Cybersecurity and Resilience in IoT and Distributed Networks (Including AI‑Enabled Approaches)

A Special Issue of Future Internet (ISSN 1999-5903) belonging to the section "Cybersecurity".

Deadline for manuscript submissions: 31 March 2027 | Viewed by 1520

Editors


E-Mail Website
Guest Editor
Department of Computer Science, University of Lancashire, Lancashire PR1 2HE, UK
Interests: IoT security; privacy; blockchain-based cybersecurity solutions; wireless sensor networks; cryptography; risk analysis; digital forensics; cyber–physical energy systems

E-Mail Website
Guest Editor
Department of Computer Science, Faculty of Arts and Sciences, Edge Hill University, Ormskirk L39 4QP, UK
Interests: cyber security; IoT security; ethical hacking; network security; cyber attack and defence; artificial intelligence; block chain; cryptography and cryptanalysis
Special Issues, Collections and Topics in MDPI journals

E-Mail Website
Guest Editor
Department of Computer Science, Faculty of Arts and Science, Edge Hill University, Ormskirk L39 4QP, Lancashire, UK
Interests: image-based malware detection; IoT security; adversarial ML attacks; distributed systems; digital forensics; secure machine learning; randomized defences for adversarial robustness, post-quantum cryptography, machine and deep learning

Special Issue Information

Dear Colleagues,

The accelerating evolution of modern digital ecosystems including IoT networks, cyber physical systems, cloud and edge infrastructures, AI‑enabled services and next-generation communication technologies has significantly expanded the global cyber-threat landscape. While IoT deployments continue to grow across smart homes, healthcare, industrial automation, transportation and critical infrastructure, broader cybersecurity domains face increasingly sophisticated challenges such as advanced malware, large scale data breaches, AI‑driven attacks, ransomware campaigns and emerging quantum‑era risks.

As the future internet becomes more autonomous, distributed, interconnected and data‑intensive, the demand for scalable, intelligent and resilient security mechanisms has never been greater. Traditional defences are insufficient in the face of dynamic adversarial techniques, expanding attack surfaces and heterogeneous environments that combine resource‑constrained devices with complex cloud and network infrastructures.

This Special Issue invites high quality research contributions addressing both IoT‑specific security challenges and advanced cybersecurity topics more broadly. We seek innovative models, architectures, algorithms, frameworks, evaluations and surveys that advance the state of the art in protecting IoT ecosystems, next‑generation networks, digital infrastructures and intelligent cyber-defence systems. Submissions should focus on security, privacy, trust, resilience and emerging threats across diverse connected environments.

Topics of Interest

  • AI‑Driven Cybersecurity and Autonomous Threat Detection;
  • IoT and Cyber–Physical System Security;
  • Cloud, Edge and Fog Security Architectures;
  • Advanced Malware Analysis and Ransomware Defence;
  • Blockchain and Decentralized Security Mechanisms;
  • IoT‑Focused Lightweight and Post‑Quantum Cryptographic Solutions;
  • IoT‑Integrated Security for 5G/6G and Next‑Generation Networks;
  • Digital Forensics, Incident Response and Threat Intelligence;
  • Privacy‑Preserving Security Models and Data Protection;
  • Security Challenges in Autonomous and Virtualized Systems.

Dr. Waqar Asif
Dr. Muhammad Waqar
Dr. Husnain Rafiq
Guest Editors

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Future Internet is an international peer-reviewed open access monthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 1800 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • cybersecurity
  • IoT security
  • cyber–physical systems
  • AI‑driven threat detection
  • malware analysis
  • blockchain security
  • lightweight and post‑quantum cryptography
  • network security
  • digital forensics
  • privacy‑preserving technologies

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (3 papers)

Order results
Result details
Select all
Export citation of selected articles as:

Research

38 pages, 8131 KB  
Article
HFS-SVE: A Hybrid Feature Selection and Soft Voting Ensemble for Android Malware Detection
by Hany F. Atlam and Samyak M. Jeevane
Future Internet 2026, 18(9), 495; https://doi.org/10.3390/fi18090495 (registering DOI) - 20 Sep 2026
Abstract
Android malware continues to evolve in complexity, creating challenges for detection systems that must distinguish malicious applications from increasingly heterogeneous benign applications. Although machine learning provides effective mechanisms for learning malware characteristics, the high dimensionality of Android malware datasets can introduce redundant and [...] Read more.
Android malware continues to evolve in complexity, creating challenges for detection systems that must distinguish malicious applications from increasingly heterogeneous benign applications. Although machine learning provides effective mechanisms for learning malware characteristics, the high dimensionality of Android malware datasets can introduce redundant and weakly informative features and increase computational requirements. To address this problem, this paper proposes a Hybrid Feature Selection and Soft-Voting Ensemble (HFS-SVE) framework that integrates complementary feature-selection and ensemble-learning strategies. The proposed framework sequentially applies Random Forest (RF) feature importance, Chi-square-based SelectKBest, correlation filtering, and L1 regularisation, reducing the original 489-feature representation to 13 selected features. These features are subsequently classified using RF, XGBoost, and LightGBM, whose probability outputs are combined through soft voting. Experimental results on the KronoDroid dataset demonstrate that the proposed HFS-SVE achieves 99.41% accuracy, 99.52% precision, 99.30% recall, 99.40% F1-score, and 99.41% ROC-AUC. The proposed framework also records the lowest measured detection time among the evaluated feature-selection strategies. Cross-dataset evaluation on Malgenome, TUANDROMD, and Drebin achieves accuracy above 98% on each dataset. The findings demonstrate that the proposed HFS-SVE can combine substantial feature-space reduction with strong Android malware detection performance, while the cross-dataset results highlight the importance of dataset variation and feature provenance when assessing generalisation. Full article
Show Figures

