Previous Issue
Volume 6, June
 
 

Network, Volume 6, Issue 3 (September 2026) – 35 articles

  • Issues are regarded as officially published after their release is announced to the table of contents alert mailing list.
  • You may sign up for e-mail alerts to receive table of contents of newly released issues.
  • PDF is the official format for papers published in both, html and pdf forms. To view the papers in pdf format, click on the "PDF Full-text" link, and use the free Adobe Reader to open them.
Order results
Result details
Select all
Export citation of selected articles as:
47 pages, 2380 KB  
Systematic Review
Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review
by Majed Alzahrani, Priyadarsi Nanda, Manoranjan Mohanty and Farag El Zegil
Network 2026, 6(3), 76; https://doi.org/10.3390/network6030076 - 10 Sep 2026
Viewed by 98
Abstract
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned [...] Read more.
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned against 2024–2025 EU regulatory requirements (NIS2, the Cyber Resilience Act). Eligibility criteria: Peer-reviewed empirical studies proposing or evaluating a machine learning or deep learning IoT intrusion detection method published in English from January 2018 (limited pre-2018 exceptions for seminal works). Information sources: IEEE Xplore, SpringerLink, Elsevier ScienceDirect, Scopus, Web of Science, and Google Scholar, searched on 12 February 2025. Risk of bias: Each candidate was scored against four criteria (objectives clarity, methodological soundness, reproducibility, IoT-security relevance); studies scoring at least 3 out of 4 were retained. Screening and scoring were performed by one reviewer, with a second reviewer independently checking 20 percent of records. Synthesis methods: Narrative thematic synthesis; heterogeneous metrics and incompatible datasets across studies precluded quantitative meta-analysis. Included studies: Of 427 records identified, 52 studies initially met inclusion criteria; a post hoc independently validated reconstruction of individual QA1–QA4 scores subsequently found that six did not meet the threshold or topical eligibility criteria, yielding a final 46-study corpus. Main findings: Generative adversarial networks (GANs) dominate dataset augmentation work, graph-based communication analysis addresses dependency modelling, and methods based on transformers or federated learning emerge from 2023 onward. Certainty of evidence: No formal grading (GRADE) applies to this narrative synthesis. Confidence in the corpus composition is high, following independent QA1–QA4 validation, while confidence in the thematic findings is moderate given single-reviewer screening and judgment-based classification. Conclusions: We identify three recurring gaps: real-time detection under resource constraints, dependency-aware detection, and regulatory compliance. Closing these gaps requires detection methods that treat IoT security as a networked and regulated system rather than an isolated device classification problem. Registration: Open Science Framework, 10.17605/OSF.IO/NMAK4 (registered retrospectively). No external funding supported this review. Full article
23 pages, 331 KB  
Review
Secure Programming and Secure Design in DevSecOps: A Literature-Based Conceptual Synthesis
by Faisal A. Al-Qadda, Abdulaziz Y. Alhumaidi and Nazar Abbas Saqib
Network 2026, 6(3), 75; https://doi.org/10.3390/network6030075 - 9 Sep 2026
Viewed by 118
Abstract
Secure programming and secure design are often managed as separate activities, leaving a gap between architectural intent and the implementation that reaches production. This paper presents a structured conceptual synthesis of twenty core publications, supplemented by standards and recent work on AI-assisted development. [...] Read more.
Secure programming and secure design are often managed as separate activities, leaving a gap between architectural intent and the implementation that reaches production. This paper presents a structured conceptual synthesis of twenty core publications, supplemented by standards and recent work on AI-assisted development. It makes three contributions. First, it frames secure programming as the implementation-facing realization of secure design within a closed feedback loop. Second, it uses an explicit 0–5 rubric to produce an illustrative comparison of Waterfall, Iterative, Spiral, and Agile with DevSecOps across six security-integration dimensions. These profiles are structured author judgments, not empirical measurements of security effectiveness. Third, it proposes an operational Secure SDLC–DevSecOps framework that links six stages through named artifacts, accountable roles, traceability rules, release gates, exceptions, and outcome measures. A comparison with NIST SSDF, OWASP SAMM, Microsoft SDL, ISO/IEC 27034, and OWASP implementation guidance shows that the individual practices are established; the framework’s intended contribution is the project-level control loop that connects design decisions to pipeline evidence and production feedback. The illustrative profiles place Spiral and Agile with DevSecOps close together under the baseline weights, while sensitivity scenarios show that their ordering depends on whether design-time risk analysis or delivery-time verification is emphasized. The synthesis therefore supports contextual tailoring rather than a universal ranking. Full article
Show Figures

Figure 1

30 pages, 22021 KB  
Article
Sentinel: Proactive Elastic Controller Scaling with MARL-Guided Load Redistribution for Resilient SD-WANs
by Abdulrahman M. Abdulghani, Azizol Abdullah, Amir Rizaan Abdul Rahiman, Nor Asilah Wati Abdul Hamid and Bilal Omar Akram
Network 2026, 6(3), 74; https://doi.org/10.3390/network6030074 - 9 Sep 2026
Viewed by 88
Abstract
Controller placement in software-defined wide area networks (SD-WANs) is commonly optimized assuming continuously available controllers, leaving the control plane vulnerable to overload and abrupt reassignment after controller unavailability. This paper presents Sentinel, an auditable supervisory mechanism that extends GMM-MARL placement into proactive elastic [...] Read more.
Controller placement in software-defined wide area networks (SD-WANs) is commonly optimized assuming continuously available controllers, leaving the control plane vulnerable to overload and abrupt reassignment after controller unavailability. This paper presents Sentinel, an auditable supervisory mechanism that extends GMM-MARL placement into proactive elastic controller management through utilization monitoring, hysteresis-based scaling, learned aiding-controller placement, and bounded incremental migration. Deterministic supervision decides when scaling is authorized, whereas the learned policy selects placement and assignment subject to capacity and latency constraints. Evaluation uses a 95-node composite topology derived from OS3E, Darkstrand, and CRL. An operational track compares proactive Sentinel scale-out with reactive CCA-PSO, and an equal-resource ablation separates resource restoration from placement quality. Sentinel reduces operational average case latency (ACL) from 3988 to 3008 µs and limits maximum utilization to 87.5%, versus 98.4% under CCA-PSO. Under equal resources, Sentinel achieves 3453 ± 627 µs ACL, within 2.9% of static GMM-MARL re-optimization. An auxiliary matched RL application benchmark on OS3E against a reconstruction (RL-HCP*) shows lower ACL and worst-case latency for RL-HCP*, while Sentinel retains competitive load and coordination behavior. Overall, proactive controller headroom restoration, learned placement, and bounded migration provide resilient control-plane management without disruptive global reassignment. Full article
Show Figures

Figure 1

20 pages, 1271 KB  
Article
Hybrid Watermarking and Adaptive Misinformation for Protection Against AI Model Extraction in Edge-Deployed Cyber-Physical Security
by Fatimah Azzahrah binti Razali, Mohamed Hadi Habaebi and Mohammed Abdullah Salem Al-Hussaini
Network 2026, 6(3), 73; https://doi.org/10.3390/network6030073 - 8 Sep 2026
Viewed by 106
Abstract
Artificial intelligence (AI) models are increasingly deployed in edge-deployed cyber-physical security systems for tasks encompassing monitoring, threat classification, and automated decision-making. While these models offer robust performance, their deployment through open or semi-open Machine Learning as a Service (MLaaS) interfaces exposes them to [...] Read more.
Artificial intelligence (AI) models are increasingly deployed in edge-deployed cyber-physical security systems for tasks encompassing monitoring, threat classification, and automated decision-making. While these models offer robust performance, their deployment through open or semi-open Machine Learning as a Service (MLaaS) interfaces exposes them to severe security threats, prominently model extraction attacks. In such attacks, an adversary systematically queries a target API to replicate the victim model’s behavior. This study proposes a novel hybrid defense framework combining Adaptive Misinformation (AM) and Trigger-Based Watermarking (WM) to protect AI models against black-box extraction. Utilizing a LeNet architecture, the victim model was trained on the MNIST dataset, while a simulated attack utilized 50,000 EMNIST samples to train a clone model. The framework employs Maximum Softmax Probability (MSP) for out-of-distribution (OOD) detection to identify suspicious queries and strategically inject misleading responses, alongside a fine-tuned embedded watermark for ownership verification. Experimental evaluations using 10-fold cross-validation reveal that the baseline extraction attack yielded a clone model accuracy of 96.32%. Upon implementing the AM + WM framework, clone model accuracy degraded significantly to 53.67%, while the victim model maintained an accuracy of 98.97%. Furthermore, the protected model achieved a 100% Trigger Match Rate (TMR), ensuring reliable intellectual property verification. The proposed framework provides a prototype validation for lightweight edge architectures to balance security, model utility, and ownership protection in cyber-physical deployments. Full article
Show Figures

