Sign in to use this feature.

Years

Between: -

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (3,696)

Search Parameters:
Journal = Future Internet

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
40 pages, 5151 KB  
Article
A Novel Density-Based Hybrid Multi-Hop PEGASIS Protocol with Adaptive Packet Transmission for Energy-Efficient Wireless Sensor Networks
by Alyaa Salim, Noor Saadallah, Sara Basheer, Neam Hussin, Salah Alabady and Muhamad Mashadani
Future Internet 2026, 18(10), 524; https://doi.org/10.3390/fi18100524 - 29 Sep 2026
Abstract
Energy imbalance and costly long-distance communication remain limitations of chain-based routing in energy-constrained wireless sensor networks. Energy imbalance is still a problem even though PEGASIS reduces transmission distance through chain-based data aggregation. Energy imbalance can be affected by repeated leader burden, expensive leader-to-sink [...] Read more.
Energy imbalance and costly long-distance communication remain limitations of chain-based routing in energy-constrained wireless sensor networks. Energy imbalance is still a problem even though PEGASIS reduces transmission distance through chain-based data aggregation. Energy imbalance can be affected by repeated leader burden, expensive leader-to-sink communication, fixed packet size, and limited adaptation to changes in node-energy distribution. This study proposes Density-Based Hybrid MultiHop PEGASIS, which integrates adaptive DBSCAN clustering localized nearest-neighbor chain construction, multi-criteria leader selection, adaptive packet sizing, conditional energy-aware relay transmission and periodic mobile-sink repositioning. The protocol was evaluated using a custom round-based MATLAB simulator with 300 homogeneous sensor nodes deployed over a 300 m × 300 m field. At (Eo = 0.5) J, the mean first node dies values were 208.13, 163.67, and 41.30 rounds for Density-Based Hybrid Multi- Hop PEGASIS, PEGASIS, and HEED, respectively; at (Eo = 1.0) J, the corresponding values were 400.63, 327.57, and 104.93 rounds. Density-Based Hybrid Multi-Hop PEGASIS did not differ significantly from PEGASIS, in the first node dies analysis. Differed significantly from HEED under both energy conditions. Energy and energy-distribution analyses further indicate slower energy depletion, improved routing-level energy management, and enhanced long-term network persistence across both evaluated initial-energy conditions in the controlled experiments. Full article
(This article belongs to the Special Issue Wireless Sensor Networks and Internet of Things—2nd Edition)
►▼ Show Figures

