Next Issue
Volume 18, July
Previous Issue
Volume 18, May
 
 

Future Internet, Volume 18, Issue 6 (June 2026) – 59 articles

Cover Story (view full-size image): Contemporary vulnerability management relies on CVSS and EPSS, both of which evaluate CVE entries in isolation, disregarding network topology. This research presents the Dynamic Security Resistance Distance (DSRD) framework, which parses Docker Compose, GNS3, and Containerlab files into weighted attack graphs where edge conductance reflects EPSS exploitability. Version-aware filtering matches CVEs against software versions in image tags, reducing version-irrelevant CVE matches by up to 97%. Kirchhoff effective resistance yields a structural compromise affinity guaranteed not to increase upon patching. Four algorithms rank vulnerabilities in terms of structural impact on network-wide risk. Evaluation on nine representative topologies shows that graph-aware prioritization reduces structural risk more effectively than EPSS-only ordering. View this paper
  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list.
  • You may sign up for e-mail alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.
Order results
Result details
Section
Select all
Export citation of selected articles as:
26 pages, 2202 KB  
Article
A Multi-Seed Analysis of Adversarial Vulnerability in BiLSTM Continuous Authentication
by Ahmed Mahfouz, Mohammed Abdulla Salim Al Husaini, Alaa A. K. Ismaeel and Yousuf Al Husaini
Future Internet 2026, 18(6), 332; https://doi.org/10.3390/fi18060332 - 22 Jun 2026
Viewed by 552
Abstract
A single user-invariant tensor, kinematically impossible for any human finger to produce, bypasses bidirectional long short-term memory (BiLSTM) continuous-authentication defenders with numerically identical structure across four independently trained generators. We arrive at this finding by training generative adversarial networks against BiLSTM defenders on [...] Read more.
A single user-invariant tensor, kinematically impossible for any human finger to produce, bypasses bidirectional long short-term memory (BiLSTM) continuous-authentication defenders with numerically identical structure across four independently trained generators. We arrive at this finding by training generative adversarial networks against BiLSTM defenders on 51 users across three independent random seeds, with the data partition held fixed, to test the prevailing assumption that successful generative attacks must reproduce the victim’s kinematic behavior. Aggregate attack success rate varies from 31.4% to 45.1% across seeds, a 13.7 percentage-point spread arising purely from optimization stochasticity, demonstrating how unreliable single-seed reporting is as an estimator of the true attack surface. A four-group descriptive stratification shows that 8% of users are attacked across all three seeds, 31% are consistently safe, and 61% exhibit seed-dependent outcomes. Classifier accuracy on zero-effort impostors does not predict adversarial vulnerability (Spearman ρ=0.058, permutation p=0.688), whereas intra-user behavioral variance does (ρ=+0.351, permutation p=0.012, Bonferroni-corrected). The mechanism is not behavioral emulation but convergence to an Adversarial Skeleton Key, a tensor located in an unregularized region of the BiLSTM’s decision surface that the network reliably maps to acceptance, despite lying many standard deviations outside any genuine human distribution. The mimicry-centric evaluation paradigm underestimates the real threat surface. Input-space plausibility must be treated as a defensive layer rather than a preprocessing concern. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Graphical abstract

18 pages, 1548 KB  
Article
Machine Learning-Based Diabetes Risk Prediction via DiaHealth Dataset with Explainable AI and Streamlit Deployment
by Samson Adeyemi, Muhammad Zahid Iqbal and Md Golam Muttaquee Talukder
Future Internet 2026, 18(6), 331; https://doi.org/10.3390/fi18060331 - 21 Jun 2026
Viewed by 857
Abstract
The growing worldwide prevalence of Diabetes Mellitus highlights the urgent need for effective early detection methods to enable prompt intervention. This study develops a machine learning-based decision-support prototype for predicting diabetes risk using health metrics from the DiaHealth dataset, a recently published Bangladeshi [...] Read more.
The growing worldwide prevalence of Diabetes Mellitus highlights the urgent need for effective early detection methods to enable prompt intervention. This study develops a machine learning-based decision-support prototype for predicting diabetes risk using health metrics from the DiaHealth dataset, a recently published Bangladeshi open-source dataset for Type 2 diabetes prediction. Five supervised learning algorithms were evaluated: Logistic Regression (LR), Support Vector Machine (SVM), K-Nearest Neighbour (KNN), Decision Tree (DT), and Random Forest (RF). Models were assessed across three stages: before feature scaling, after standardisation, and following hyperparameter optimisation via GridSearchCV, using accuracy, precision, recall, and F1-score as evaluation metrics. LR and SVM showed marked improvements after standardisation, consistent with their sensitivity to feature magnitude, whilst tree-based approaches such as DT and RF remained largely unchanged. KNN displayed minimal sensitivity to scaling, which is discussed in relation to the feature distributions of the dataset. Following hyperparameter tuning, RF achieved the highest accuracy of 95%, outperforming all other models. RF predictions were interpreted using Local Interpretable Model-agnostic Explanations (LIME) to promote transparency in model decision-making. The best-performing model was subsequently deployed as an interactive web-based prototype application using Streamlit, providing real-time prediction outputs. These findings demonstrate how preprocessing choices and hyperparameter tuning can differentially affect algorithm performance and illustrate the potential of combining explainable AI with practical deployment for diabetes risk assessment in a research context. Full article
(This article belongs to the Special Issue The Future Internet of Medical Things, 3rd Edition)
Show Figures

Graphical abstract

33 pages, 28731 KB  
Article
RiDTwin: XR-First Operator Support and Maintenance for Textile Manufacturing with AR, VR and an Intelligent Virtual Assistant
by André Costa, João Miranda, João Mirra, Nuno Dinis, Luís Romero and Pedro Miguel Faria
Future Internet 2026, 18(6), 330; https://doi.org/10.3390/fi18060330 - 17 Jun 2026
Viewed by 613
Abstract
This article presents an integrated approach that combines Virtual Reality (VR), Augmented Reality (AR), and an Intelligent Virtual Assistant (IVA) to support training, on-the-job assistance, and maintenance in a textile manufacturing environment. The solution spans three systems: RioRV, a Unity-based VR platform for [...] Read more.
This article presents an integrated approach that combines Virtual Reality (VR), Augmented Reality (AR), and an Intelligent Virtual Assistant (IVA) to support training, on-the-job assistance, and maintenance in a textile manufacturing environment. The solution spans three systems: RioRV, a Unity-based VR platform for immersive, step-by-step procedure rehearsal, instructional videos, and simplified 3D animations; RiAR, a mobile AR application for assisted maintenance and access to real-time and historical machine data using marker-based (VuMark) identification; and Ria, a web-based IVA that delivers document-grounded answers, operational queries over a secure plant API, short-horizon forecasting, and a narrow set of guarded remote actions. The architecture prioritizes human-centered Industry 5.0 principles—safety, usability, and resilience—by enabling operators to learn procedures in VR, execute tasks with AR overlays and maintenance media at the workstation, and obtain concise, source-cited guidance via the IVA without leaving immersion. In the case study with a spinning section at RIOPELE, the convergence of VR, AR, and IVA reduced reliance on bulky manuals, shortened time-to-information for machine status, and established a feedback loop in which training and operational experience continuously enrich the knowledge base. Full article
Show Figures