Figure 1

29 pages, 6477 KB  
Article
A Risk-Gated Security Attention Mechanism for Rare-Threat Detection in Industrial IoT Networks
by Shaimaa Ahmed Elsaid, Ahmed M. Saad and Eslam Mahmoud Fouda
Network 2026, 6(3), 72; https://doi.org/10.3390/network6030072 - 8 Sep 2026
Viewed by 130
Abstract
In current state-of-the-art intrusion detection systems (IDSs), models are trained to detect the repetitive behavior of data traffic. This leads to the problem of ignoring rare yet important attacks. To solve the problem stated above, a risk-gated security attention (RGSA) architecture is proposed. [...] Read more.
In current state-of-the-art intrusion detection systems (IDSs), models are trained to detect the repetitive behavior of data traffic. This leads to the problem of ignoring rare yet important attacks. To solve the problem stated above, a risk-gated security attention (RGSA) architecture is proposed. The initialization of the risk estimator based on the CVE/CVSS severity score enables the attention network to detect important yet rare patterns. Furthermore, a tier-aware focal loss is proposed to mitigate security threats in the real world without any data augmentation process. Evaluations were conducted on held-out 80/20 test splits of the CIC-IDS2017, CIC-IDS2018, and CIC-IoT2023 datasets. The calibrated binary detection process reached false negative rates (FNRs) of 0.50% and 0.40% on the CIC-IDS2017 and CIC-IDS2018 datasets, respectively, remaining below the 1.0% FNR operational target adopted in this study. For micro-support critical threats, precise discrete analysis had to be applied to maintain statistical validity. Also, weighted F1-scores of at least 99.65% were consistently achieved for all testbeds analyzed. This network contains 284,317 trainable parameters and strictly avoids the creation of any synthetic samples through complete rejection of synthetic oversampling. The findings indicate that adding priors for security tiers to the attention process is favorable for moving towards an impact-based threat management approach. Full article
Show Figures

Figure 1

34 pages, 4895 KB  
Article
Direct-to-Cell NTN Systems in Terrestrial 5G Bands: Network-Level Sensitivity Analysis and PFD/EPFD Limits for Coexistence
by Alexander Pastukh, Olga Mironova and Valery Tikhvinskiy
Network 2026, 6(3), 71; https://doi.org/10.3390/network6030071 - 7 Sep 2026
Viewed by 261
Abstract
Direct-to-cell (D2C) non-terrestrial networks (NTNs) based on 5G technology are emerging as a key complement to terrestrial cellular networks, extending connectivity to underserved and remote areas while enabling integration with existing mobile ecosystems. As these systems begin operating in frequency bands already used [...] Read more.
Direct-to-cell (D2C) non-terrestrial networks (NTNs) based on 5G technology are emerging as a key complement to terrestrial cellular networks, extending connectivity to underserved and remote areas while enabling integration with existing mobile ecosystems. As these systems begin operating in frequency bands already used by terrestrial International Mobile Telecommunications (IMT) networks, coexistence becomes critical. This paper presents a victim-centric methodology for evaluating D2C interference into terrestrial 5G networks in the 694/698 MHz-2.7 GHz regulatory study range. Seven downlink carrier cases and four uplink carrier cases between 734 and 2620 MHz are evaluated. For a prescribed external interference-to-noise ratio, the external contribution is referenced to receiver thermal noise, while terrestrial intra-network interference remains part of the baseline and interfered signal-to-interference-plus-noise ratio (SINR). The resulting throughput loss is translated into candidate power-flux-density (PFD) and equivalent-power-flux-density (EPFD) protection levels. A reference non-geostationary-satellite-orbit (NGSO) system is used only to motivate the assumed receiver-exposure fractions; the numerical network results are therefore conditional on those exposure assumptions. The same external interference level produces approximately three times greater network throughput loss at base stations than at user equipment, so direction-specific protection levels are required. For downlink protection, the tested 3 dB noise-rise case gives candidate PFD levels from −109.23 to −98.17 dB(W/(m2·MHz)); for opposite-direction cross-border uplink protection, I/N = −6 dB gives candidate EPFD levels from −138.23 to −130.18 dB(W/(m2·MHz)) for non-AAS base stations. The approximately 11 dB offset for AAS cases results from the maximum-gain normalization used in EPFD and should not be interpreted as evidence of greater satellite exposure. These values are tested candidate levels rather than estimates of an exact 5% crossing point. Full article
(This article belongs to the Special Issue 5G and Next-Generation Communication Technologies)
Show Figures

Figure 1

25 pages, 622 KB  
Systematic Review
When and How to Use Post-Quantum Cryptography: A Systematic Literature Review
by Tasneem Annahdi, Albandari Alsumayt and Naya Nagy
Network 2026, 6(3), 70; https://doi.org/10.3390/network6030070 - 31 Aug 2026
Viewed by 233
Abstract
Post-quantum cryptography (PQC) is driven by the threat posed by quantum computers, particularly the harvest-now-decrypt-later attack. PQC aims to prepare classical systems and hardware to become resilient against quantum attacks. This research discusses the system vulnerabilities, the need to migrate to PQC, and [...] Read more.
Post-quantum cryptography (PQC) is driven by the threat posed by quantum computers, particularly the harvest-now-decrypt-later attack. PQC aims to prepare classical systems and hardware to become resilient against quantum attacks. This research discusses the system vulnerabilities, the need to migrate to PQC, and how to integrate this migration. PQC has become one of the solutions for addressing today’s vulnerabilities and threats while increasing security. The paper concludes that harvest-now-decrypt-later, Q-Day attacks, and new quantum attacks are today’s most critical threats, which can be addressed by deploying PQC solutions and, thus, increasing security. This research proposes a conceptual multi-phased model framework for the migration. The framework first addresses system objectives, goals and assets, then ranks assets based on the highest sensitivity. Crypto-Agility is achieved via the automation of PQC migration, such as the automation of re-keying endpoints, followed by the automation of auditing and testing of each migration stage. Human judgment is required to review the migration process. Once one asset is successfully transitioned, the framework goes to the next highest asset; otherwise, testing is repeated. This is expected to help systems migrate at the lowest cost and with the fewest consequences. However, the limitation of PQC migration is its high resource cost, time, requirement of human professionals, burden on existing systems, and financial expenses. Lastly, the paper recommends creating an ML model to help rank a system’s data and vulnerabilities. Moreover, the paper recommends conducting experiments to evaluate the effectiveness of the proposed framework. In addition, the paper recommends performing migration in relation to a real-world company. Full article
Show Figures