Figure 1

46 pages, 4623 KB  
Article
DANA: A Digital Agent for Network Data Acquisition in Network Digital Twin Context
by Mario Sanz-Rodrigo, Diego Rivera, José Ignacio Moreno, Manuel Álvarez-Campana and Carmen Sánchez-Zas
Future Internet 2026, 18(10), 523; https://doi.org/10.3390/fi18100523 - 29 Sep 2026
Abstract
Network Digital Twins (NDTs) require accurate, structured, and timely data from heterogeneous communication networks. However, many existing approaches assume that this information is already available and do not address the operational path needed to convert raw observations into deployable twin artifacts. This paper [...] Read more.
Network Digital Twins (NDTs) require accurate, structured, and timely data from heterogeneous communication networks. However, many existing approaches assume that this information is already available and do not address the operational path needed to convert raw observations into deployable twin artifacts. This paper presents DANA, a lifecycle-aware data acquisition and transformation system for dedicated network devices and general-purpose systems hosting virtualized or containerized functions. Its key technical contribution is a unified workflow that coordinates centralized and distributed acquisition through a common, state-aware normalization layer. Each observation is associated with source, temporal, scenario, and lifecycle metadata, enabling the system to preserve the structural baseline used to construct the twin while processing runtime monitoring information separately. The normalized representation is decoupled from deployment-specific descriptor generation, while data and control exchanges follow a publish/subscribe communication model. The system is evaluated in two complementary controlled laboratory scenarios. The centralized workflow demonstrates accurate topology reconstruction and high agreement in network reachability, whereas the distributed workflow validates the complete path from host-level acquisition and normalization to descriptor generation and twin instantiation. Complementary local microbenchmarks characterize MQTT transport, fixed-load resource use, and stop/recovery event propagation to a test consumer while preserving the structural baseline. These results support the feasibility of the proposed workflow in the studied environments; large-scale operation and full synchronization of deployed NDTs require further experimental validation. Full article
26 pages, 2493 KB  
Review
Machine Learning-Enabled Optimization for Next-Generation Wireless Networks: A Survey of Intelligent Resource Management in RIS-Assisted Systems
by Omar Abdullatif Jassim, Sameh Najeh and Ammar Bouallegue
Future Internet 2026, 18(10), 522; https://doi.org/10.3390/fi18100522 - 29 Sep 2026
Abstract
In recent years, reconfigurable intelligent surfaces (RISs) have been proposed as a promising disruptive technology for future wireless communication systems. RISs enable unprecedented dynamic and programmable control of the electromagnetic waves by integrating software-defined metasurfaces into wireless environments. When smartly configured with the [...] Read more.
In recent years, reconfigurable intelligent surfaces (RISs) have been proposed as a promising disruptive technology for future wireless communication systems. RISs enable unprecedented dynamic and programmable control of the electromagnetic waves by integrating software-defined metasurfaces into wireless environments. When smartly configured with the phase shifts of incident signals, RIS systems have the potential to improve spectral efficiency, energy efficiency, coverage, security, and other wireless metrics without the need for additional transmit power or active radio frequency chains. However, optimizing RIS-assisted wireless networks is highly nontrivial, due to the high-dimensional search space, cascaded channel model, coupled design of active and passive beamforming, etc. Machine learning (ML), and in particular deep reinforcement learning (DRL), has shown great promise in addressing these challenges by providing intelligent, adaptive, and real-time resource allocation and control. In this survey, we present a comprehensive overview of the state-of-the-art Machine Learning (ML) empowered RISs, from the fundamentals to the various ML paradigms, including supervised learning, unsupervised learning and the DRL framework. We then discuss in details ML-based solutions for channel estimation, beamforming design, power allocation, and resource management in RIS-aided multiple access systems. We further survey recent advances in ML for mobile edge computing, federated learning, unmanned aerial vehicles (UAVs), and physical layer security with RISs. Finally, we discuss several open challenges and future directions to spur future research on ML-empowered RISs, including scalability, hardware impairments, and integration with future 6G wireless networks. Critically, we provide a substantive technical treatment of Explainable AI (XAI) for RIS scenarios, detailing how SHAP value attribution, Grad-CAM saliency mapping over RIS element indices, and Transformer attention maps can be applied to interpret black-box DRL policies and CNN-based models used for continuous phase-shift and beamforming optimisation, enabling operators to understand, trust, and debug ML-driven RIS control decisions. Full article
►▼ Show Figures

Figure 1

18 pages, 3077 KB  
Article
Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model
by Mohamed Ali Fakri, Abdellah Najid, Rachid Ben Said and Nezha El Idrissi
Future Internet 2026, 18(10), 521; https://doi.org/10.3390/fi18100521 - 29 Sep 2026
Abstract
Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work [...] Read more.
Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget. Full article
(This article belongs to the Special Issue Anomaly and Intrusion Detection in Networks)
►▼ Show Figures