Figure 1

24 pages, 453 KB  
Article
AI-Augmented Compliance Auditing for Cloud Systems: A Hybrid ML–LLM Approach
by Moïse Iradukunda Ingabire and Jema David Ndibwile
Future Internet 2026, 18(6), 329; https://doi.org/10.3390/fi18060329 - 17 Jun 2026
Viewed by 639
Abstract
Manual compliance auditing in cloud environments consumes up to 40% of IT security budgets annually, yet existing approaches verify control presence rather than effectiveness, leaving institutions vulnerable to adversarial evasion. This paper presents an AI-augmented hybrid ML–LLM compliance auditing system evaluated on [...] Read more.
Manual compliance auditing in cloud environments consumes up to 40% of IT security budgets annually, yet existing approaches verify control presence rather than effectiveness, leaving institutions vulnerable to adversarial evasion. This paper presents an AI-augmented hybrid ML–LLM compliance auditing system evaluated on Rwanda’s National Cyber Security Authority (NCSA) Minimum Cybersecurity Standards (169 controls across 14 families). The system combines leakage-free XGBoost multi-label classification with GPT-4o-mini semantic log analysis, grounded in a formal effectiveness model. Key findings: (1) XGBoost v2 achieves 85.45% macro-F1 on leakage-free synthetic data (Wilson 95% CI = [84.9%, 86.0%]); an initial 86.3% data-leakage rate artificially inflated prior results to 99.99% and was identified and corrected in this revision; (2) GPT-4o-mini achieves 92.3% macro accuracy across four log types (n = 628, 37.5% real enterprise data, Wilson CI = [89.9%, 94.3%]); (3) adversarial validation across five MITRE ATT&CK scenarios yields 92.8% macro detection with 0.0% false-positive rate on real SSH/PAM compliant logs (n = 75); (4) a cross-dataset generalization analysis confirms 87.6% F1 on real SSH logs but identifies a 37.8-percentage-point out-of-vocabulary gap for Windows and HTTP log types, motivating the hybrid architecture; (5) the combined hybrid system (XGBoost for in-vocabulary logs, GPT-4o-mini for out-of-vocabulary) achieves 85.1% F1 with 6.4% false-positive rate on 180 real-world logs. The system runs at 2.0 CPU cores, 2.66 GB RAM, on $50/month cloud hosting (Apple M1 Pro baseline; storage and maintenance excluded), producing audit reports in 2–5 s depending on log volume and policy document size, demonstrating that effectiveness-based compliance auditing is accessible without enterprise-grade infrastructure. Full article
Show Figures

Figure 1

27 pages, 704 KB  
Article
Computing Incentive and Data Offloading in Digital Twin Networks: A Contract Theory and Multi-Agent Deep Reinforcement Learning Approach
by Nan Zhao, Henan Xu, Yuxiang Su, Bokun He, Fan Zhang, Jing Tang and Sheng Hu
Future Internet 2026, 18(6), 328; https://doi.org/10.3390/fi18060328 - 16 Jun 2026
Viewed by 472
Abstract
In the digital twin (DT) network, effective edge data processing is essential to meet the real-time requirements of DT models. However, edge servers (ESs) are self-interested and have limited computation resources. The virtual content operator (VCO) cannot observe their true computing capabilities, leading [...] Read more.
In the digital twin (DT) network, effective edge data processing is essential to meet the real-time requirements of DT models. However, edge servers (ESs) are self-interested and have limited computation resources. The virtual content operator (VCO) cannot observe their true computing capabilities, leading to participation reluctance and information asymmetry. To address these challenges, this paper proposes a contract-learning integration method for computing incentive and data offloading. A two-dimensional computation-reward contract incentive mechanism is designed to motivate ESs to provide computation resources for data pre-processing, where both continuous and discrete distributions of ES types are considered. Then, ESs upload the processed results to the VCO for DT model mapping, synchronization, and final construction. Based on the individual rationality and incentive compatibility constraints, the optimal incentive reward and computing resource allocation strategies are analytically derived to maximize the VCO’s utility. Then, based on the signed contracts, a multi-agent double deep Q-network algorithm is developed to jointly optimize the binary data offloading decision, transmission bandwidth, and transmission power for the minimal system delay. The algorithm learns adaptive strategies in the dynamic network environment and mitigates Q-value overestimation. Numerical results demonstrate that the proposed method improves system performance in terms of computing incentive and data offloading. Full article
Show Figures

Figure 1

24 pages, 5165 KB  
Article
Application of a Hybrid Approach in the Synthesis of a Knowledge Extraction Module of an Intelligent Assistant for a Microcontroller Technical Specialist
by Vadim Voloshchuk, Eduard Melnik, Oleg Kartashov, Alexey Samoylov and Yaroslav Melnik
Future Internet 2026, 18(6), 327; https://doi.org/10.3390/fi18060327 - 16 Jun 2026
Viewed by 332
Abstract
A Retrieval-Augmented Generation (RAG) approach is widely used as a key element for intelligent assistants. However, the knowledge extraction stage from technical text corpora is fraught with difficulties due to the presence of highly specialized terminology, tables, and abbreviations. The goal of this [...] Read more.
A Retrieval-Augmented Generation (RAG) approach is widely used as a key element for intelligent assistants. However, the knowledge extraction stage from technical text corpora is fraught with difficulties due to the presence of highly specialized terminology, tables, and abbreviations. The goal of this study is to develop methodological support for knowledge extraction for an intelligent assistant for a technical specialist in the field of microcontroller-based device design. This study systematically compares and analyzes the computational performance of knowledge extraction methods and their various combinations. The results showed that the hybrid version of the baseline methods (hybrid_v2_dense) provides the best R@1 (45.2%), MRR@5 (49.8%) and nDCG@5 (52.0%) values, while the R@5 level remains comparable to BM25. Among the extended configurations of the hybrid_v2 family, the best R@5 value (57.7%) is achieved by the hybrid_v2_dense_splade method, while the best values of R@1 (48.9%), MRR@5 (52.1%), and nDCG@5 (53.7%) are achieved by the hybrid_v2_dense_unicoil method. Based on the obtained results, an expert decision tree was formed for selecting the knowledge extraction module configuration considering hardware limitations. These results provide experimental evidence of the effectiveness of the developed methodological support for knowledge extraction for an intelligent assistant of a technical specialist. Full article
Show Figures

Graphical abstract

61 pages, 4350 KB  
Review
LLM-Based Multi-Agent Orchestration: A Survey of Frameworks, Communication Protocols, and Emerging Patterns
by Yiwen Zhu, Lihe Liu, Jiaqian Yu and Di Zhang
Future Internet 2026, 18(6), 326; https://doi.org/10.3390/fi18060326 - 15 Jun 2026
Viewed by 11815
Abstract
The proliferation of large language model (LLM) agents has enabled increasingly complex multi-step automation; however, composing multiple agents into coherent systems introduces significant orchestration challenges that remain poorly documented. This survey examines LLM-based multi-agent orchestration from 2023 through early 2026 (literature cutoff: March [...] Read more.
The proliferation of large language model (LLM) agents has enabled increasingly complex multi-step automation; however, composing multiple agents into coherent systems introduces significant orchestration challenges that remain poorly documented. This survey examines LLM-based multi-agent orchestration from 2023 through early 2026 (literature cutoff: March 2026), with explicit attention to the evidence hierarchy used to interpret deployment claims. We propose a three-topology, one-adaptivity taxonomy—centralized, decentralized, and hierarchical coordination topologies, each optionally augmented with a dynamic–adaptive control axis—grounded in classical multi-agent systems theory and recent empirical evidence. We compare six leading frameworks (LangGraph, CrewAI, AutoGen/Microsoft Agent Framework, OpenAI Agents SDK, MetaGPT, and DSPy) along axes directly relevant to practitioners: state-management granularity, token-cost structure, failure-recovery options, and design philosophy. The emerging protocol stack is examined in terms of why MCP (agent-to-tool) and A2A (agent-to-agent) occupy complementary layers, how the ACP–A2A merger signals protocol convergence, and where ANP’s decentralized-discovery design fits. Production design considerations—state management, task planning, error handling, scalability, and security—are evaluated with reference to published benchmarks. Vendor-reported figures are marked † throughout and held to a documented evidence hierarchy, which separates them from peer-reviewed and government-evaluator measurements. We close by identifying eight open challenges and proposing a six-dimension evaluation framework for multi-agent coordination quality. This paper offers practitioners a decision framework covering taxonomy, framework selection, protocol adoption, and early operational pilots. Full article
Show Figures