Figure 1

36 pages, 2804 KB  
Article
Exploiting and Mitigating Staleness in Distributed Edge Offloading via Predictive Load Awareness
by Sawsan Ali Hamid, Yassine Boujelben and Faouzi Zarai
Network 2026, 6(3), 69; https://doi.org/10.3390/network6030069 - 28 Aug 2026
Viewed by 202
Abstract
Distributed offloading systems rely on periodic broadcasts to disseminate server state, yet propagation delays inevitably leave agents operating with stale information at decision time. Staleness is typically viewed as a performance limitation that should be minimized. This work revisits this assumption by studying [...] Read more.
Distributed offloading systems rely on periodic broadcasts to disseminate server state, yet propagation delays inevitably leave agents operating with stale information at decision time. Staleness is typically viewed as a performance limitation that should be minimized. This work revisits this assumption by studying its role in a distributed asynchronous offloading framework that operates under delayed and potentially stale load information. Players make independent server-selection decisions using locally available information and may optionally compensate for staleness through lightweight load-prediction mechanisms. A central finding is that staleness can act as an implicit coordination mechanism. By inducing heterogeneous and desynchronized perceptions of system state, it naturally diversifies agent decisions and mitigates collective migration oscillations that arise under perfect information sharing. These oscillations are shown to significantly delay convergence and can lead to unstable behavior in lightly loaded regimes. In contrast, stale yet diverse views prevent synchronized reactions and promote faster stabilization. The results further show that the value of prediction increases with communication staleness. As broadcast intervals grow and server-state information becomes increasingly outdated, prediction-based approaches substantially reduce performance degradation, improve load-balancing fairness, and lower migration activity relative to stale-information decisions. The numerical results show that increasing the broadcast interval from 0.5 s to 4 s causes a performance deterioration of approximately 95% for stale-information decisions, whereas prediction-based approaches limit this degradation to less than 15% over the same range. These findings suggest that the objective of distributed offloading should not be to eliminate staleness entirely, but rather to combine its stabilizing effects with lightweight predictive mechanisms that mitigate its negative impact on decision quality. Full article
(This article belongs to the Special Issue Convergence of Edge Computing and Next Generation Networking)
Show Figures

Figure 1

37 pages, 2899 KB  
Article
Green FTTR in Smart Buildings: A Comparative Framework for Energy Efficiency, QoS and QoE Evaluation
by Jorge Duarte, António Valente, Fernando Santos, Pedro Lopes, Miguel Ângelo Mota, Sérgio Ramos and Sérgio Leitão
Network 2026, 6(3), 68; https://doi.org/10.3390/network6030068 - 25 Aug 2026
Viewed by 222
Abstract
The growth of cloud services and immersive applications based on extended reality (XR), including Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR), imposes increasingly demanding requirements on access networks. The large-scale integration of IoT devices in smart buildings further increases the [...] Read more.
The growth of cloud services and immersive applications based on extended reality (XR), including Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR), imposes increasingly demanding requirements on access networks. The large-scale integration of IoT devices in smart buildings further increases the need for high throughput, low latency and jitter, and reliable connectivity. Traditional Fiber-to-the-Home (FTTH) networks with a single access point (AP) become quite limiting when there are high performance requirements, with many users with indoor mobility and high device density. Fiber-to-the-Room (FTTR) is an extension of FTTH, which brings fiber optics to each room of the house through a Main FTTR Unit (MFU) and several Sub FTTR Units (SFU) along with the APs, with centralized device management. Green FTTR networks are characterized by their energy efficiency through centralized control of signal power and Dynamic Bandwidth Allocation (DBA) management. The fgONT architecture allows for deterministic network slicing, enabling the allocation of specific resources isolated from the rest of the network traffic, allowing for predictable bandwidth and QoS. This work presents a framework that allows for a comparative analysis of FTTR and FTTH networks in different scenarios in order to ensure a compromise between transmission quality, network energy efficiency, and the user’s perceived experience. The results obtained show that, in high device density scenarios, FTTR reduces the average packet loss from 52.69% to less than 0.08%, decreases the average latency from 151 ms to less than 2 ms, and maintains the overall QoE above 0.974, compared to 0.27 in FTTH with a single AP. Full article
(This article belongs to the Special Issue Advances in Wireless Communications and Networks)
Show Figures

Figure 1

47 pages, 1670 KB  
Article
Interference-Calibrated Algebraically Projected Antenna Selection with Certified Graph Learning for Massive MIMO Under Realistic Multi-Cell Impairments
by Iacovos Ioannou and Vasos Vassiliou
Network 2026, 6(3), 67; https://doi.org/10.3390/network6030067 - 22 Aug 2026
Viewed by 290
Abstract
Antenna selection is investigated as a means of reducing radio-frequency (RF) chain power in massive multiple-input multiple-output (MIMO) base stations under realistic channel state information (CSI) impairments. The study is motivated by the mismatch between conventional selection objectives and multi-cell operation with estimation [...] Read more.
Antenna selection is investigated as a means of reducing radio-frequency (RF) chain power in massive multiple-input multiple-output (MIMO) base stations under realistic channel state information (CSI) impairments. The study is motivated by the mismatch between conventional selection objectives and multi-cell operation with estimation error, pilot contamination, spatial correlation and inter-cell interference. APCS-Boost-R is introduced as the primary contribution. An interference-whitened D-optimal seed is combined with projected rank-one exchanges and a calibrated surrogate that incorporates a user-side interference-plus-noise report and a closed-form estimation-error correction. APCS-Boost-RG is retained as an optional graph neural network (GNN) refinement in which residual exchanges are ranked after the algebraic solution has been formed, while feasibility and non-degradation of the calibrated surrogate are verified deterministically. In a three-cell urban macro configuration derived from Third Generation Partnership Project (3GPP) TR 38.901 with 64 antennas, 16 active RF chains and eight users per cell, APCS-Boost-R achieves 19.364 bit/s/Hz over 200 paired realizations. Improvements of 2.58 percent over APCS-Boost, 6.76 percent over greedy search and 10.16 percent over a genetic algorithm are obtained. APCS-Boost-RG adds 0.019 bit/s/Hz but is treated as an optional refinement because it requires a second-stage neighborhood evaluation and offline model maintenance. In the archived common timing record, APCS-Boost-R requires 20.376 ms per three-cell realization, compared with 12.728 ms for APCS-Boost, 57.775 ms for norm-initialized greedy search and 41.302 ms for the genetic algorithm, while APCS-Boost-RG requires 24.0 ms versus 20.4 ms for APCS-Boost-R in the separate archived learned-stage record. Separate reconstructions on the documented reproducibility host require 55.3±14.5 ms for APCS-Boost-R and 592.2±181.9 ms for a complete APCS-Boost-RG rebuild. Additional paired examinations confirm robustness across stronger search budgets, report imperfections, regularized precoding, coordination, near-field sensitivity, hardware perturbations, and configurations ranging from 32 to 128 antennas and one to seven cells. Full article
(This article belongs to the Special Issue Advances in Wireless Communications and Networks)
Show Figures

Graphical abstract

34 pages, 9427 KB  
Review
Adaptive 360° Video Streaming: Prediction, Tiling, and Transport Trade-Offs
by Muhammad Farooq, Gioacchino Manfredi, Luca De Cicco and Saverio Mascolo
Network 2026, 6(3), 66; https://doi.org/10.3390/network6030066 - 17 Aug 2026
Viewed by 383
Abstract
The growing demand for virtual reality and immersive applications has increased interest in 360° video streaming. When viewing omnidirectional content through a head-mounted display, users observe only a limited portion of the content, i.e., the viewport, at any given time. Consequently, transmitting the [...] Read more.
The growing demand for virtual reality and immersive applications has increased interest in 360° video streaming. When viewing omnidirectional content through a head-mounted display, users observe only a limited portion of the content, i.e., the viewport, at any given time. Consequently, transmitting the complete panoramic frame at uniformly high quality is bandwidth-inefficient. This review presents a system-level analysis of viewport-adaptive three-degree-of-freedom (3DoF) 360° video streaming, focusing on the coupled roles of viewport prediction, tile-based multi-rate encoding and bitrate allocation, transport mechanisms, and edge-assisted processing. The reviewed literature is examined to identify the design dependencies and trade-offs among these components. Viewport-adaptive approaches seek to reduce the bandwidth allocated to regions outside the instantaneous viewport while preserving the quality of the visible region. The analysis shows that their effectiveness cannot be attributed to prediction accuracy alone: the resulting Quality of Experience (QoE) depends jointly on tile granularity, bitrate allocation, buffer occupancy, transport delay, and whether prioritized tiles arrive before their playback deadlines. Finer tiling can improve spatial selectivity but increases coding, signaling, and request overhead. Moreover, HTTP/2, HTTP/3/QUIC, RTP/RTSP, and WebRTC present different reliability, latency, congestion-control, and scalability trade-offs across buffered video-on-demand, low-latency live streaming, and interactive immersive applications. Based on this synthesis, the review formulates a unified closed-loop cross-layer framework that coordinates prediction, tiling, bitrate allocation, request timing, transport configuration, buffering, and edge processing under bandwidth, latency, and resource constraints. Full article
Show Figures

