficient Multi-User Computation Offloading for Mobile-Edge Cloud Computing. IEEE/ACM Trans. Netw. 2016, 24, 2795–2808. [Google Scholar]
- Ateya, A.A.; Algarni, A.D.; Hamdi, M.; Koucheryavy, A.; Soliman, N.F. Enabling Heterogeneous IoT Networks over 5G Networks with Ultra-Dense Deployment—Using MEC/SDN. Electronics 2021, 10, 910. [Google Scholar]
- Serepas, F.; Papias, I.; Christakis, K.; Dimitropoulos, N.; Marinakis, V. Lightweight Embedded IoT Gateway for Smart Homes Based on an ESP32 Microcontroller. Computers 2025, 14, 391. [Google Scholar] [CrossRef] [Scilit]
- Azad, T.; Newton, M.A.H.; Trevathan, J.; Sattar, A. IoT Edge Network Interoperability. Comput. Commun. 2025, 236, 108125. [Google Scholar] [CrossRef] [Scilit]
- Carbone, P.; Katsifodimos, A.; Ewen, S.; Markl, V.; Haridi, S.; Tzoumas, K. Apache Flink: Stream and Batch Processing in a Single Engine. Bull. Tech. Comm. Data Eng. 2015, 38, 28–38. [Google Scholar]
- Gupta, A.; Harrison, R.; Canini, M.; Feamster, N.; Rexford, J.; Walker, W. SONATA: Query-Driven Streaming Network Telemetry. In Proceedings of the ACM SIGCOMM Conference, Budapest, Hungary, 20–25 August 2018; pp. 247–260. [Google Scholar]
- Sedlak, B.; Casamayor Pujol, V.; Morichetta, A.; Donta, P.K.; Dustdar, S. Adaptive Stream Processing on Edge Devices through Active Inference. Evol. Syst. 2025, 16, 130. [Google Scholar] [CrossRef] [Scilit]
- Grieves, M.; Vickers, J. Digital Twin: Mitigating Unpredictable, Undesirable Emergent Behavior in Complex Systems. In Transdisciplinary Perspectives on Complex Systems; Springer: Cham, Switzerland, 2017; pp. 85–113. [Google Scholar]
- Khan, L.U.; Han, Z.; Saad, W.; Hossain, E.; Guizani, M.; Hong, C.S. Digital Twin of Wireless Systems: Overview, Taxonomy, Challenges, and Opportunities. IEEE Commun. Surv. Tutor. 2022, 24, 2230–2254. [Google Scholar] [CrossRef] [Scilit]
- Dong, R.; She, C.; Hardjawana, W.; Li, Y.; Vucetic, B. Deep Learning for Hybrid 5G Services in Mobile Edge Computing Systems: Learn from a Digital Twin. IEEE Trans. Wirel. Commun. 2019, 18, 4692–4707. [Google Scholar] [CrossRef] [Scilit]
- Ren, Y.; Guo, S.; Cao, B.; Qiu, X. End-to-End Network SLA Quality Assurance for C-RAN: A Closed-Loop Management Method Based on Digital Twin Network. IEEE Trans. Mob. Comput. 2023, 23, 4405–4422. [Google Scholar]
- Wang, J.; Li, J.; Liu, J. Digital Twin-Assisted Flexible Slice Admission Control for 5G Core Network: A Deep Reinforcement Learning Approach. Future Gener. Comput. Syst. 2024, 153, 467–476. [Google Scholar]
- Moore, A.W.; Zuev, D. Internet Traffic Classification Using Bayesian Analysis Techniques. ACM Sigmetrics Perform. Eval. Rev. 2005, 33, 50–60. [Google Scholar] [CrossRef] [Scilit]
- Lotfollahi, M.; Siavoshani, M.J.; Zade, R.S.H.; Saberian, M. Deep Packet: A Novel Approach for Encrypted Traffic Classification Using Deep Learning. Soft Comput. 2020, 24, 1999–2012. [Google Scholar] [CrossRef] [Scilit]
- Rezaei, S.; Liu, X. Deep Learning for Encrypted Traffic Classification: An Overview. IEEE Commun. Mag. 2019, 57, 76–81. [Google Scholar] [CrossRef] [Scilit]