Graphical abstract

30 pages, 6102 KB  
Article
Development and Experimental Validation of an Educational Robotic Platform with Machine Vision and Web-Based Monitoring for Automation Teaching
by Elizabeth Salazar-Jácome, Jean Ruiz-Espinoza, Wilson Sánchez-Ocaña, Javier De la Torre-Guzmán, Félix Chávez-Jácome and Mario Pérez-Cargua
Future Internet 2026, 18(6), 325; https://doi.org/10.3390/fi18060325 - 15 Jun 2026
Viewed by 1378
Abstract
The development of accessible and experimentally validated robotic systems for engineering education is a challenge, especially in academic environments where industrial manipulators are economically inaccessible. This paper presents the design, mechanical validation, and experimental evaluation of a robotic arm-based didactic module developed for [...] Read more.
The development of accessible and experimentally validated robotic systems for engineering education is a challenge, especially in academic environments where industrial manipulators are economically inaccessible. This paper presents the design, mechanical validation, and experimental evaluation of a robotic arm-based didactic module developed for the classification of objects according to color and morphology. The proposed system integrates a five-degree-of-freedom articulated configuration, a servomotor drive, motion planning with a trapezoidal speed profile, and a web-based control interface, enabling local and remote operation within an educational environment aligned with Industry 4.0 principles. The mechanical structure was designed using CAD modeling and validated through static structural analysis to ensure mechanical integrity and adequate safety factors. The selection of actuators was made considering the torque, angular velocity, and load requirements. A trapezoidal speed profile was implemented in order to ensure smooth trajectories and minimize positioning errors. Experimental validation was carried out through repetitive tests under controlled laboratory conditions, evaluating the accuracy and repeatability metrics. Statistical indicators such as mean error, standard deviation, and root mean square error (RMSE) were calculated. The results show the stable performance of the system, with low variability in multiple test cycles, confirming the viability of the proposed architecture for its implementation in automation and educational robotics laboratories. The integration of structural validation, motion control strategy, and experimental quantitative evaluation contributes to bridging the gap between theoretical teaching of robotics and its practical application, offering a scalable, low-cost platform for engineering training. Full article
(This article belongs to the Special Issue Mobile Robotics and Autonomous System)
Show Figures

Graphical abstract

16 pages, 5619 KB  
Article
An Edge Artificial Intelligence Framework for IoMT-Enabled Remote Health Monitoring and Clinical Information Retrieval
by Pir Noman Ahmad, Muhammad Shahid Anwar, Igor Heberto Barahona, Atta Ur Rahman, Haseeb Nisar and Umama Burhan
Future Internet 2026, 18(6), 324; https://doi.org/10.3390/fi18060324 - 15 Jun 2026
Viewed by 628
Abstract
Intelligent sensors and Internet of Medical Things (IoMT) platforms are rapidly changing smart healthcare by enabling continuous capture of physiological, behavioral, and clinical events outside conventional hospital settings. Yet the value of connected sensing depends on more than signal acquisition alone. A practical [...] Read more.
Intelligent sensors and Internet of Medical Things (IoMT) platforms are rapidly changing smart healthcare by enabling continuous capture of physiological, behavioral, and clinical events outside conventional hospital settings. Yet the value of connected sensing depends on more than signal acquisition alone. A practical remote-monitoring ecosystem must also convert sensor alerts, clinician-facing summaries, and historical electronic clinical records (ECRs) into ranked evidence that supports care decisions. This study reframes a large-AI clinical retrieval model as the intelligence layer of an edge–cloud IoMT architecture. The proposed framework combines Transformer-Based Sequence (TBS) encoding, BioBERT-driven representation learning, explicit retrieval, and domain-guided re-ranking to connect sensor-originated narratives, patient records, and clinician queries. The empirical evaluation is conducted on Medical Information Mart for Intensive Care III (MIMIC-III) and i2b2, two de-identified clinical text benchmarks that approximate the documentation layer of real-world remote patient monitoring. Compared with strong baselines, including DeepBio, UniT2T, Web4IR, A2A-API, CoLTiD, VLRG, ColBERT, DeepSDH, BiRex, and DL4BTM, the proposed model achieves the best overall performance, reaching F1/Pre/NDCG scores of 0.8399/0.8338/0.5235 on MIMIC-III and 0.8090/0.8100/0.5129 on i2b2. Ablation experiments confirm the importance of exploratory data adaptation, critical feature modeling, critical token learning, cross-disciplinary supervision, and data-driven regularization. Parameter sensitivity analysis shows stable behavior for beta values greater than or equal to 1, with the strongest results at beta = 5. The study concludes that large-AI retrieval can strengthen the clinical interpretation layer required for IoMT-enabled remote monitoring, while future work should validate the approach on live multimodal sensor streams and privacy-preserving deployments. Full article
Show Figures

Figure 1

26 pages, 5317 KB  
Article
Enhancing SYN Cookie Security Against DDoS Attacks: Mitigating Replay Attacks with Nonce Implementation
by Nazar Abbas Saqib, Haifa Alobiad, Layan Alsuliman and Tala Almulla
Future Internet 2026, 18(6), 323; https://doi.org/10.3390/fi18060323 - 15 Jun 2026
Viewed by 737
Abstract
SYN flooding attacks remain a persistent threat to network availability, particularly in Distributed Denial-of-Service (DDoS) scenarios that exploit the TCP three-way handshake. Traditional SYN cookies mitigate half-open connection exhaustion but may exhibit limited replay resistance under certain adversarial conditions. This paper presents a [...] Read more.
SYN flooding attacks remain a persistent threat to network availability, particularly in Distributed Denial-of-Service (DDoS) scenarios that exploit the TCP three-way handshake. Traditional SYN cookies mitigate half-open connection exhaustion but may exhibit limited replay resistance under certain adversarial conditions. This paper presents a nonce-enhanced, HMAC-SHA256-based SYN cookie mechanism designed to strengthen handshake validation while preserving stateless operation. The implemented framework binds each connection attempt to a time-bounded, per-session nonce and embeds a truncated HMAC within the TCP sequence number field. The mechanism is implemented and experimentally evaluated using a custom-built simulation framework, NOxSYN. Under concurrent SYN flood conditions, the enhanced design successfully validated legitimate handshakes while maintaining stable operation under adversarial load. Measured server-side cryptographic processing remained below 1 ms per connection, with stable CPU utilization during testing. These results demonstrate that nonce-based replay protection can be integrated into a SYN cookie framework while preserving scalability and stateless operation. The current evaluation focuses on implementation-level validation and performance characterization, providing a foundation for future security-oriented assessment across a broader range of replay-based attack scenarios. Full article
(This article belongs to the Special Issue Security of Computer System and Network)
Show Figures

Figure 1

28 pages, 4866 KB  
Article
A Hybrid DAO-Based Framework for Faculty Governance in Higher Education: Regulatory Alignment, Prototype Implementation, and Simulation-Based Evaluation
by Tawfiq Hasanin, Rayan Mosli and Sahar Jambi
Future Internet 2026, 18(6), 322; https://doi.org/10.3390/fi18060322 - 14 Jun 2026
Viewed by 648
Abstract
Faculty governance in higher education depends on transparent participation, reliable quorum enforcement, accountable record keeping, and strict alignment with institutional regulations. Conventional departmental council processes provide formal authority and academic deliberation, but they often rely on manual documentation, fragmented records, and procedural enforcement [...] Read more.
Faculty governance in higher education depends on transparent participation, reliable quorum enforcement, accountable record keeping, and strict alignment with institutional regulations. Conventional departmental council processes provide formal authority and academic deliberation, but they often rely on manual documentation, fragmented records, and procedural enforcement that is difficult to verify after the fact. This work presents an integrated hybrid Decentralized Autonomous Organization (DAO) framework for faculty governance that combines regulatory alignment analysis, a working smart-contract prototype, and scenario-based simulation. The framework is designed for university departmental councils and is structured across three layers: off-chain community governance, on-chain protocol governance, and off-chain execution governance. It expands prior conceptual work by incorporating governance dimensions related to roles, incentives, membership, communication, decision-making, identity, auditability, conflict-of-interest handling, and institutional ratification. The evaluation simulates 1488 proposals across twelve scenarios covering four faculty sizes (15, 30, 50, and 100 members) and three adoption levels (low, moderate, and high). Scenario results indicate that adoption intensity is the dominant driver of governance performance: mean participation increases from about 33% under low usage to about 85% under high usage, quorum achievement rises from about 6% to about 96%, and execution rises from about 19% to about 70%. Relative to a modeled conventional workflow baseline, the DAO-supported process reduces decision-cycle time by about 76%, improves audit completeness by about 30%, and increases traceability from about 0.63 to 1.00. The results indicate that DAO-assisted faculty governance can strengthen transparency, procedural consistency, and auditability while preserving legally mandated university authority, but its practical value depends on sustained participation, privacy safeguards, cost control, and clearly defined hybrid control points. Full article
Show Figures