Figure 1

35 pages, 2657 KB  
Article
Design and Evaluation of PSA-FRR and PSAR-FRR for Fast Reroute in Homogeneous and Hybrid SDN Networks
by Md Imtiaz Ahmed and Yaser Al Mtawa
Network 2026, 6(3), 65; https://doi.org/10.3390/network6030065 - 10 Aug 2026
Viewed by 287
Abstract
Fast Reroute (FRR) after link failures is essential for carrier-grade Software-Defined Networking (SDN), yet hybrid deployments remain dominated by slow legacy routing convergence. This paper presents two port-state-driven FRR mechanisms for homogeneous and hybrid SDN networks. First, Port-State-Aware Fast Reroute (PSA-FRR) uses OpenFlow [...] Read more.
Fast Reroute (FRR) after link failures is essential for carrier-grade Software-Defined Networking (SDN), yet hybrid deployments remain dominated by slow legacy routing convergence. This paper presents two port-state-driven FRR mechanisms for homogeneous and hybrid SDN networks. First, Port-State-Aware Fast Reroute (PSA-FRR) uses OpenFlow port-status events to trigger proactive, rule-based protection in the data plane. Second, Port-State-Aware Neural Fast Reroute (PSAR-FRR) formulates hybrid FRR as a controller-local multi-class classification problem and predicts the backup egress port from a port-centric state representation, enabling microsecond-scale decision latency. We evaluate the methods on the Abilene wide-area network (WAN) topology using Mininet with Open vSwitch (OVS) and a Ryu controller (homogeneous case) and Graphical Network Simulator-3 (GNS3) with Cisco IOS routers (hybrid baseline). In homogeneous SDN emulation, PSA-FRR restores connectivity within 30–100 ms under the evaluated configurations. In the hybrid baseline, conventional routing protocols converge in 13.8–256.1 s (Enhanced Interior Gateway Routing Protocol (EIGRP), Intermediate System to Intermediate System (IS-IS), Open Shortest Path First (OSPF), Border Gateway Protocol (BGP), and Routing Information Protocol (RIP)), confirming that control-plane recovery cannot meet a 50 ms target. Using the collected dataset, PSAR-FRR reduces controller decision time from 6.753 μs (PSA-FRR rule evaluation) to 0.214 μs (deep neural network (DNN) inference), a 31.5× speedup. These results show that port-state awareness combined with learned, controller-local policies can substantially reduce the decision-to-action latency of FRR, providing a practical path toward low-latency failure recovery in SDN migration scenarios. Full article
(This article belongs to the Special Issue Recent Advances in Software-Defined Networking (SDN))
Show Figures

Figure 1

46 pages, 2025 KB  
Article
HERMES: Metric-Driven Multi-Transport Routing for Civilian Messaging During Connectivity Disruption
by Charbel El Gemayel, Joseph El Gemayel and Joseph Constantin
Network 2026, 6(3), 64; https://doi.org/10.3390/network6030064 - 6 Aug 2026
Viewed by 471
Abstract
Civilian communication systems often fail during armed conflicts, political unrest, and large-scale Internet disruptions—precisely when reliable communication is most needed. This paper presents HERMES, a resilient hybrid communication architecture that integrates HTTP/IP networking, Bluetooth Low Energy (BLE) mesh communication, and Delay-Tolerant Networking (DTN) [...] Read more.
Civilian communication systems often fail during armed conflicts, political unrest, and large-scale Internet disruptions—precisely when reliable communication is most needed. This paper presents HERMES, a resilient hybrid communication architecture that integrates HTTP/IP networking, Bluetooth Low Energy (BLE) mesh communication, and Delay-Tolerant Networking (DTN) within a unified adaptive routing framework. Unlike conventional approaches that treat alternative transports as backup solutions, HERMES dynamically selects the most efficient transport path based on current network conditions using a transport-aware forwarding policy whose cost function combines round-trip time, transport preference, and observed link risk. The architecture is built on distributed microservices that support topology discovery, shortest-path routing, and fault-tolerant message delivery. Reliability is enhanced through acknowledgments, bounded retransmissions, duplicate suppression, and graceful degradation mechanisms, while end-to-end authenticated encryption (Noise XX with a Double Ratchet) ensures secure communication across transport changes. A prototype implementation developed in C# on .NET 9 was evaluated on a five-node testbed, and a custom Network Simulator 3 (NS-3) module was used to extend the evaluation to networks of up to 500 nodes, under multiple failure scenarios, including node crashes, network partitioning, and complete Internet outages. Experimental results show that HERMES maintains perfect or near-perfect delivery in static topologies, including during a complete Internet blackout that disables IP-only messaging. Compared with the published Delay-Tolerant Networking protocols Epidemic and PRoPHET at one hundred nodes, HERMES exceeds their delivery ratio in static and failure scenarios and remains within 0.06 of them under pedestrian mobility during blackout, while transmitting roughly 35× fewer bytes– and about 21× fewer even relative to the more bandwidth-efficient MaxProp baseline. Under coordinated drop attacks by adversarial relays, HERMES degrades gracefully where flooding-based baselines collapse. This approach demonstrates that resilient civilian communication can be effectively achieved through metric-driven adaptive multi-transport routing, making it suitable for disaster recovery, contested environments, and connectivity-limited regions. Full article
Show Figures

Figure 1

33 pages, 522 KB  
Article
Embedding-Based K-Means for Multi-Controller Placement in Software-Defined Networks: A Cross-Scale Empirical Study on Internet Topology Zoo
by Aymen Chentouf, Zouhair Chiba and Mounia Miyara
Network 2026, 6(3), 63; https://doi.org/10.3390/network6030063 - 6 Aug 2026
Viewed by 304
Abstract
Multi-controller deployments in Software-Defined Networking require choosing both the number of controllers and their placement on the topology. Clustering-based methods, particularly k-means, are widely used for this problem, but the topology representation that the clustering operates on is rarely chosen explicitly. We treat [...] Read more.
Multi-controller deployments in Software-Defined Networking require choosing both the number of controllers and their placement on the topology. Clustering-based methods, particularly k-means, are widely used for this problem, but the topology representation that the clustering operates on is rarely chosen explicitly. We treat the representation step as a design axis: the clustering algorithm is held fixed at k-means with k-means++ initialisation, and the input is varied across three classical, training-free embeddings of the propagation-delay distance matrix: metric multidimensional scaling (MDS), Isomap, and Laplacian Eigenmaps (Spectral). The evaluation covers thirteen Internet Topology Zoo backbones grouped into three scale tiers under an effective-N definition, with the controller count K varied from 2 to 10, and reports node-to-controller latency (N2C), controller-to-controller latency (C2C), and load imbalance jointly rather than singly, with paired significance tests over ten distinct seeds. The representation choice is consequential: 60% of pairwise embedding comparisons are statistically separated (Holm-corrected Wilcoxon, α=0.05), and the median best-versus-worst gap per configuration is 23–25% on the two latency metrics and 71% on load imbalance. Metric MDS achieves the lowest N2C in most regimes; Spectral achieves the lowest C2C on the medium and large tiers at mid-to-high K; Isomap trades single-metric wins for worst-case robustness and is non-dominated in 79% of the 63 large-tier configurations. Across all 117 configurations, each embedding is empirically non-dominated (within the embeddings compared and on this benchmark) in 67–85% of configurations, and 16% admit a single statistically separated best choice. Two baselines contextualise these results: k-means on the raw latency matrix leads in under 8% of configurations, and a Node2Vec baseline is competitive on C2C and load balance but trails the classical methods on N2C at one to two orders of magnitude higher embedding cost. Best-embedding identities transfer from k-means to a k-medoids variant in 70% of configurations. Capacity-, energy-, and reliability-aware extensions remain open. Full article
(This article belongs to the Special Issue Recent Advances in Software-Defined Networking (SDN))
Show Figures