- Kleinrock, L. Queueing Systems: Theory; Wiley: Hoboken, NJ, USA, 1974; Volume 2. [Google Scholar]
- Chan, W.C.; Lu, T.; Chen, R. Pollaczek–Khinchin Formula for the M/G/1 Queue in Discrete Time with Vacations. IEE Proc.-Comput. Digit. Tech. 1997, 144, 222–226. [Google Scholar]
- Freund, R.W.; Jarre, F. Solving the Sum-of-Ratios Problem by an Interior-Point Method. J. Glob. Optim. 2001, 19, 83–102. [Google Scholar]
- Chen, T.; Guestrin, C. XGBoost: A Scalable Tree Boosting System. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA, 13–17 August 2016; pp. 785–794. [Google Scholar]
- Aho, A.V.; Corasick, M.J. Efficient String Matching: An Aid to Bibliographic Search. Commun. ACM 1975, 18, 333–340. [Google Scholar] [CrossRef] [Scilit]
- Shapiro, M.; Preguiça, N.; Baquero, C.; Zawirski, M. Conflict-Free Replicated Data Types. In Proceedings of the 13th International Symposium on Stabilization, Safety, and Security of Distributed Systems (SSS); Springer: Cham, Switzerland, 2011; pp. 386–400. [Google Scholar]
- Liu, F.T.; Ting, K.M.; Zhou, Z.-H. Isolation Forest. In Proceedings of the 8th IEEE International Conference on Data Mining (ICDM), Pisa, Italy, 15–19 December 2008; pp. 413–422. [Google Scholar]
- Boyd, S.; Vandenberghe, L. Convex Optimization; Cambridge University Press: Cambridge, UK, 2004. [Google Scholar]
- Karger, D.; Lehman, E.; Leighton, T.; Panigrahy, R.; Levine, M.; Lewin, D. Consistent Hashing and Random Trees: Distributed Caching Protocols for Relieving Hot Spots on the World Wide Web. In Proceedings of the 29th ACM Symposium on Theory of Computing (STOC), El Paso, TX, USA, 4–6 May 1997; pp. 654–663. [Google Scholar]
- Kovatsch, M.; Lanter, M.; Shelby, Z. Californium: Scalable Cloud Services for the Internet of Things with CoAP. In Proceedings of the 4th International Conference on the Internet of Things (IoT), Cambridge, MA, USA, 6–8 October 2014; pp. 1–8. [Google Scholar]
- Center for Applied Internet Data Analysis (CAIDA). The CAIDA UCSD Network Telescope Traffic Dataset. Available online: https://www.caida.org/catalog/datasets/telescope-near-real-time_dataset/ (accessed on 10 June 2026).
- Neto, E.C.P.; Dadkhah, S.; Ferreira, R.; Zohourian, A.; Lu, R.; Ghorbani, A.A. CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors 2023, 23, 5941. [Google Scholar] [PubMed]
- Chen, R.; Dai, T.; Zhang, Y.; Zhu, Y.; Liu, X.; Zhao, E. GBDT-IL: Incremental Learning of Gradient Boosting Decision Trees to Detect Botnets in Internet of Things. Sensors 2024, 24, 2083. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Martínez Hernández, L.A.; Pérez Arteaga, S.; Sandoval Orozco, A.L.; García Villalba, L.J. Adversarial Attacks on Machine Learning Models for Network Traffic Filtering. Eng. Proc. 2026, 123, 23. [Google Scholar] [CrossRef] [Scilit]
- Parisi, G.I.; Kemker, R.; Part, J.L.; Kanan, C.; Wermter, S. Continual Lifelong Learning with Neural Networks: A Review. Neural Netw. 2019, 113, 54–71. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Lin, H.; Chung, J.W.; Lao, Y.; Zhao, W. Online Gradient Boosting Decision Tree: In-Place Updates for Efficient Adding/Deleting Data. arXiv 2025, arXiv:2502.01634. [Google Scholar]