Graphical abstract

37 pages, 1493 KB  
Article
Executable Trust: A Formal Model and Architecture for Verifiable Digital Interactions
by Geun-Hyung Kim and Young Kuen Jang
Future Internet 2026, 18(6), 321; https://doi.org/10.3390/fi18060321 - 12 Jun 2026
Viewed by 298
Abstract
Digital trust in online interactions is commonly established through mechanisms such as decentralized identifiers (DIDs), verifiable credentials (VCs), and digital wallets. While these technologies support the correctness of individual components, they do not by themselves establish that an interaction as a whole is [...] Read more.
Digital trust in online interactions is commonly established through mechanisms such as decentralized identifiers (DIDs), verifiable credentials (VCs), and digital wallets. While these technologies support the correctness of individual components, they do not by themselves establish that an interaction as a whole is trustworthy. This limitation arises because real-world interactions consist of sequences of dependent steps, where inconsistencies may arise even when each step is locally valid. In this paper, we introduce the concept of executable trust, which models trust as a verifiable property of execution across complete interaction sequences. We formalize interactions as chains of TrustEvidence objects that capture step-level validity, constraint satisfaction, and cross-step dependencies. Based on this model, we show that step-level correctness alone is insufficient to characterize interaction-level trust under the stated execution assumptions. We further clarify the definition-induced modular structure of interaction-level trust and use a local failure-witness characterization to connect the formal model with scenario-based validation. We also present the Executable Trust Architecture (ETA), a five-layer architecture that operationalizes the proposed model through components for evidence generation, constraint enforcement, secure communication, and auditability. The feasibility of the approach is examined through scenario-based evaluation covering key trust properties—authenticity, integrity, privacy, and accountability—across nine scenarios comprising 68 test cases. The evaluation illustrates cases in which cross-step violations that pass conventional step-level verification are reflected as failures of ETA’s sequence-aware trust conditions under the evaluated assumptions. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Figure 1

26 pages, 8630 KB  
Article
Experimental Evaluation and Performance Analysis of 5G NSA Networks
by Vasileios D. Batsios, Spiridoula V. Margariti, Constantinos T. Angelis and Eleftherios Stergiou
Future Internet 2026, 18(6), 320; https://doi.org/10.3390/fi18060320 - 12 Jun 2026
Viewed by 744
Abstract
5G technology was introduced in 2019 with the aim of transforming digital connectivity, enabling a new generation of communication capabilities, such as significantly faster mobile broadband, highly reliable low-latency links, and the capacity to support vast IoT deployments. However, the expected improvements promised [...] Read more.
5G technology was introduced in 2019 with the aim of transforming digital connectivity, enabling a new generation of communication capabilities, such as significantly faster mobile broadband, highly reliable low-latency links, and the capacity to support vast IoT deployments. However, the expected improvements promised by 5G technology do not seem to be reflected in actual usage. This study aims to address the issue of the real-world usage of 5G telecommunications networks and compare it with the theoretical specifications of the network as officially published by 3GPP. Specifically, the focus will be on the evaluation of the implementation of the 5G network in northwestern Greece, which operates in Non-Standalone (NSA) mode as of the date of this study’s completion. 5G Standalone (SA) networks were not available for public testing in this region during the data collection period. The analysis focuses on key performance indicators, including throughput, latency, stability, and coverage, to assess how effectively current deployments meet the expectations set by 5G standards. Results show that while 5G delivers notable improvements in peak data rates and latency, several practical limitations persist. NSA deployments remain constrained by their dependence on 4G infrastructure, resource sharing between LTE and 5G components affects performance under high-load conditions, and inconsistent coverage leads to significant variability in user experience. These findings highlight the gap between theoretical capabilities and operational performance, offering insights that can guide future network optimization and inform the transition toward 5G Standalone (SA) architectures. Full article
(This article belongs to the Special Issue 5G/6G and Beyond: The Future of Wireless Communications Systems)
Show Figures

Graphical abstract

37 pages, 12330 KB  
Review
Secure V2X Communication in the Quantum Era: A Survey of Post-Quantum Authentication and Key Agreement (AKA) Protocols for Autonomous Vehicles
by Weiqi Wang and Soo Fun Tan
Future Internet 2026, 18(6), 319; https://doi.org/10.3390/fi18060319 - 11 Jun 2026
Viewed by 899
Abstract
Vehicle-to-Everything (V2X) communication is a critical enabler of autonomous driving, supporting real-time information exchange among vehicles, roadside infrastructure, pedestrians, and cloud services. However, the security of current V2X systems largely relies on classical cryptographic mechanisms, which are expected to become vulnerable in the [...] Read more.
Vehicle-to-Everything (V2X) communication is a critical enabler of autonomous driving, supporting real-time information exchange among vehicles, roadside infrastructure, pedestrians, and cloud services. However, the security of current V2X systems largely relies on classical cryptographic mechanisms, which are expected to become vulnerable in the presence of large-scale quantum computers. Given the long operational lifespan and stringent safety requirements of autonomous vehicular networks, the transition toward quantum-resistant authentication and key management mechanisms has become increasingly important. This paper presents a comprehensive survey of post-quantum Authentication and Key Agreement (AKA) protocols for secure V2X communications. The survey systematically reviews V2X communication architectures, security and privacy requirements, existing authentication frameworks, and emerging post-quantum cryptographic approaches. Representative AKA schemes and NIST-standardized post-quantum algorithms are comparatively analyzed in terms of security strength, computational complexity, communication overhead, storage requirements, scalability, and deployment suitability for resource-constrained vehicular environments. The survey further examines practical implementation challenges, including latency constraints, bandwidth limitations, signature size expansion, memory consumption, and hardware resource requirements. The analysis reveals that achieving quantum-resistant security in V2X networks requires balancing strong cryptographic protection with the stringent performance demands of safety-critical vehicular applications. While recent post-quantum approaches offer promising security guarantees against quantum adversaries, their practical deployment remains constrained by computational and communication overhead. Finally, this survey identifies key research gaps and outlines future directions for the development of lightweight, scalable, and quantum-resilient AKA frameworks capable of supporting next-generation autonomous transportation systems. The findings provide researchers and practitioners with a structured understanding of the opportunities, limitations, and challenges associated with securing future V2X communications in the quantum era. Full article
(This article belongs to the Special Issue Future Industrial Networks: Technologies, Algorithms, and Protocols)
Show Figures

Figure 1

25 pages, 3996 KB  
Article
Enhancing Respiratory Disease Diagnosis with AI Lung Sound Analysis: A Web-Based Approach
by Reshma Sreejith, R. Kanesaraj Ramasamy, Wan-Noorshahida Mohd-Isa and Junaidi Abdullah
Future Internet 2026, 18(6), 318; https://doi.org/10.3390/fi18060318 - 11 Jun 2026
Viewed by 745
Abstract
Accurate and timely diagnosis of respiratory diseases remains a critical challenge in clinical practice, particularly in resource-limited and remote healthcare settings. This study proposes a web-based automated respiratory disease classification system leveraging a hybrid Convolutional Neural Network–Long Short-Term Memory with Time-Distributed (CNN-LSTM-TD) architecture [...] Read more.
Accurate and timely diagnosis of respiratory diseases remains a critical challenge in clinical practice, particularly in resource-limited and remote healthcare settings. This study proposes a web-based automated respiratory disease classification system leveraging a hybrid Convolutional Neural Network–Long Short-Term Memory with Time-Distributed (CNN-LSTM-TD) architecture for lung sound analysis. The proposed model integrates three complementary time-frequency representations—Mel-Frequency Cepstral Coefficients (MFCCs), Mel-spectrograms, and Chroma Short-Time Fourier Transform (Chroma-STFT)—to comprehensively capture both local spectral characteristics and long-range temporal dependencies inherent in respiratory cycles. Specifically, the TimeDistributed CNN block extracts localised acoustic features from sequential frames, while the LSTM layer models their temporal evolution, enabling robust identification of pathological acoustic signatures such as wheezes and crackles. The model was rigorously evaluated on the benchmark ICBHI 2017 dataset across six diagnostic categories: healthy, asthma, chronic obstructive pulmonary disease (COPD), pneumonia, upper respiratory tract infection (URTI), and bronchiectasis. The CNN-LSTM-TD model achieved an F1-score of 0.94, recall of 0.91, precision of 0.97, overall accuracy of 96.40%, and an AUC-ROC of 0.96, significantly outperforming standalone CNN, LSTM, and CNN-LSTM baseline models. The accompanying web interface supports audio file upload, real-time visualisation of waveforms and spectrograms, and confidence score reporting, collectively facilitating clinical decision support and telemedicine integration. These results demonstrate that the synergy of temporally aware deep feature extraction and accessible web deployment positions the proposed system as a clinically viable, scalable tool for automated respiratory disease diagnosis and remote patient monitoring. Full article
(This article belongs to the Special Issue Artificial Intelligence-Enabled Smart Healthcare)
Show Figures