Figure 1

27 pages, 1681 KB  
Article
Lightweight Rescaled Range R/S-Based Real-Time DDoS Detection for Software-Defined Networks
by Mohamad Khattar Awad, Ghazal Alsholi, Haniah Altabaa, Dania Hani Abu Daqar, Shahad Alshaher and Hamed M. K. Alazemi
Network 2026, 6(3), 62; https://doi.org/10.3390/network6030062 - 5 Aug 2026
Viewed by 269
Abstract
Software-defined Networking (SDN) is a promising networking architecture that separates the control and data planes to allow flexible network management. However, the SDN architecture makes networks vulnerable to various security threats, such as Distributed Denial-of-Service (DDoS) attacks. A DDoS attack is one of [...] Read more.
Software-defined Networking (SDN) is a promising networking architecture that separates the control and data planes to allow flexible network management. However, the SDN architecture makes networks vulnerable to various security threats, such as Distributed Denial-of-Service (DDoS) attacks. A DDoS attack is one of the most common SDN threats, aiming to exhaust a network’s computational and bandwidth resources. Self-similarity is a statistical property of time series in which data patterns repeat at different time scales. Several studies have shown that network traffic exhibits increased self-similarity during DDoS attacks, making it a promising tool for DDoS detection. Despite the effectiveness of statistical methods for detecting DDoS, some methods, such as self-similarity, are discarded due to their high computational cost, leading to detection delays. This paper proposes a lightweight Rescaled Range (R/S)-based scheme for effective real-time DDoS attack detection in SDN. The scheme employs the Welford online algorithm to compute statistical parameters of the R/S scheme. Experimental results demonstrate that the proposed scheme efficiently captures changes in self-similarity and detects TCP/UDP DDoS attacks in real time. Moreover, it achieves high detection performance compared to other R/S methods, with a False Positive Rate (FPR) below 0.5% and an average computation time of 0.047 ms. Full article
Show Figures

Figure 1

21 pages, 613 KB  
Article
Two-Stage BER-Surrogate-Based Resource Allocation for Uplink SCMA in IoT Networks
by Bin Bai, Gang Xie and Yuanan Liu
Network 2026, 6(3), 61; https://doi.org/10.3390/network6030061 - 3 Aug 2026
Viewed by 198
Abstract
This paper develops a reliability-oriented resource-allocation framework for a single-cell uplink sparse code multiple access (SCMA) system with fixed low-projection codebook (LPCB) constellation components. Link-level SCMA–message-passing-algorithm (MPA) samples calibrate a compact bit-error-rate (BER) surrogate, enabling repeated candidate evaluation without embedding MPA decoding in [...] Read more.
This paper develops a reliability-oriented resource-allocation framework for a single-cell uplink sparse code multiple access (SCMA) system with fixed low-projection codebook (LPCB) constellation components. Link-level SCMA–message-passing-algorithm (MPA) samples calibrate a compact bit-error-rate (BER) surrogate, enabling repeated candidate evaluation without embedding MPA decoding in the search loop. The proposed two-stage method combines a subcarrier allocation whale optimization algorithm (SAWOA), equipped with stochastic binary mapping and exact degree-feasibility repair, with an exact Karush–Kuhn–Tucker (KKT) active-set power allocator. For the J=6, K=4 setting, exact enumeration over all 210 main conditions shows that the SAWOA attains the enumerated equal-power P1 oracle objective within relative tolerance 1010 in every case. Across 30 paired channel/optimizer blocks, each aggregating the seven power points, the SAWOA reduces the initial-gap-normalized convergence area under the curve by 47.5% relative to the Standard Binary WOA (Holm-adjusted p=1.19×105); its oracle-hit rate by iteration 20 is 93.3% versus 75.7%, while no significant AUC difference is detected relative to particle swarm optimization. After 100 iterations, the three population methods approach the same oracle plateau, whereas random is significantly worse at the midpoint (p=7.45×109). Exact KKT refinement improves every recorded SAWOA solution and reduces the equal-power surrogate by 3.64–56.27% on average across the sweep, with a maximum relative KKT residual of 1.01×1016. A single-point direct Rayleigh SCMA–MPA check confirms the executable transfer of the selected allocation and returns the same decoded BER for the SAWOA and Standard Binary WOA; it remains a bounded transfer sanity check. The results demonstrate finite-budget stage-1 search efficiency, reliable feasible support recovery, and effective exact power refinement for the investigated quasi-static configuration. Full article
(This article belongs to the Special Issue Recent Advances in Wireless Sensor Networks and Mobile Edge Computing)
Show Figures

Figure 1

20 pages, 626 KB  
Article
ARP Optimization in SDN Using Controller-Independent Strategies for Data Center Networks
by Jose Neftali Limon-Ortiz, Pedro David Arjona-Villicaña, Alejandra Guadalupe Silva-Trujillo, Francisco Javier Torres-Reyes and Francisco Javier Ramirez-Aguilera
Network 2026, 6(3), 60; https://doi.org/10.3390/network6030060 - 3 Aug 2026
Viewed by 388
Abstract
Data Centers that implement Software-Defined Networks (SDN) are not required to employ the Address Resolution Protocol (ARP), but network hosts do. Therefore, there is a need to support this protocol without modifying the intrinsic functionality of the SDN controller. In this work, four [...] Read more.
Data Centers that implement Software-Defined Networks (SDN) are not required to employ the Address Resolution Protocol (ARP), but network hosts do. Therefore, there is a need to support this protocol without modifying the intrinsic functionality of the SDN controller. In this work, four strategies for handling ARP are evaluated using an SDN and OpenFlow rules. The strategies include disabling ARP at the host level, using static MAC addresses, introducing a fake gateway, and generating ARP replies using OpenFlow flows. To our knowledge, nobody has tested and compared the main characteristics and advantages offered by these four strategies. Experimental evaluation was conducted on a real SDN network and complemented with similar experiments using Mininet. Performance was assessed using metrics such as ping response time, address resolution response time, jitter, and packet loss ratio. The results show that OpenFlow-based ARP replies provide a good balance in terms of scalability, performance, and configuration effort. This strategy achieved the lowest average ping response time (0.641 ms) and ARP response time (0.6188 ms), while avoiding the manual configuration requirements of static approaches. Full article
Show Figures

Figure 1

22 pages, 2513 KB  
Article
Towards Fully AI-Driven Converged Optical Burst Switching and Elastic Optical Networks for Autonomous QoS-Aware IoT Backhaul in 6G and Beyond
by Xaba Mondli and Bakhe Nleya
Network 2026, 6(3), 59; https://doi.org/10.3390/network6030059 - 3 Aug 2026
Viewed by 211
Abstract
The convergence of optical burst switching (OBS) and elastic optical networks (EON) offers a promising pathway for 6G IoT backhaul. However, existing solutions treat OBS and EON separately and rely on heuristic resource allocation that fails to meet stringent QoS demands. This paper [...] Read more.
The convergence of optical burst switching (OBS) and elastic optical networks (EON) offers a promising pathway for 6G IoT backhaul. However, existing solutions treat OBS and EON separately and rely on heuristic resource allocation that fails to meet stringent QoS demands. This paper proposes a fully AI-driven converged OBS/EON architecture integrating a hybrid switching fabric, a multi-agent deep reinforcement learning (DRL) orchestrator, and a federated learning (FL) plane for autonomous, QoS-aware resource provisioning. The control plane implements multi-agent Proximal Policy Optimization (PPO) for joint burst scheduling, routing, modulation selection, and spectrum allocation. The orchestration plane employs q-fair FL for privacy-preserving cross-domain traffic prediction. Mathematical formulations of the optimization problem with spectrum, GSNR, and delay constraints are provided, along with pseudo-algorithms. Simulations over a 14-node NSFNET topology demonstrate a 78% reduction in blocking probability, a 42% improvement in spectral efficiency, sub-millisecond URLLC delays, and a Jain’s fairness index of 0.92, while preserving data privacy. The framework builds upon SDN principles for seamless integration with optical transport infrastructures. Full article
Show Figures