- Fezeu, R.A.K.; Fiandrino, C.; Ramadan, E.; Carpenter, J.; De Freitas, L.C.; Bilal, F.; Ye, W.; Widmer, J.; Qian, F.; Zhang, Z.-L. Unveiling the 5G Mid-Band Landscape: From Network Deployment to Performance and Application QoE. In Proceedings of the ACM SIGCOMM 2024 Conference, Sydney, Australia, 4–8 August 2024; pp. 358–372. [Google Scholar]
- Rappaport, T.S.; Xing, Y.; MacCartney, G.R.; Molisch, A.F.; Mellios, E.; Zhang, J. Overview of Millimeter Wave Communications for Fifth-Generation (5G) Wireless Networks—With a Focus on Propagation Models. IEEE Trans. Antennas Propag. 2017, 65, 6213–6230. [Google Scholar] [CrossRef] [Scilit]













| Category | Representative Works | Core Capability | Edge Suitability & Latency | Key Limitation |
|---|---|---|---|---|
| IoT Middleware Parsers | Kaa [19], AWS IoT Core | Full application-layer parsing | ✗ Cloud-centric; △ moderate latency | Sequential, non-adaptive processing |
| Programmable Data Planes | [18,20] | Line-rate packet classification (L2–L4) | ✓ High; ✓ line-rate | No application-layer semantics |
| Edge Computing/MEC | ETSI MEC [15], 3GPP SBA [13,21,22,23] | Edge infrastructure & task offloading | ✓ Native; ✓ latency-aware | No protocol parsing support |
| Edge IoT Gateways | integrating MEC with SDN [24,25,26] | Application-layer protocol translation | ✓ Moderate; △ limited optimization | Static, non-adaptive pipelines |
| Stream Processing Frameworks | Flink [27], Kafka Streams, Sonata [28,29] | Distributed stream analytics | ✗ Heavyweight for MEC; △ latency | Resource-intensive; not line-rate |
| Network Digital Twins | [30,31,32,33,34] | Network state modeling & simulation | ✓ Moderate; △ indirect latency benefits | No application-layer parsing focus |
| ML-based Classification | [35,36,37] | Traffic classification via ML | ✗ Limited (large models); △ latency | High resource usage; lacks deep parsing |
| HeteroEdge (This Work) | — | Adaptive cross-layer parsing (L2–L7) | ✓ MEC-native; ✓ low-latency, line-rate | — |
| Parameter | Value |
|---|---|
| MEC nodes | 4 MEC nodes (two active + two standby for fault tolerance) |
| CPU per node | Xeon Silver 4316, 20 cores @ 2.3 GHz (match actual hardware spec) |
| Memory per node | 128 GB DDR4-3200 (match actual hardware spec) |
| NIC | 25 Gbps DPDK-enabled |
| IoT devices | 2000 emulated devices via 16 Raspberry Pi 4B units. The ‘10k devices’ figure refers to a scaled simulation |
| Device types | Sensors (70%), Gateways (20%), PLCs (10%) |
| 5G NR latency | 5–10 ms |
| Throughput basis | 18 Gbps is DPDK NIC-injection throughput 5G air-interface tests are bounded by ~2 Gbps. |
| Backhaul latency | 2 ms |
| HPPL workers per node | 16 |
| RTIE interval (ΔT) | 50 ms |
| NDT sync interval | 500 ms |
| Per-protocol SLA ( | MQTT/Modbus/OPC-UA: 5 CoAP/LwM2M: 10 ms; HTTP/2/gRPC: 8 ms; WebSocket: 8 ms; HTTP/1.1/Thrift: 15 ms; HTTP/3: 6 ms; PROFINET: 4 ms |
| Software stack | DPDK 22.11, XGBoost 1.7, SimPy 4.0 |