Figure 1

28 pages, 8499 KB  
Article
A Load-Aware Task Offloading Method for Mobile Edge Computing Under Eligibility Constraints
by Yarong Liu, Zijian Che and Xiaolan Xie
Future Internet 2026, 18(6), 317; https://doi.org/10.3390/fi18060317 - 10 Jun 2026
Viewed by 595
Abstract
Mobile edge computing (MEC) enables computation-intensive and latency-sensitive tasks to be offloaded from mobile devices to nearby edge servers. Most existing MEC task offloading studies formulate offloading as a selection problem over a fixed or fully available set of candidate servers, which is [...] Read more.
Mobile edge computing (MEC) enables computation-intensive and latency-sensitive tasks to be offloaded from mobile devices to nearby edge servers. Most existing MEC task offloading studies formulate offloading as a selection problem over a fixed or fully available set of candidate servers, which is restrictive in heterogeneous MEC scenarios with task-node eligibility constraints. Under such constraints, a task can be processed by an edge server only when task attributes, service requirements, link conditions, and node states jointly satisfy the corresponding eligibility conditions. The feasible action set therefore varies over time, while offloading decisions are further coupled with edge-node-side queue competition and long-term load evolution. To address this problem, this paper proposes Resource-oriented Scheduling Coordination (RoSCo), a load-aware task offloading method with scheduling-level constraint handling for eligibility-constrained MEC systems. In this paper, scheduling coordination refers to the joint use of feasible-action control, priority-aware edge-node service-order modeling, and load-responsive feedback within the task offloading decision process; it does not denote inter-server communication, task aggregation, federated model aggregation, or a distributed coordination protocol. RoSCo constructs a dynamic feasible action set, applies eligibility-aware action masking to exclude infeasible offloading actions, incorporates priority-aware edge-node service-order information to characterize queueing competition among heterogeneous tasks, and designs a load-responsive reward to guide congestion mitigation and load balancing. A dueling double deep Q-network (D3QN) is adopted as the value-learning backbone, while the main methodological contribution lies in embedding task-specific feasible-action control, priority-aware node-side queue information, and load-responsive feedback into the constrained offloading process. Simulation results show that RoSCo reduces the task drop rate and edge-node load imbalance while maintaining competitive task completion delay and energy consumption, especially under high-load and sparse-eligibility conditions. Full article
Show Figures

Figure 1

17 pages, 354 KB  
Article
Evaluating Post-Quantum Cryptography in IoT Networks: Communication, Fragmentation, and Reliability
by Eric Sakk, Guobin Xu, Jianzhou Mao and Shuangbao Wang
Future Internet 2026, 18(6), 316; https://doi.org/10.3390/fi18060316 - 10 Jun 2026
Viewed by 796
Abstract
Post-quantum cryptographic (PQC) algorithms are being developed to guard against quantum-computing attacks, but their behavior in constrained Internet of Things (IoT) environments remains an important topic of discussion. In this work, we study the impact of deploying PQC protocols in IoT networks using [...] Read more.
Post-quantum cryptographic (PQC) algorithms are being developed to guard against quantum-computing attacks, but their behavior in constrained Internet of Things (IoT) environments remains an important topic of discussion. In this work, we study the impact of deploying PQC protocols in IoT networks using the Open Quantum Safe (liboqs) framework. In particular, key encapsulation and digital signature schemes are evaluated in terms of their computational performance, communication costs, and energy consumption. Our results indicate that although PQC operations can be completed in microseconds using general-purpose processors, substantially larger key and ciphertext sizes introduce significant communication overhead. When mapped to common IoT protocols such as Bluetooth Low Energy (BLE), IEEE 802.15.4 (Zigbee), and LoRa, these larger payloads must be divided into multiple packets. In low-payload LoRa networks, for example, ML-KEM handshakes can require up to 62 packets. This level of fragmentation increases latency and energy consumption, thus potentially affecting reliability. Furthermore, when packet delivery probabilities approaching 99% are achieved, handshake success rates can drop to values approaching 50%. These results suggest that communication metrics, rather than computational performance, pose key challenges to PQC deployment in constrained IoT settings. Full article
Show Figures

Graphical abstract

27 pages, 2066 KB  
Article
Joint Optimization of Task Offloading and Image–Container Caching Based on Hierarchical Multi-Agent Reinforcement Learning in Containerized MEC Networks
by Zihan Xu and Chengqun Wang
Future Internet 2026, 18(6), 315; https://doi.org/10.3390/fi18060315 - 10 Jun 2026
Viewed by 392
Abstract
Future Internet applications such as intelligent transportation, immersive services, and edge-assisted artificial intelligence require latency-sensitive service provisioning at the network edge. In containerized mobile edge computing (MEC), service orchestration is not only a task-offloading problem, but also a task–container–image constrained decision problem: an [...] Read more.
Future Internet applications such as intelligent transportation, immersive services, and edge-assisted artificial intelligence require latency-sensitive service provisioning at the network edge. In containerized mobile edge computing (MEC), service orchestration is not only a task-offloading problem, but also a task–container–image constrained decision problem: an offloaded task can be executed only when the required runtime container is active, and a newly activated container must be supported by a locally cached service image. This dependency couples task placement, runtime container caching, and persistent image caching under limited RAM and ROM resources. To address this challenge, this paper proposes HAM-MADDPG, a dependency-aware hierarchical action-masked multi-agent reinforcement learning algorithm for joint task offloading and image–container caching in containerized MEC networks. HAM-MADDPG decomposes the monolithic orchestration decision into three causally ordered policy layers: task offloading, runtime container caching, and persistent image caching. Each layer learns a structured subproblem conditioned on upstream realized decisions, while dynamic action masking and feasibility-aware action realization guide the learned policies toward executable decisions satisfying task–container and container–image constraints. Extensive simulations under dynamic service demands and heterogeneous edge resources show that HAM-MADDPG achieves more stable convergence than non-hierarchical reinforcement learning baselines and reduces long-term system latency by approximately 14–25% compared with representative heuristic and flat DRL baselines. Full article
(This article belongs to the Section Network Virtualization and Edge/Fog Computing)
Show Figures

Figure 1

33 pages, 16037 KB  
Article
A Mixed-Reality Approach to Cardiovascular Anatomy Education
by Shantanu Patil, Virinchi Lalwani, Bahar Uddin Mahmud, Steven M. Carr, Jade Woodcock, Kelsey Grellinger and Guan Yue Hong
Future Internet 2026, 18(6), 314; https://doi.org/10.3390/fi18060314 - 9 Jun 2026
Cited by 1 | Viewed by 737
Abstract
Mixed-reality (MR) technologies have enhanced anatomy education through immersive three-dimensional visualization; however, most existing systems lack tutoring capabilities that respond contextually during anatomical exploration. This paper presents a reproducible MR anatomy learning platform implemented on the Apple Vision Pro that integrates the open-source [...] Read more.
Mixed-reality (MR) technologies have enhanced anatomy education through immersive three-dimensional visualization; however, most existing systems lack tutoring capabilities that respond contextually during anatomical exploration. This paper presents a reproducible MR anatomy learning platform implemented on the Apple Vision Pro that integrates the open-source Z-Anatomy atlas, with cardiovascular anatomy as the case domain. The system supports interactive exploration through hand gestures and eye tracking, alongside natural-language voice interaction. To provide context-grounded tutoring, we incorporate a retrieval-augmented generation (RAG) voice assistant whose responses are bounded by the Terminologia Anatomica knowledge base and weighted by the learner’s current spatial focus, with spatially anchored labels supporting contextual understanding. The platform was profiled on Apple Vision Pro hardware using Xcode Instruments and exercised through scenario-based walkthroughs of representative anatomical exploration tasks; the system met its real-time interaction and rendering thresholds across eight integrated anatomical systems. By leveraging open-source content and a substitutable AI backend, the architecture reduces software-licensing and development costs by an estimated one to two orders of magnitude relative to comparable proprietary systems and ports across XR platforms via a single bridge layer. Full article
Show Figures