Figure 1

26 pages, 9715 KB  
Article
Enhancing Vehicular Ad Hoc Networks Routing via SDN-Based Traffic Engineering with MPLS and Segment Routing
by Ronild Hako, Evjola Spaho and Andres Annuk
Network 2026, 6(3), 58; https://doi.org/10.3390/network6030058 - 1 Aug 2026
Viewed by 372
Abstract
Vehicular Ad Hoc Networks (VANETs) are essential components of Intelligent Transportation Systems (ITS), allowing communication exchanges between vehicles and road infrastructure elements. These networks face challenges from vehicular mobility, including frequent topology changes, link instability, and variable wireless channel quality. This paper presents [...] Read more.
Vehicular Ad Hoc Networks (VANETs) are essential components of Intelligent Transportation Systems (ITS), allowing communication exchanges between vehicles and road infrastructure elements. These networks face challenges from vehicular mobility, including frequent topology changes, link instability, and variable wireless channel quality. This paper presents an extensive evaluation of Software-Defined Networking (SDN) integrated with two traffic engineering technologies, Multi-Protocol Label Switching (MPLS) and Segment Routing (SR), applied to the AODV and OLSR routing protocols. Nine incremental configurations are evaluated for each protocol, ranging from the default protocol through MPLS-enhanced forwarding, SDN-based centralized optimization, combined SDN-MPLS and SDN-SR integration, to advanced configurations using distance-based IS-IS weighted topology metrics with both Fixed and Adaptive metric computation approaches. Two distinct SDN topology construction methods are compared: a Protocol-based approach that uses routing table entries with equal hop-count metrics, and a distance-based approach using IS-IS weighted metrics. The simulation uses a realistic urban topology with 50 vehicles and 5 RSUs, evaluated across several traffic patterns, representing different application types. Results demonstrate that SR with distance-based IS-IS metrics achieves the highest Packet Delivery Ratio (PDR) and lowest delay by leveraging RSU infrastructure as reliable forwarding relays. Moreover, the proposed SDN-SR framework reduces routing overhead and control-plane signaling, improving network resource utilization and thereby indicating its potential to enhance the energy efficiency of vehicular communication infrastructures. Full article
(This article belongs to the Special Issue Emerging Trends and Applications in Vehicular Ad Hoc Networks)
Show Figures

Figure 1

43 pages, 16241 KB  
Article
ICT Infrastructure for Sustainable Mobility: The Lessons Learned from the MOST Spoke 5 Project
by Salvatore Dello Iacono, Chiara Franzoni, Paolo Bellagente, Alessandra Flammini and Emiliano Sisinni
Network 2026, 6(3), 57; https://doi.org/10.3390/network6030057 - 22 Jul 2026
Viewed by 667
Abstract
Smart and sustainable mobility increasingly relies on distributed sensing, low-power communication technologies, and cloud-based ICT platforms. This article presents a comprehensive scientific analysis of the technological foundations of sensitized mobility, reviewing the state of the art in embedded sensing, distributed systems, and communication [...] Read more.
Smart and sustainable mobility increasingly relies on distributed sensing, low-power communication technologies, and cloud-based ICT platforms. This article presents a comprehensive scientific analysis of the technological foundations of sensitized mobility, reviewing the state of the art in embedded sensing, distributed systems, and communication paradigms for future mobility challenges. The research project “MOST” and in particular its subgroup “Spoke 5” falls within this framework of sustainable and sensorized mobility, with numerous activities in data collection, analysis, and field experimentation. In order to allow data collection, retention and analysis, one of the challenges that we must address is the definition of an adequate ICT architecture. The core contribution of this work is the presentation of the MOST ICT architecture, designed as a containerized, scalable, and resilient infrastructure capable of integrating heterogeneous data coming from field-deployed systems. In addition, it discusses the primary research challenges encountered in the definition and development of the presented architecture by examining two representative case studies within the MOST-Spoke 5 research project: renewable energy charging stations for light electric vehicles and cyclists monitoring systems. Full article
Show Figures

Graphical abstract

23 pages, 2614 KB  
Article
A Requirement-Driven Expert System for Blockchain Consensus Mechanism Selection
by Ivica Lukić, Nikola Ramčić, Ivan Ivković and Miljenko Švarcmajer
Network 2026, 6(3), 56; https://doi.org/10.3390/network6030056 - 22 Jul 2026
Viewed by 285
Abstract
Blockchain technology has introduced a rapidly expanding range of consensus mechanisms, each designed to satisfy different operational requirements related to security, scalability, decentralization, transaction throughput, and energy efficiency. Selecting an appropriate consensus mechanism has consequently become a complex multi-criteria decision problem, particularly for [...] Read more.
Blockchain technology has introduced a rapidly expanding range of consensus mechanisms, each designed to satisfy different operational requirements related to security, scalability, decentralization, transaction throughput, and energy efficiency. Selecting an appropriate consensus mechanism has consequently become a complex multi-criteria decision problem, particularly for developers and organizations without extensive expertise in distributed systems and blockchain architectures. Existing tools primarily address protocol benchmarking and static documentation, leaving the decision-support dimension largely unaddressed. This paper presents a web-based expert system designed to support the selection of blockchain consensus mechanisms according to specific user-defined operational requirements. The proposed solution was implemented using the MERN technology stack, consisting of MongoDB, Express.js, React, and Node.js, enabling a modular and scalable architecture suitable for future expansion and maintenance. The recommendation process is based on a two-phase filtering and scoring algorithm. In the first phase, mechanisms incompatible with mandatory user-defined constraints, including network type and key resource type, are systematically eliminated. In the second phase, the remaining mechanisms are ranked using attribute matching across criteria encompassing energy efficiency, scalability, security, decentralization, and transaction speed. The system returns the three most suitable consensus mechanisms for the given operational scenario together with their key characteristics. In addition to recommendation functionality, the application supports user authentication, recommendation history management, and administrative maintenance of the consensus mechanism database, which currently contains 38 distinct blockchain consensus protocols. Experimental evaluation through twelve representative usage scenarios demonstrated that the system consistently produces contextually relevant recommendations aligned with user-specified requirements. A comparative analysis with existing tools confirms that the proposed system occupies a distinct decision-support role currently absent from the available tooling landscape. A comparative analysis against four representative existing tools indicates that the proposed system combines a set of decision-support capabilities not jointly offered by any one of them. The presented approach contributes a transparent and extensible decision-support framework intended to simplify architectural planning and management of blockchain-based distributed systems. Full article
Show Figures