Graphical abstract

23 pages, 2428 KB  
Article
Heterogeneous Conditional Counter-Inspection: Configurable Error Control and Weak-Filter Recovery for 5G Network Intrusion Detection
by Khaoula Tahori, Imade Fahd Eddine Fatani, Mohamed Moughit and Hicham Magri
Future Internet 2026, 18(7), 381; https://doi.org/10.3390/fi18070381 - 22 Jul 2026
Viewed by 441
Abstract
Intrusion detection systems for 5G networks are typically reported at a single operating point, obscuring the trade-off between missed attacks and false alarms that governs real deployments. Building on a lightweight conditional counter-inspection pipeline, in which a global classifier is selectively validated by [...] Read more.
Intrusion detection systems for 5G networks are typically reported at a single operating point, obscuring the trade-off between missed attacks and false alarms that governs real deployments. Building on a lightweight conditional counter-inspection pipeline, in which a global classifier is selectively validated by curriculum-biased experts under a unanimous dissent rule, we remove the constraint that all components share one learning algorithm, assigning decision trees, random forests, extremely randomized trees, and histogram-based gradient boosting independently to the global (G), malicious-biased (EM), and benign-biased (EB) roles. Across two datasets of contrasting difficulty, 5G-NIDD and UNSW-NB15, all 14 evaluated tree-based configurations reduce missed attacks, by 36.5–79.6% on 5G-NIDD, confirming that the recovery effect is a property of the architecture rather than of decision trees. The expert assignment also selects which error the system controls: the same pipeline can be steered toward fewer false alarms, fewer missed attacks, or higher aggregate F1 without retraining the first stage. The mechanism also rescues a weak linear filter: on 5G-NIDD it cuts false positives and false negatives by 92.8% and 95.8%, and on UNSW-NB15 it raises F1 from 0.903 to 0.934 while reducing missed attacks by 35.5%. These results reframe the pipeline as a configurable validation layer matched to a deployment’s cost structure. We further show, through direct measurement on both datasets, that the conditional routing evaluates at most four of seven models per record, keeping classifier inference below 0.1 ms per record and leaving the detection stage a small contributor to overall processing cost. Full article
Show Figures

Figure 1

26 pages, 793 KB  
Article
Imbalance-Aware Cross-Modal Focal Modulation for Cross-Dataset Audio-Visual Deepfake Detection
by Shahad Mohammad Bn Dokiey, Tariq M. Khan and Qazi Emad Ul Haq
Future Internet 2026, 18(7), 379; https://doi.org/10.3390/fi18070379 - 20 Jul 2026
Viewed by 514
Abstract
Audio-visual deepfake detection remains challenging under cross-dataset distribution shift, especially when the source-domain training data are severely imbalanced. Existing middle-fusion detectors often rely on softmax-based cross-attention, which can learn sharp source-domain token interactions and may transfer poorly to unseen datasets. This study proposes [...] Read more.
Audio-visual deepfake detection remains challenging under cross-dataset distribution shift, especially when the source-domain training data are severely imbalanced. Existing middle-fusion detectors often rely on softmax-based cross-attention, which can learn sharp source-domain token interactions and may transfer poorly to unseen datasets. This study proposes FocalNet, an audio-visual detector that replaces the cross-attention block of the 2D3MF framework with cross-modal focal modulation. The proposed module aggregates multi-scale temporal context before audio-visual interaction, enabling softmax-free contextual modulation between visual MARLIN features and audio EAT features. We evaluate the method under a strict FakeAVCeleb-to-DFDC protocol, where all training and validation is performed on FakeAVCeleb and the DFDC is used only as an unseen target-domain test set. Compared with the reproduced 2D3MF baseline, which collapses to a single-class prediction pattern on the DFDC, FocalNet achieves substantially stronger zero-shot score separation, with a DFDC ROC-AUC of 0.9324. Thresholded analysis further shows an improved balanced accuracy, macro F1 score, and MCC when the frozen source-domain operating point is applied. The model also preserves practical efficiency, requiring comparable FLOPs and lower per-sample inference time than the reproduced baseline. These findings suggest that cross-modal focal modulation is a promising alternative to attention-based middle fusion for audio-visual deepfake detection under dataset shifts, while broader validation across additional unseen datasets, multi-seed training, and deployment-oriented calibration remain important for future work. Full article
Show Figures

Graphical abstract

Back to TopTop