Graphical abstract

23 pages, 3782 KB  
Article
Measuring Baseline Web Security Posture: Tier-1 HTTP Security Header Adoption in the Maldives and the WSHS-B Governance Metric
by Leela Waheed and Ammar Alazab
Future Internet 2026, 18(6), 313; https://doi.org/10.3390/fi18060313 - 9 Jun 2026
Viewed by 638
Abstract
Baseline web security configuration is a critical but often overlooked component of national cybersecurity posture, particularly in small and developing digital economies. This study presents a systematic empirical assessment of Tier-1 HTTP security header adoption across 51 Maldivian government and public limited company [...] Read more.
Baseline web security configuration is a critical but often overlooked component of national cybersecurity posture, particularly in small and developing digital economies. This study presents a systematic empirical assessment of Tier-1 HTTP security header adoption across 51 Maldivian government and public limited company (PLC) websites, benchmarked against 20 internationally recognised secure domains. To enable reproducible, policy-relevant evaluation, this paper introduces the Website Security Header Score–Benchmark (WSHS-B), a normalised metric quantifying deployment of three foundational browser-enforced controls: Strict-Transport-Security, X-Frame-Options, and X-Content-Type-Options. Only 11.8% of evaluated Maldivian websites implement all three Tier-1 headers; 39.2% implement none and 49.0% partially comply. Benchmark domains achieve near-complete adoption (mean WSHS-B = 0.92) versus 0.35 for Maldivian websites, a gap of 57 percentage points. Mann–Whitney U tests confirm statistically significant differences between groups (p < 0.001), with large rank-based effect sizes (Cliff’s δ ≈ 0.80). Unlike practitioner-facing tools such as Mozilla Observatory and SecurityHeaders.com, which produce composite site-level grades, WSHS-B is purpose-built for population-level governance monitoring through binary, policy-enforceable indicators. To the authors’ knowledge, this is the first nationally scoped empirical baseline of Tier-1 header adoption in the Maldives and the first governance-aligned metric of its kind for small digital economies. The findings provide an evidence base for NCSS 2024–2029 implementation, including mandatory baseline standards, automated compliance monitoring, and targeted capacity development. The methodology is replicable across comparable Small Island Developing States using passive, open-source scanning. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Figure 1

44 pages, 4238 KB  
Article
A Batch-Based VNF Deployment Mechanism for Privacy-Preserving Multi-Domain SFC Deployment Using Deep Reinforcement Learning
by Arif Indra Irawan and Yukinobu Fukushima
Future Internet 2026, 18(6), 312; https://doi.org/10.3390/fi18060312 - 8 Jun 2026
Viewed by 355
Abstract
Future 6G networks require higher performance and wider service coverage. Multi-domain Service Function Chain (SFC) deployment enables service provisioning across multiple network domains to meet these demands. However, when collaboration occurs among different network operators, privacy-preserving mechanisms are required to protect sensitive information [...] Read more.
Future 6G networks require higher performance and wider service coverage. Multi-domain Service Function Chain (SFC) deployment enables service provisioning across multiple network domains to meet these demands. However, when collaboration occurs among different network operators, privacy-preserving mechanisms are required to protect sensitive information such as internal topology and resource availability. Existing SIRM-based mechanisms, such as the Privacy-Preserving Deployment Mechanism (PPDM), address this challenge but suffer from structural limitations: PPDM performs whole-chain feasibility evaluation with extensive virtual occupation. This paper proposes a B-Batch Sequential Deployment mechanism for privacy-preserving multi-domain SFC deployment. Instead of evaluating whole-chain feasibility at once, the proposed B-Batch mechanism partitions each incoming SFC into fixed-size VNF batches and constructs a batch-level SIRM. This design confines virtual occupation to the current batch and reduces both its magnitude and duration while remaining fully compatible with the SIRM privacy model and the hierarchical multi-domain control architecture. A Deep Q-Network (DQN) is employed to learn substrate node selection policies based solely on SIRM-based state information, without exposing domain-internal topology or resource details. Simulation results on a three-domain AARNET substrate topology demonstrate that the proposed mechanism consistently improves deployment robustness under varying traffic intensities and SFC lengths, including short (3–6 VNFs), medium (6–9 VNFs), and long (9–12 VNFs) service chains. Compared with PPDM, the proposed B-Batch mechanism achieves higher acceptance ratios under moderate-to-heavy traffic while reducing end-to-end delay and improving average substrate resource utilization. Node selection analysis further shows that smaller batch sizes preserve feasibility through compact node reuse, whereas larger batch sizes encourage broader substrate exploration. Overall, the proposed B-Batch mechanism enhances feasibility preservation and deployment robustness in privacy-preserving multi-domain SFC orchestration. Full article
(This article belongs to the Special Issue Software-Defined Networking and Network Function Virtualization)
Show Figures

Figure 1

31 pages, 8044 KB  
Article
Topology-Aware Joint Control Plane Placement and Assignment for Resilient Hierarchical Cloud–Edge Networks
by Samer Mohammed Rasool, Yassine Boujelben and Faouzi Zarai
Future Internet 2026, 18(6), 311; https://doi.org/10.3390/fi18060311 - 8 Jun 2026
Viewed by 496
Abstract
Hierarchical cloud–edge networks rely on distributed control planes to manage large-scale heterogeneous infrastructures, where controller placement and node assignment strongly affect latency, load balancing, and resilience. Existing methods typically decouple these decisions and provide limited guarantees under controller failures or topology constraints. We [...] Read more.
Hierarchical cloud–edge networks rely on distributed control planes to manage large-scale heterogeneous infrastructures, where controller placement and node assignment strongly affect latency, load balancing, and resilience. Existing methods typically decouple these decisions and provide limited guarantees under controller failures or topology constraints. We introduce a topology-aware joint optimization framework for controller placement and node assignment in hierarchical cloud–edge networks. The problem is formulated as a multi-objective integer linear program capturing latency, load balancing, and control continuity. To ensure scalability, we design a two-phase heuristic: structurally important controller candidates are selected using graph-based metrics, including node degree and k-core decomposition, followed by a redundancy-aware proximity assignment strategy that preserves connectivity under single-controller failures. Experiments on synthetic hierarchical and random topologies with up to 500 nodes show that the proposed approach achieves optimality gaps below 10% with execution times under 10 ms. It improves load distribution and reduces control latency compared to baseline methods while maintaining resilience under controller failures. Results show that exploiting topological structure in joint placement and assignment enables efficient and resilient control plane design for hierarchical cloud–edge networks, supporting near-real-time reconfiguration. Full article
Show Figures

Graphical abstract

27 pages, 1800 KB  
Article
TLS-Aware Anomaly Detection for Encrypted IoT Traffic Using a β-Variational Autoencoder with ANOVA–Mutual Information Feature Selection
by Muhammad Nouman, Raja Ujjan and Muhsin Hassanu
Future Internet 2026, 18(6), 310; https://doi.org/10.3390/fi18060310 - 8 Jun 2026
Viewed by 658
Abstract
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection [...] Read more.
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection must instead rely on flow-level statistics and TLS metadata. This is challenging because IoT traffic is heterogeneous, non-stationary, and distributionally inconsistent across datasets, while many existing studies rely on single-dataset evaluation and therefore provide limited evidence of real-world generalisation. We introduce a TLS-aware anomaly detection framework that combines a β-Variational Autoencoder (β-VAE) with a hybrid ANOVA–Mutual Information (ANOVA–MI) feature-selection pipeline. The incremental contribution lies not in the individual use of these components, but in their integrated application to encrypted IoT anomaly detection under strict cross-dataset evaluation, where feature filtering, probabilistic latent regularisation, and threshold transferability are jointly examined without retraining or recalibration on target datasets. The framework models benign encrypted IoT traffic using probabilistic latent representations and identifies anomalies through reconstruction-error-based scoring. Network flows from the BoT-IoT, IoT-23, and ToN-IoT datasets were processed using Zeek and CICFlowMeter to construct a unified metadata feature space incorporating flow statistics and TLS attributes such as JA3 and JA3S fingerprints. The model was trained on benign BoT-IoT traffic and evaluated in both in-dataset and cross-dataset scenarios. The model achieves strong in-dataset performance on BoT-IoT (ROC-AUC 0.9996; F1 0.9922) and retains robust anomaly-ranking and threshold-based detection capability under cross-dataset domain shift (IoT-23: ROC-AUC 0.9882, F1 0.9422; ToN-IoT: ROC-AUC 0.9465, F1 0.8732). A comparative evaluation against deterministic autoencoders and classical baselines further indicates that the proposed β-VAE achieves stronger cross-dataset anomaly-ranking performance than the compared methods. These findings support the suitability of probabilistic latent modelling for privacy-preserving anomaly detection in encrypted IoT environments. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Graphical abstract