Figure 1

23 pages, 348 KB  
Article
A Dual-Model Framework for Detecting IPv4 Fragmentation-Consistent Traffic Patterns in Flow-Level Datasets
by Maksim Iavich and Vladimer Svanadze
Network 2026, 6(3), 55; https://doi.org/10.3390/network6030055 - 16 Jul 2026
Viewed by 902
Abstract
IPv4 fragmentation attacks, including tiny fragment injection, teardrop offset manipulation, and fragment flooding exploit the RFC 791 reassembly process to evade firewalls and network intrusion detection systems (NIDSs). Detection is challenging because widely used flow-level datasets (UNSW-NB15, CIC-IDS2017), lack the packet-level fragment header [...] Read more.
IPv4 fragmentation attacks, including tiny fragment injection, teardrop offset manipulation, and fragment flooding exploit the RFC 791 reassembly process to evade firewalls and network intrusion detection systems (NIDSs). Detection is challenging because widely used flow-level datasets (UNSW-NB15, CIC-IDS2017), lack the packet-level fragment header information required for direct RFC 791 validation. This study investigates whether fragmentation-related traffic can be identified using only flow-level statistical features. The proposed framework introduces four contributions: (1) a direction-corrected proxy labeling scheme, where flows are labeled as fragmented when CVL < 0.70, validated on a controlled 3000-flow Scapy dataset with F1 = 0.873 and ROC-AUC = 0.895 against verified packet-level ground truth; (2) a dual-model Random Forest architecture with feature separation to prevent circular self-prediction; (3) RFC 791-inspired statistical heuristics applied as a post-inference filter; and (4) a six-configuration ablation study with a reproducible protocol. The study distinguishes fragmentation-like statistical signatures from confirmed packet-level fragmentation. The benchmark model Mfrag achieves F1 ≈ 0.998 on synthetic data, while external PCAP validation yields F1 = 0.873. Unlike most flow-level NIDS research, the framework is validated against both controlled Scapy-generated traffic and the MAWI real-world backbone trace, establishing a practical performance bound (F1 = 0.82 for the full hybrid framework). The attack classification model Mattack achieves F1 = 0.974 on dataset-provided labels. Results show that flow-level analysis can provide useful indicators of fragmentation-related activity when packet-level evidence is unavailable, while highlighting the limitations of statistical detection. Full article
20 pages, 763 KB  
Article
Key Value Indicators for Sustainable AI-Based Communication Networks: Are They Adequate?
by Lucia Pintor, Marco Garau, Virginia Pilloni and Luigi Atzori
Network 2026, 6(3), 54; https://doi.org/10.3390/network6030054 - 16 Jul 2026
Viewed by 249
Abstract
As climate and societal challenges intensify, achieving sustainable development requires a holistic approach that balances economic growth with environmental preservation and social equity. The United Nations’ 2030 Agenda outlines 17 Sustainable Development Goals with corresponding global indicators. However, adapting these high-level goals to [...] Read more.
As climate and societal challenges intensify, achieving sustainable development requires a holistic approach that balances economic growth with environmental preservation and social equity. The United Nations’ 2030 Agenda outlines 17 Sustainable Development Goals with corresponding global indicators. However, adapting these high-level goals to the specific context of telecommunications networks, which are more and more governed by AI-based components, presents major challenges. This paper proposes an extensive framework for assessing the adequacy of Key Value Indicators, used to evaluate the Key Values brought by network services and applications. The framework encompasses the phases of indicator elicitation, analysis, technical realization, and assessment. Applying this framework ensures that Key Value Indicators remain relevant, actionable, and pertinent to the objectives throughout the system’s evolution. Case studies from leading projects in the telecommunications sector illustrate how the proposed methodology effectively identifies deficiencies and helps refine the framework. Full article
Show Figures

Figure 1

17 pages, 5000 KB  
Article
Machine Learning Framework for Detecting False Alerts in Safety Messages
by Avinash Karhana, Ikjot Saini and Arunita Jaekel
Network 2026, 6(3), 53; https://doi.org/10.3390/network6030053 - 14 Jul 2026
Viewed by 308
Abstract
The recent advances in Vehicular Ad Hoc Networks (VANETs) can have a tremendous positive impact on vehicle safety and traffic flow. In VANETs, vehicles communicate wirelessly with each other and with roadside infrastructure nodes to improve awareness of neighboring vehicles and traffic conditions. [...] Read more.
The recent advances in Vehicular Ad Hoc Networks (VANETs) can have a tremendous positive impact on vehicle safety and traffic flow. In VANETs, vehicles communicate wirelessly with each other and with roadside infrastructure nodes to improve awareness of neighboring vehicles and traffic conditions. However, such communication also increases the potential for various safety and security challenges, such as the threat of false reporting attacks. In these attacks, malicious or compromised nodes inject alert notifications that report fictitious traffic incidents that may trigger unnecessary evasive actions and increase the risk of collisions. This research addresses false alert attacks in VANETs by developing a machine learning-based detection framework that leverages innovative feature engineering and model assessment strategies. The proposed framework designs new features that capture vehicle kinematics to improve the detection of malicious alerts. The performance of multiple ML models is then analyzed in terms of both detection effectiveness and computational requirements to determine their suitability for different deployment scenarios. Our simulation results demonstrate that the proposed framework can achieve significant improvements compared to existing techniques for false alert detection. In addition, the study highlights the critical role of feature engineering in improving detection performance. Full article
Show Figures

Figure 1

25 pages, 1772 KB  
Article
Performance Analysis of Sigmoid-Enhanced OSPF for Risk-Aware Adaptive Routing in Secure Networks
by Chakadkit Thaenchaikun and Komsan Kanjanasit
Network 2026, 6(3), 52; https://doi.org/10.3390/network6030052 - 10 Jul 2026
Viewed by 431
Abstract
Modern communication networks require routing protocols that can adapt to dynamic traffic conditions while accounting for topology-based structural risk. Conventional open shortest path first (OSPF) relies on static or linear link cost metrics, which are often inadequate for capturing the nonlinear behavior of [...] Read more.
Modern communication networks require routing protocols that can adapt to dynamic traffic conditions while accounting for topology-based structural risk. Conventional open shortest path first (OSPF) relies on static or linear link cost metrics, which are often inadequate for capturing the nonlinear behavior of network dynamics and structural risk. This paper proposes sigmoid-enhanced OSPF (SE-OSPF), which integrates topology-based structural risk into the OSPF routing metric through a nonlinear sigmoid function. The proposed framework employs two configurable sigmoid parameters, the midpoint (x0) and the steepness (k), to provide smooth cost transitions and adaptive routing decisions under varying network conditions. Simulation results on a Barabási–Albert scale-free topology demonstrate that SE-OSPF reduces the average end-to-end delay by 19.7% and packet jitter by 8.6% compared with Standard OSPF. In addition, SE-OSPF increases the average number of successfully delivered packets by up to 16.6% compared with Linear-OSPF while reducing maximum link utilization (MLU), indicating more balanced traffic distribution, improved load balancing, and reduced congestion. These results demonstrate that the proposed sigmoid-based routing metric effectively balances routing efficiency, packet delivery reliability, and network load distribution, establishing SE-OSPF as an effective framework for topology-based structural risk-aware adaptive routing in modern communication networks. Full article
(This article belongs to the Special Issue Recent Advances in Network Security)
Show Figures

Figure 1

29 pages, 3468 KB  
Article
Adaptive Scheduling Optimization for Isogeny Mapping in SQIsign Based on Lightweight Learning to Rank
by Xinyi Zhuang, Shiyang He and Yuxin Zhang
Network 2026, 6(3), 51; https://doi.org/10.3390/network6030051 - 7 Jul 2026
Viewed by 373
Abstract
The post-quantum signature scheme SQIsign achieves extremely compact public keys and signatures, making it attractive for bandwidth-constrained environments. However, its signing efficiency is limited by the high random failure rate of the ideal-to-isogeny mapping procedure and the substantial cost of each retry. Existing [...] Read more.
The post-quantum signature scheme SQIsign achieves extremely compact public keys and signatures, making it attractive for bandwidth-constrained environments. However, its signing efficiency is limited by the high random failure rate of the ideal-to-isogeny mapping procedure and the substantial cost of each retry. Existing optimizations mainly reduce the number or cost of isogeny computations, while overlooking how to schedule commitment retries when multiple candidate ideals are available. We formulate commitment-stage scheduling as a lightweight learning-to-rank problem and provide an instrumented scheduling framework for SQIsign signing only. The pipeline uses two features, trains a weighted logistic regression scorer offline by maximum likelihood with class weighting, and deploys the same scorer online in Rank-ML mode. Live instrumentation on Apple M2 (n = 20,000 candidate attempts at NIST-I) quantifies the commitment bottleneck (86.4% failure; 7.36 mean attempts per session) and shows constant features at a fixed commitment degree (live AUC =0.50). Synthetic training supports the scorer when feature variance is present (test AUC 0.634). A remeasured four-way ablation with Batch-only control (n=100, seed 42) separates batch overhead from learned ordering: Rank-ML is indistinguishable from Batch-only at deployment, while Baseline remains fastest for its wall-clock signing time at batch size 10. These results clarify when lightweight ML scheduling applies in SQIsign and provide a reproducible evaluation template separating live, synthetic, remeasured, and proxy evidence. Full article
(This article belongs to the Special Issue Advances in AI-Powered Cybersecurity)
Show Figures