Figure 1

25 pages, 1778 KB  
Article
IoT Sensing for Green Buildings: An Assessment of Indoor Environmental Risk in Vulnerable Occupants
by Spyridon K. Chronopoulos, Evangelia I. Kosma, Vasilis Christofilakis and Konstantinos P. Peppas
Future Internet 2026, 18(10), 520; https://doi.org/10.3390/fi18100520 - 29 Sep 2026
Abstract
Green buildings not only operate as energy-efficient structures but are also enriched with various sensors and network-supported environments. These are capable of sustaining high indoor environmental quality. This paper presents a simplified deterministic simulation framework and an extended simulation scenario for assessing how [...] Read more.
Green buildings not only operate as energy-efficient structures but are also enriched with various sensors and network-supported environments. These are capable of sustaining high indoor environmental quality. This paper presents a simplified deterministic simulation framework and an extended simulation scenario for assessing how IoT-monitored green buildings may reduce indoor environmental risk for occupants with chronic health vulnerabilities. The model is motivated by previous work on green residences, housing conditions, and their relationship to physical and psychological health, where indoor air quality, ventilation, thermal comfort, humidity, noise, lighting, dust, chemical exposure, and smoke are treated as relevant housing-related factors. A baseline simulation with a virtual duration of 100 days was conducted using 100 code-generated participants distributed across two building categories: a bad climate house (BCH) and a green monitored house (GMH). Three chronic-condition profiles were taken into consideration: asthma, chronic obstructive pulmonary disease, and anxiety/stress. This prototype version of the developed Octave-compatible code allows the baseline behavior of the proposed risk model to be examined directly. The simulation protocol included nine indoor environmental indicators and a normalized risk score ranging from 0 to 100, with values classified as low, moderate, or high risk. An extended simulation was then introduced to examine a broader scenario. This extension added a normal house (NH) as an intermediate building category and expanded the health-condition set from three to five assigned profiles by including allergies and depression/low well-being. Controlled building-profile and health-profile deviations were also included, while allergies and depression/low well-being were parameterized with building-specific coefficients. This allowed the model to examine not only the separation between the two extreme cases but also the intermediate role of a partially controlled building scenario. The results showed a clear difference in risk response between the building categories. In the basic scenario, the BCH produced high final risk scores, whereas the GMH achieved low final risk scores. At the building level, the final mean risk was approximately 100.00 for the BCH and 9.37 for the GMH. In the extended simulation, the aggregated final mean risk was 99.08 for the BCH, 44.95 for the NH, and 9.02 for the GMH. These results show a clear building-level risk stratification, i.e., high risk for the adverse building case, moderate risk for the intermediate building case, and low risk for the green monitored building case. These findings should be interpreted as deterministic and extended simulation results under predefined normalized environmental profiles, not as direct clinical or field validation. The proposed code strategy is not intended as a clinical diagnostic tool, but as an oriented modeling approach for future IoT-based green building assessment, digital twin integration, and risk-aware environment management. Full article
►▼ Show Figures

Graphical abstract

20 pages, 8288 KB  
Article
DeepShield-IoT: A Hybrid AI and Lotka–Volterra Model for Efficient IoT Intrusion Detection Systems
by Mohamed Bachar, Azeddine Khiat and Kamal El Guemmat
Future Internet 2026, 18(10), 519; https://doi.org/10.3390/fi18100519 - 28 Sep 2026
Abstract
Internet of Things devices introduce significant security challenges caused by their heterogeneous and resource-constrained nature in many sectors, such as healthcare, industry, education, and agriculture. Intrusion detection systems (IDSs) serve a key role in identifying malicious activities in such environments; traditional approaches cannot [...] Read more.
Internet of Things devices introduce significant security challenges caused by their heterogeneous and resource-constrained nature in many sectors, such as healthcare, industry, education, and agriculture. Intrusion detection systems (IDSs) serve a key role in identifying malicious activities in such environments; traditional approaches cannot often capture dynamic interactions and temporal correlations in network traffic. In this research, we propose a novel hybrid IDS technique utilizing Long Short-Term Memory (LSTM) networks in conjunction with Lotka–Volterra (LV) dynamic modeling. The LSTM component is employed to learn temporal patterns and estimate system states from IoT traffic, while the LV model captures the dynamic interaction between normal and malicious behavior. We introduce a mathematically based decision mechanism on an anomaly score for effective classification. The model’s results on DataSense: CIC IIoT dataset 2025 achieve an accuracy of 99.85%, outperforming other models, and have a detection time of 47 ms and a reduced-complexity algorithm. These results highlight the effectiveness of combining artificial intelligence with dynamic system modeling for intrusion detection in IoT environments, providing a promising direction for future research in intelligent cybersecurity systems. Full article
(This article belongs to the Section Cybersecurity)
►▼ Show Figures