22 pages, 2554 KB  
Article
Multi-Agent Intelligent System for Dynamic Predictive Evaluation of National and Regional Labour Markets in Bulgaria
by Ivona Plamenova Velkova and Valentin Stefanov Kisimov
Future Internet 2026, 18(6), 309; https://doi.org/10.3390/fi18060309 - 7 Jun 2026
Viewed by 315
Abstract
Reliable public-sector labour-market forecasting requires models that can be updated as data sources, AI tools, and labour-market signals evolve. This paper proposes a provider-independent multi-agent framework for dynamic predictive evaluation of national and regional labour markets in Bulgaria. Implemented as a Model Context [...] Read more.
Reliable public-sector labour-market forecasting requires models that can be updated as data sources, AI tools, and labour-market signals evolve. This paper proposes a provider-independent multi-agent framework for dynamic predictive evaluation of national and regional labour markets in Bulgaria. Implemented as a Model Context Protocol (MCP) server, the system coordinates specialised agents for data ingestion, preprocessing, semantic extraction, AI-adjusted transformation modelling, automated model evaluation, and reporting through stable input–output contracts. The empirical application integrates Bulgarian Employment Agency administrative registered-unemployment indicators, Eurostat labour-market data, World Bank macroeconomic data, and textual, audio, and video evidence on AI, skills, and employment change. The analysis covers the period 2015–2030. Observed official data are used up to 2025 for model construction and validation, while the 2026–2030 values are reported only as forecast and scenario projections. For youth unemployment among persons aged 24 years or younger, the semantic-enhanced model achieves the best predictive accuracy (RMSE = 0.2033; MAE = 0.1457), representing a small improvement over the structured baseline (RMSE = 0.2057; MAE = 0.1462) and a substantial RMSE reduction relative to the persistence benchmark (RMSE = 0.4750; MAE = 0.2891). The AI-adjusted coefficient does not reduce holdout error relative to the semantic-enhanced model, but provides an explicit and sensitivity-tested mechanism for regional scenario interpretation. Regional forecasts indicate persistent spatial inequality, with the Northwest remaining the highest-risk region and the Southwest the lowest-risk region. Full article
(This article belongs to the Special Issue Intelligent Agents and Their Application)
Show Figures

Graphical abstract

27 pages, 18807 KB  
Article
Features over Architecture: Physics-Informed Anomaly Detection in Industrial Control Systems
by Khaled Chahine and Hassan N. Noura
Future Internet 2026, 18(6), 308; https://doi.org/10.3390/fi18060308 - 6 Jun 2026
Viewed by 677
Abstract
Industrial control systems (ICS) are increasingly targeted by cyberattacks that manipulate physical processes while evading data-driven detectors trained on raw time-series data. This paper extracts 34–41 control-theoretic features, including tracking error, valve mismatch, sensor liveness, and their temporal derivatives, from Proportional–Integral–Derivative (PID) control [...] Read more.
Industrial control systems (ICS) are increasingly targeted by cyberattacks that manipulate physical processes while evading data-driven detectors trained on raw time-series data. This paper extracts 34–41 control-theoretic features, including tracking error, valve mismatch, sensor liveness, and their temporal derivatives, from Proportional–Integral–Derivative (PID) control loops and evaluates them using an Isolation Forest combined with a maximum z-score. On HAI 21.03, Stage 1 achieves a PA-F1 score of 0.8945, detecting 48 out of 50 attacks. On HAI 23.05, Stage 1 attains a PA-F1 score of 0.9210, surpassing seven deep-learning baselines by at least 23 PA-F1 points; the closest baseline, a learned Graph Neural Network (GNN), achieves 0.6890. Re-implementations of ConvBiLSTM-AE (PA-F1 = 0.6689) and TranAD (PA-F1 = 0.6838) on the same evaluation split confirm this performance gap. A controlled USAD experiment, with PA-F1 = 0.7343 for physics features versus 0.6687 for raw Supervisory Control and Data Acquisition (SCADA), demonstrates that the extracted features provide the detection signal independently of the model architecture. Adding a bidirectional Gated Recurrent Unit (GRU) refinement stage improves PA-F1 by 8.1 percentage points on HAI 21.03, but the same stage reduces it by 6.8 percentage points on HAI 23.05, where attacks manifest as brief perturbations; four alternative Stage 2 designs reproduce this degradation. We therefore characterize temporal refinement as beneficial only for sustained-deviation attacks and identify Stage 1 as the primary deployable detector. This study is the first to apply physics-informed features, report both PA-F1 and eTaPR on HAI 23.05, and perform per-window error diagnosis on this dataset. Results show that 10 of 15 detected windows are covered by fewer than 10% of their timesteps, revealing a structural tension between PA-F1 and eTaPR. Full article
Show Figures

Graphical abstract

51 pages, 2014 KB  
Review
AIoT-Based Security Systems for Smart Homes and Smart Buildings: A Tertiary Study
by Francesco Pilotti, Aurora Pavone, Lia Di Sabatino Farinelli, Simone Tinelli and Gaetanino Paolone
Future Internet 2026, 18(6), 307; https://doi.org/10.3390/fi18060307 - 5 Jun 2026
Viewed by 788
Abstract
The rapid evolution of Smart Homes and Smart Buildings is driven by the transition from the Internet of Things (IoT) to the Artificial Intelligence of Things (AIoT). Within this scenario, Security Systems are particularly critical and data-intensive systems. Despite extensive research, a high-level [...] Read more.
The rapid evolution of Smart Homes and Smart Buildings is driven by the transition from the Internet of Things (IoT) to the Artificial Intelligence of Things (AIoT). Within this scenario, Security Systems are particularly critical and data-intensive systems. Despite extensive research, a high-level synthesis focusing exclusively on the synergy between AIoT and Security Systems in Smart Home and Smart Building application domains is still lacking. To bridge this gap, this paper presents a systematic Tertiary Study (TS) following a well-known research protocol. 13 Secondary Studies (SSs) were synthesized and discussed from an initial pool of 139 publications (years 2024–2025). Findings reveal that monitoring is the most addressed system, followed by security and alarm, while surveillance and access control remain comparatively underexplored. Moreover, results highlight a definitive shift toward Edge and Fog computing to meet latency and privacy requirements, whereas Deep Learning and Ensemble Learning techniques predominate for anomaly detection and predictive maintenance. This study identifies open challenges and future research directions, providing a foundational roadmap for resilient, cognitive-driven security infrastructures in smart environments. Full article
Show Figures

Figure 1

30 pages, 5542 KB  
Article
Secure Federated Intrusion Detection for Resource-Constrained IoT Devices Using Lightweight Cryptography: A Hardware-Validated Study
by Yerlan Tursynbek, Nurtay Albanbay, Djamel Djenouri, Shahid Latif, Ainur Akhmediyarova, Zhibek Alibiyeva, Janna Alimkulova and Dina Oralbekova
Future Internet 2026, 18(6), 306; https://doi.org/10.3390/fi18060306 - 5 Jun 2026
Viewed by 572
Abstract
Federated learning (FL) enables distributed model training in IoT environments while keeping raw data on local devices. However, protecting model-update exchange is difficult on microcontroller-class devices due to strict latency, memory, and energy constraints. Existing studies often evaluate lightweight cryptography outside complete FL [...] Read more.
Federated learning (FL) enables distributed model training in IoT environments while keeping raw data on local devices. However, protecting model-update exchange is difficult on microcontroller-class devices due to strict latency, memory, and energy constraints. Existing studies often evaluate lightweight cryptography outside complete FL pipelines or on more powerful hardware, leaving its practical overhead on MCU-class devices insufficiently explored. This paper presents an end-to-end, hardware-validated secure framework for exchanging model updates in federated learning on resource-constrained IoT microcontrollers. Implemented on ESP32-based edge devices, the framework combines lightweight block ciphers (SPECK, SIMON, and PRESENT), HMAC-SHA256 for integrity verification, and ECDH-HKDF for session-key establishment. The evaluation assessed latency, throughput, RAM/ROM footprint, and energy consumption. Results show that SPECK provides the lowest overhead (0.13 µs/byte, 8.68 MB/s, 138.3 mJ), SIMON offers intermediate performance (0.41 µs/byte, 1.96 MB/s, 184.9 mJ), and PRESENT incurs the highest computational cost (89.37 µs/byte, 0.011 MB/s, 446.2 mJ). In the CICIoT2023 federated intrusion-detection evaluation, the secure model maintained stable convergence and achieved 85.43% accuracy after 20 rounds, remaining close to the centralized baseline. These findings demonstrate the practical feasibility of secure model-update exchange in FL on real IoT microcontrollers and provide hardware-grounded guidance for cipher selection under tight resource budgets. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Figure 1