| Experiment repetitions | 5 independent runs (different burst-injection seeds) |
| Protocol | Category | Avg Packet (B) | Arrival Rate (Flows/s) | QoS Class | Traffic Pattern |
|---|---|---|---|---|---|
| HTTP/2 | Web | 1200 | 800 | Latency-sensitive | Bursty |
| WebSockets | Web | 900 | 500 | Latency-sensitive | Persistent |
| MQTT | IoT-native | 200 | 2000 | Ultra-reliable | Periodic |
| CoAP | IoT-native | 150 | 1500 | Best-effort | Poisson |
| LwM2M | IoT-native | 180 | 600 | Best-effort | Periodic |
| gRPC | RPC | 1000 | 700 | Latency-sensitive | Bursty |
| Thrift | RPC | 950 | 400 | Best-effort | Poisson |
| OPC-UA | Industrial | 1100 | 300 | Ultra-reliable | Periodic |
| Modbus/TCP | Industrial | 120 | 1200 | Ultra-reliable | Periodic |
| PROFINET | Industrial | 100 | 900 | Ultra-reliable | Deterministic |
| Baseline | Implementation | Hardware/Software | Optimization Applied | Fairness Notes |
|---|---|---|---|---|
| Cloud-Only (CO) | All application-layer parsing is executed in the cloud; the MEC node acts only as an L3 forwarder. | AWS c5.4xlarge (16 vCPUs, 32 GB RAM); same XGBoost 1.7 classifier as HeteroEdge. | No latency optimization; identical classifier hyperparameters. | Uses the same ML model as HeteroEdge, ensuring that latency differences reflect cloud backhaul overhead rather than classifier design. |
| Static MEC (SM) | HeteroEdge HPPL deployed on the MEC cluster with fixed equal-capacity allocation across all 12 protocol classes; ACA, NDT, and WIS disabled. | Same 4-node MEC cluster (Xeon Silver 4316), DPDK 22.11, XGBoost 1.7. | Same DPDK optimizations as HeteroEdge; no adaptive allocation. | Isolates the benefit of adaptive resource allocation while maintaining identical edge infrastructure. |
| DPI-Based (DPI) | Rule-based packet classification using an 847-entry signature dictionary on a P4-programmable switch emulator; no semantic payload parsing. | BMv2 P4 software switch on the same MEC hardware. | Aho–Corasick signature matching; no ML inference. | Evaluates classification latency and accuracy of traditional DPI without adaptive intelligence or semantic parsing. |
| ML-Static (MLS) | Same GBDT classifier as HeteroEdge with static equal-capacity allocation; ACA, NDT, and WIS disabled. | Same 4-node MEC cluster, DPDK 22.11, XGBoost 1.7. | Same DPDK, SIMD, and AVX2 optimizations as HeteroEdge. | Isolates the contribution of the ACA, NDT, and WIS adaptive mechanisms beyond ML-based protocol classification. |
| Method | W1 L50 (ms) | W1 L95 (ms) | W2 L50 (ms) | W2 L95 (ms) |
|---|---|---|---|---|
| Cloud-Only | 47.1 ± 1.2 | 61.3 ± 1.8 | 43.8 ± 1.4 | 58.2 ± 1.9 |
| Static MEC | 11.4 ± 0.4 | 20.1 ± 0.7 | 10.8 ± 0.5 | 18.4 ± 0.6 |
| DPI-Based | 8.2 ± 0.3 | 14.3 ± 0.5 | 7.9 ± 0.3 | 13.1 ± 0.4 |
| ML-Static | 9.7 ± 0.3 | 16.8 ± 0.6 | 9.1 ± 0.4 | 15.6 ± 0.5 |
| HeteroEdge | 6.3 ± 0.2 | 11.2 ± 0.4 | 6.0 ± 0.2 | 11.2 ± 0.4 |
| HeteroEdge-noWIS | 6.8 ± 0.3 | 17.6 ± 0.7 | 6.5 ± 0.3 | 16.9 ± 0.6 |
| Method | Avg Latency (ms) | P95 (ms) | P99 (ms) | SLA Violations (%) |
|---|---|---|---|---|
| Static Allocation | 42.5 | 88.2 | 130.4 | 12.6 |