Figure 1

24 pages, 635 KB  
Article
Federated Learning over 5G/6G Networks: Dynamic Client Selection and Resource Allocation for Heterogeneous Edge Environments
by Ahmed Lateef Salih Al-Karawi and Rafet Akdeniz
Network 2026, 6(3), 50; https://doi.org/10.3390/network6030050 - 6 Jul 2026
Viewed by 486
Abstract
Federated learning (FL) has emerged as a promising paradigm for privacy-preserving edge intelligence because it enables geographically distributed devices to collaboratively train a shared model without transferring raw data to a central cloud. This capability is particularly valuable for 5G and emerging 6G [...] Read more.
Federated learning (FL) has emerged as a promising paradigm for privacy-preserving edge intelligence because it enables geographically distributed devices to collaboratively train a shared model without transferring raw data to a central cloud. This capability is particularly valuable for 5G and emerging 6G networks, where edge-native services are required to satisfy stringent latency, bandwidth, and privacy constraints while operating on highly heterogeneous devices and time-varying wireless channels. In practice, however, synchronous FL is often constrained by straggling clients with limited computation capability or unfavorable communication conditions, which increases round latency and reduces overall resource efficiency. To address this challenge, this study develops a rigorously structured framework for dynamic client selection and radio resource allocation in heterogeneous wireless edge environments. Each FL round is formulated as a latency-aware scheduling problem that jointly captures local computation time, uplink transmission time, minimum participation constraints, and resource block assignment. On this basis, we propose a Dynamic Client Selection and Resource Allocation (DCS-RA) method that integrates computation-aware, channel-aware, and fairness-aware scoring with greedy resource block allocation guided by marginal completion time reduction. The study further provides a clear methodological structure, workflow visualization, literature-grounded justification, dataset documentation, and uncertainty-aware result reporting. Under the reported simulation setting with 100 clients and 20 resource blocks, DCS-RA reduces the average round completion time from 1.92 s to 1.55 s on MNIST and from 2.02 s to 1.57 s on CIFAR-10, corresponding to improvements of 19.39% and 22.47%, respectively. Standard deviation reductions of 70.59% and 80.77% further indicate improved round-to-round stability and more reliable training behavior. These results support the central conclusion that lightweight joint scheduling can materially improve wall-clock FL efficiency in heterogeneous 5G/6G edge networks. Full article
(This article belongs to the Special Issue 5G and Next-Generation Communication Technologies)
Show Figures

Figure 1

16 pages, 510 KB  
Article
Reinforcement Learning for Resource Allocation in Energy-Harvesting Cooperative IoT Networks
by Olumide Alamu, Thomas O. Olwal and Munguakonkwa Emmanuel Migabo
Network 2026, 6(3), 49; https://doi.org/10.3390/network6030049 - 6 Jul 2026
Viewed by 463
Abstract
The internet of things (IoT) has rapidly evolved into a ubiquitous communication paradigm for enabling the deployment of autonomous wireless networks across diverse application domains. However, the limited energy storage capacity and computational resources of IoT devices (IoTDs) pose a serious concern to [...] Read more.
The internet of things (IoT) has rapidly evolved into a ubiquitous communication paradigm for enabling the deployment of autonomous wireless networks across diverse application domains. However, the limited energy storage capacity and computational resources of IoT devices (IoTDs) pose a serious concern to their long-term sustainability and the expected quality of service delivery. Moreover, in the foreseeable era of the internet of everything, centralised network resource management is likely to constrain network scalability. To tackle these challenges in the current and next-generation communication networks, the adoption of adaptive and lightweight computational frameworks coupled with energy-efficient transmission strategies is essential. To demonstrate this, we exploit the concept of cooperative communication and radio frequency-based energy-harvesting to improve the network throughput while maintaining power supply to the IoTDs. Furthermore, to intelligently and autonomously perform resource allocation, we employ the reinforcement learning frameworks, particularly state–action–reward–state–action (SARSA) and Q-learning. Based on key performance evaluation metrics, we compare our findings with the baseline methods, including the equal, random, and greedy power level selection schemes, with SARSA exhibiting the most favourable performance trade-offs. Full article
Show Figures

Figure 1

14 pages, 705 KB  
Article
ParallelEdge-AI: A Shared-Encoder Framework for Joint Traffic Classification and Latency-Aware Scheduling in Distributed IoT Edge Networks
by Abdulaziz G. Alanazi, Haifa A. Alanazi and Nasser S. Albalawi
Network 2026, 6(3), 48; https://doi.org/10.3390/network6030048 - 3 Jul 2026
Viewed by 280
Abstract
IoT networks now handle traffic from billions of devices, and edge nodes are under constant pressure to classify that traffic and dispatch tasks within tight latency deadlines. Most existing systems treat classification and scheduling as two separate steps that run one after the [...] Read more.
IoT networks now handle traffic from billions of devices, and edge nodes are under constant pressure to classify that traffic and dispatch tasks within tight latency deadlines. Most existing systems treat classification and scheduling as two separate steps that run one after the other. This sequence adds unnecessary delay and breaks the feedback between the two tasks: the scheduler never sees the traffic type, and the classifier never sees the queue state. We propose ParallelEdge-AI, a system built around a shared flow encoder that feeds two task-specific heads in parallel, one for multi-class traffic classification and one for task-urgency scoring. Both heads are trained end-to-end using a joint loss that combines cross-entropy and pairwise ranking. A load-balance controller then reads the urgency scores alongside live queue lengths to decide, every 200 ms, whether a task stays local or moves to a less-loaded edge node. No global synchronisation is needed. We test the system on three real IoT datasets: RT-IoT2022, N-BaIoT, and CICIoT2023. ParallelEdge-AI reaches 97.63% accuracy and an F1-score of 97.34%, which is 3.16 percentage points above the best baseline. Inference latency is 19.62 ms per batch, the deadline-miss rate is 2.34%, and the load-imbalance index is 0.083, all three are the best results in our comparison. These numbers show that running classification and scheduling together on a shared representation is both faster and more accurate than treating them as separate problems. Full article
Show Figures

Figure 1

23 pages, 3426 KB  
Systematic Review
A Systematic Mapping Study on Performance and Robustness Optimization of LoRaWAN Networks
by Övgüm Can Sezen, Claus Pahl and Florian Hofer
Network 2026, 6(3), 47; https://doi.org/10.3390/network6030047 - 3 Jul 2026
Viewed by 298
Abstract
Long-Range Wide-Area Networks (LoRaWANs) combine long-range and low-power communication, making them a key technology for Internet of Things (IoT) applications. This systematic mapping study provides a comprehensive analysis of research on LoRaWAN network technology, focusing on performance and robustness optimization published between 2015 [...] Read more.
Long-Range Wide-Area Networks (LoRaWANs) combine long-range and low-power communication, making them a key technology for Internet of Things (IoT) applications. This systematic mapping study provides a comprehensive analysis of research on LoRaWAN network technology, focusing on performance and robustness optimization published between 2015 and 2026. Through a rigorous screening of2746 papers, we identified and analyzed 209 papers that met strict inclusion criteria and addressed network-layer optimization mechanisms. The studies were retrieved from IEEE Xplore, ACM Digital Library, SpringerLink, and Scopus using a PICO-based search strategy, and synthesized descriptively without effect-size meta-analysis. Our analysis reveals a rapidly growing research field, with 53.1% of the 209 included studies were published in the recent period (2023–2026), predominantly simulation-based evaluation approaches (72.2%), and strong geographic concentration in Europe (38.8%) and Asia (35.4%). We identified that performance optimization is the primary focus (96.2% of papers), while robustness optimization remains significantly underfocused (27.3% of papers), representing a critical research gap. This study identifies and prioritizes five research gaps, including the need for real-world field studies, multi-objective optimization frameworks, and lightweight machine learning approaches for edge devices. This mapping study provides structured guidance for future research in LoRaWAN optimization and supports evidence-based decision-making in the field. Full article
Show Figures

Figure 1

Previous Issue
Back to TopTop