24 pages, 2340 KB  
Article
A Stability-Centric Framework for Lightweight and Explainable Intrusion Detection
by Abdalilah Alhalangy, Saleh Abdulrahman Alkhamis and Eman Abouelkheir
Future Internet 2026, 18(6), 305; https://doi.org/10.3390/fi18060305 - 5 Jun 2026
Viewed by 518
Abstract
Effective intrusion detection for Internet of Things (IoT) environments requires balancing predictive performance, resource efficiency, and interpretability—particularly in real-world deployments where traffic distributions and attack scenarios vary. While many studies report near-perfect detection on benchmark datasets, this often overlooks model stability under distribution [...] Read more.
Effective intrusion detection for Internet of Things (IoT) environments requires balancing predictive performance, resource efficiency, and interpretability—particularly in real-world deployments where traffic distributions and attack scenarios vary. While many studies report near-perfect detection on benchmark datasets, this often overlooks model stability under distribution shifts. This paper addresses this gap by introducing a stability-focused evaluation of lightweight, explainable intrusion detection models using compact IoT-23 scenarios and a constrained set of 14 connection-level features for interpretability. Four lightweight models—logistic regression, random forest, XGBoost, and LightGBM—are assessed within a unified pipeline. Beyond standard internal validation, we implement a strict cross-scenario evaluation framework featuring a fully unseen malware capture. Our proposed Internal–External Stability Gap (IESG) framework, enhanced with normalized and multi-metric measures, highlights the degradation in consistency between internal and external metrics. Surprisingly, even models with high internal F1 scores (up to 0.9994) may experience considerable drops in external macro-F1 and specificity, exposing weaknesses in conventional evaluation. Experimentally, LightGBM provides the best trade-off between performance and compactness (606 KB) and shows the smallest stability gap for malicious detection. Nevertheless, all models show reduced balanced performance under scenario shift, underscoring that deployment readiness hinges on stability under changing conditions. Feature ablation reveals that leveraging high-impact features, such as port information, can boost internal accuracy at the expense of generalization. In summary, we demonstrate that while lightweight models deliver strong detection, only those proven stable across scenarios are viable for real-world IoT intrusion detection. Our evaluation framework offers a practical, interpretable tool for assessing model robustness. Full article
Show Figures

Figure 1

20 pages, 3101 KB  
Article
Dual-Stream Wavelet Network for Early Knee Osteoarthritis Grading in IoT-Enabled Smart Clinics
by Lassaad Ben Ammar, Altahir Saad and Ahod Alghuried
Future Internet 2026, 18(6), 304; https://doi.org/10.3390/fi18060304 - 4 Jun 2026
Viewed by 468
Abstract
Knee Osteoarthritis (KOA) is a leading contributor to global physical disability, where delayed diagnosis often results in irreversible joint damage and socio-economic cost. Early diagnosis remains challenging due to subtle radiographic biomarkers and limited access to specialized expertise, particularly in distributed healthcare settings. [...] Read more.
Knee Osteoarthritis (KOA) is a leading contributor to global physical disability, where delayed diagnosis often results in irreversible joint damage and socio-economic cost. Early diagnosis remains challenging due to subtle radiographic biomarkers and limited access to specialized expertise, particularly in distributed healthcare settings. Within the evolving landscape of the Future Internet, characterized by Internet of Medical Things (IoMT), edge–cloud computing, and intelligent digital health infrastructures, there is an increasing demand for scalable, low-latency, and explainable AI-driven diagnostic solutions. In this work, we propose a Dual-Stream Wavelet Fusion Network (DS-WFN) alongside a distributed edge-cloud architectural roadmap tailored for deployment in distributed and edge-enabled healthcare ecosystems. The framework integrates a spatial morphological stream with a spectral wavelet stream, augmented by an Adaptive Wavelet Selection Mechanism (AWSM). The AWSM dynamically selects optimal frequency bases (Haar, Symlet, Daubechies) to preserve fine-grained diagnostic features typically lost in conventional CNN architectures. An Adaptive Spatial Alignment (ASA) module further ensures efficient fusion of heterogeneous representations, enabling robust feature integration across computational nodes. Experimental results across a five-fold patient-isolated cross-validation protocol demonstrate that the DS-WFN achieves a mean classification accuracy of 76.3% (95% CI: 71.6–80.8%) and a macro-averaged F1-score of 0.747 (95% CI: 0.697–0.795), consistently outperforming single-stream baselines while preventing patient-level data leakage. Furthermore, Grad-CAM visualizations provide interpretable outputs aligned with clinical diagnostic criteria, supporting trustworthy AI integration into digital healthcare workflows. Furthermore, we disclose a methodological framework for edge-based implementation, highlighting how localized inference ensures data sovereignty and real-time clinical support. By combining multiscale signal processing with deep learning under a Future Internet paradigm, this work contributes a scalable, explainable, and edge-ready diagnostic framework for early KOA detection, enabling intelligent, connected, and resource-efficient healthcare services. Full article
(This article belongs to the Special Issue Distributed Intelligence for IoT and Smart Systems)
Show Figures

Figure 1

18 pages, 5771 KB  
Systematic Review
Explainable and Human-Centered AIoT: A Systematic Review of Integration, Interaction, and Impact
by Adolfo A. Jurado Rosas, Marina Fernández Miranda, Gladys L. Peña Pazos, Elberth E. García Panta, Carlos A. Ramos Reyes, Milagros P. Córdova de Chang, José H. Chang Valdiviezo, Olga P. Gamarra Chirinos and Carlos E. Esquerre Aguirre
Future Internet 2026, 18(6), 303; https://doi.org/10.3390/fi18060303 - 4 Jun 2026
Viewed by 677
Abstract
This study analyzes the transition of the Artificial Intelligence of Things (AIoT) toward a Human-Centered Artificial Intelligence (HCAI) approach. Following PRISMA 2020 guidelines, a Systematic Literature Review was conducted on 1 April 2026, retrieving literature from Scopus, Web of Science, SciELO, and Springer [...] Read more.
This study analyzes the transition of the Artificial Intelligence of Things (AIoT) toward a Human-Centered Artificial Intelligence (HCAI) approach. Following PRISMA 2020 guidelines, a Systematic Literature Review was conducted on 1 April 2026, retrieving literature from Scopus, Web of Science, SciELO, and Springer Nature Link. The inclusion criteria prioritized open-access, peer-reviewed English articles published between 2020 and 2025 that addressed AIoT architectures and explainability mechanisms. The screening procedure involved a dual independent review process, followed by a rigorous methodological quality assessment to minimize the risk of bias, culminating in a final sample of 40 studies from an initial pool of 971 records. The findings reveal a structural paradox: while intelligent systems achieve greater operational autonomy, legal and moral accountability remains inexorably bound to the human operator. Furthermore, 77.5% of the evaluated implementations employ superficial explainability, functioning merely as a psychological buffer to manage automation anxiety rather than providing a genuine interactive control mechanism. It is concluded that programming based on HCAI principles must shift from a post hoc feature to an inherent architectural requirement. Establishing explainability by design is imperative to guarantee an interactive audit capability that comprehensively safeguards operational integrity and preserves human agency, although the exclusive reliance on open-access literature limits visibility into proprietary commercial models. Full article
(This article belongs to the Special Issue Information Networks with Human-Centric LLMs)
Show Figures

Graphical abstract

Previous Issue
Next Issue
Back to TopTop