| Round-Robin | 38.7 | 79.5 | 118.3 | 10.2 |
| Load-Based Heuristic | 31.4 | 65.2 | 95.7 | 6.8 |
| HeteroEdge (proposed) | 21.6 | 40.8 | 62.3 | 2.1 |
| Protocol | Precision (%) | Recall (%) | F1-Score (%) | Support (Flows) |
|---|---|---|---|---|
| MQTT v3.1.1 + v5.0 | 99.2 ± 0.3 | 99.3 ± 0.2 | 99.2 ± 0.2 | 99,225 |
| CoAP (DTLS) | 98.5 ± 0.4 | 98.7 ± 0.3 | 98.6 ± 0.3 | 40,470 |
| HTTP/1.1 | 96.0 ± 0.6 | 96.4 ± 0.5 | 96.2 ± 0.5 | 15,960 |
| HTTP/2 | 94.0 ± 0.8 | 94.2 ± 0.7 | 94.1 ± 0.7 | 26,790 |
| HTTP/3 (QUIC) | 98.9 ± 0.4 | 99.2 ± 0.3 | 99.1 ± 0.3 | 14,820 |
| WebSockets | 97.8 ± 0.5 | 98.5 ± 0.4 | 98.2 ± 0.4 | 23,085 |
| gRPC | 97.3 ± 0.5 | 97.7 ± 0.4 | 97.5 ± 0.4 | 19,950 |
| Apache Thrift | 95.9 ± 0.8 | 96.7 ± 0.7 | 96.3 ± 0.7 | 8835 |
| OPC-UA (binary) | 99.3 ± 0.3 | 99.7 ± 0.2 | 99.5 ± 0.2 | 21,375 |
| Modbus/TCP | 99.7 ± 0.2 | 100.0 ± 0.1 | 99.9 ± 0.1 | 52,155 |
| PROFINET | 97.1 ± 0.7 | 98.2 ± 0.5 | 97.7 ± 0.5 | 4560 |
| LwM2M | 98.2 ± 0.5 | 99.1 ± 0.4 | 98.7 ± 0.4 | 8265 |
| Macro Average | 97.7 ± 0.2 | 97.9 ± 0.2 | 97.8 ± 0.2 | 335,490 |
| Weighted Average | 98.6 ± 0.1 | 98.7 ± 0.1 | 98.6 ± 0.1 | 335,490 |
| Method | CPU Utilization (%) | Memory (MB) | Throughput (k pkt/s) |
|---|---|---|---|
| Static Allocation | 68 | 2100 | 520 |
| Round-Robin | 72 | 2200 | 540 |
| Load-Based Heuristic | 79 | 2300 | 590 |
| HeteroEdge | 85 | 2400 | 680 |
| Method | Normal (60%) | High (85%) | Burst |
|---|---|---|---|
| Cloud-Only | 0.0 | 3.1 | 22.4 |
| Static MEC | 0.0 | 5.7 | 18.3 |
| DPI-Based | 0.0 | 4.2 | 15.1 |
| ML-Static | 0.0 | 3.8 | 12.6 |
| HeteroEdge | 0.0 | 1.2 | 4.7 |
| Configuration | Avg EPL (ms) | P95 EPL (ms) | SLA Violations (%) | Throughput (k pkt/s) |
|---|---|---|---|---|
| Full HeteroEdge | 6.0 ± 0.2 | 11.2 ± 0.4 | 0.6 ± 0.1 | 680 ± 12 |
| −WIS (reactive only) | 6.5 ± 0.3 | 16.9 ± 0.6 | 2.1 ± 0.2 | 672 ± 14 |
| −NDT (no state tracking) | 7.4 ± 0.4 | 18.2 ± 0.7 | 4.3 ± 0.3 | 651 ± 16 |
| −ACA (static allocation) | 9.1 ± 0.4 | 15.6 ± 0.5 | 3.8 ± 0.2 | 635 ± 15 |
| HPPL only (−ACA, −NDT, −WIS) | 10.8 ± 0.5 | 18.4 ± 0.6 | 5.7 ± 0.3 | 610 ± 18 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Huang, X.; Dao, T.-K.; Nguyen, T.-T. HeteroEdge: Latency-Aware Adaptive Protocol Parsing with Digital Twin Intelligence for Heterogeneous 5G IoT Edge Networks. Entropy 2026, 28, 765. https://doi.org/10.3390/e28070765
Huang X, Dao T-K, Nguyen T-T. HeteroEdge: Latency-Aware Adaptive Protocol Parsing with Digital Twin Intelligence for Heterogeneous 5G IoT Edge Networks. Entropy. 2026; 28(7):765. https://doi.org/10.3390/e28070765
Chicago/Turabian StyleHuang, Xiangping, Thi-Kien Dao, and Trong-The Nguyen. 2026. "HeteroEdge: Latency-Aware Adaptive Protocol Parsing with Digital Twin Intelligence for Heterogeneous 5G IoT Edge Networks" Entropy 28, no. 7: 765. https://doi.org/10.3390/e28070765
APA StyleHuang, X., Dao, T.-K., & Nguyen, T.-T. (2026). HeteroEdge: Latency-Aware Adaptive Protocol Parsing with Digital Twin Intelligence for Heterogeneous 5G IoT Edge Networks. Entropy, 28(7), 765. https://doi.org/10.3390/e28070765