Graphical abstract

23 pages, 2045 KB  
Article
Secure Resource Allocation Against Honest-but-Curious Relays in Underlay CR-NOMA Networks: A Constraint-Aware Hybrid D3QN–TD3 Approach
by Jiayang Xiao, Chaofei Guo and Peng Zhang
Future Internet 2026, 18(10), 518; https://doi.org/10.3390/fi18100518 - 28 Sep 2026
Abstract
Underlay cognitive radio non-orthogonal multiple access (CR-NOMA) enables secondary spectrum reuse under primary-user quality-of-service (QoS) protection, and cooperative amplify-and-forward (AF) relaying extends coverage for edge secondary users. However, third-party relay-capable user equipment may behave as honest-but-curious AF relays that follow the prescribed forwarding [...] Read more.
Underlay cognitive radio non-orthogonal multiple access (CR-NOMA) enables secondary spectrum reuse under primary-user quality-of-service (QoS) protection, and cooperative amplify-and-forward (AF) relaying extends coverage for edge secondary users. However, third-party relay-capable user equipment may behave as honest-but-curious AF relays that follow the prescribed forwarding protocol while attempting to infer confidential secondary messages. To suppress relay-side eavesdropping, this paper proposes a destination-assisted jamming-based secure resource allocation framework in which the far secondary user transmits an artificial-noise sequence unavailable to the selected relay. A constraint-aware hybrid algorithm combining a dueling double deep Q-network (D3QN) with twin delayed deep deterministic policy gradient (TD3) is developed to jointly optimize relay selection and continuous power allocation under primary-user QoS, secondary-user QoS, successive interference cancellation (SIC) feasibility, and transmit-power constraints, where an adaptive decayed constraint-penalty mechanism balances secrecy enhancement and constraint satisfaction. On held-out test traces, the proposed controller achieves an effective secrecy sum rate of 0.8099±0.0219 bps/Hz with 90.68% mean full-constraint feasibility over five training seeds. This rate is 96.6% and 48.8% higher than those of standalone TD3 and deep deterministic policy gradient (DDPG), respectively, while the projected-dual and adapted D3QN–DDPG baselines attain comparable sample means. These results demonstrate the effectiveness of the proposed framework for constraint-aware secure resource allocation in dynamic relay-assisted underlay CR-NOMA networks. Full article
(This article belongs to the Special Issue Recent Advances in Security for Internet of Things)
►▼ Show Figures

Figure 1

22 pages, 531 KB  
Article
Selective Admission and Occupancy-Targeted Placement for Carbon-Aware Kubernetes Scheduling: A Measurement- Calibrated CERN Case Study
by Sebastián Andrés Uribe Ruiz, Laura Eve Sarah Llinares, Matteo Bunino and Ricardo Rocha
Future Internet 2026, 18(10), 517; https://doi.org/10.3390/fi18100517 - 28 Sep 2026
Abstract
Temporal carbon-aware scheduling can reduce electricity-related emissions, but deferring work to lower carbon-intensity intervals can concentrate demand and increase waiting. We present benefit-gated deferral (BGD), a selective admission policy for nonpreemptive batch jobs on shared clusters, evaluated using realistic high-energy physics workloads in [...] Read more.
Temporal carbon-aware scheduling can reduce electricity-related emissions, but deferring work to lower carbon-intensity intervals can concentrate demand and increase waiting. We present benefit-gated deferral (BGD), a selective admission policy for nonpreemptive batch jobs on shared clusters, evaluated using realistic high-energy physics workloads in a measurement-calibrated CERN case study. BGD requires relative and absolute estimated carbon gains and ranks eligible starts by estimated grams avoided per hour waited. Arrival patterns extracted from CERN’s Next Generation Triggers platform define the primary scenario. Measurements of CMS simulation and reconstruction, ATLAS event generation, and LHCb simulation calibrate occupancy-dependent power and runtime. A 100-worker simulation compares BGD with immediate admission under simulated default Kubernetes and occupancy-targeted placement over a 90-day French carbon-intensity series. Synthetic arrivals provide a controlled sensitivity benchmark. With 24 h flexibility, the simulations yield accounted-emissions reductions of 17.40% and 7.98% under default placement at 30% and 50% offered load. Adding occupancy-targeted placement increases these reductions to 28.34% and 12.17%, while 95th-percentile waits exceed 20 h. Completion flexibility and occupancy-dependent execution affect the benefit of deferral, which must be assessed alongside waiting times and deadline compliance. Full article
(This article belongs to the Special Issue Cloud Computing and Cloud Service Orchestration)
►▼ Show Figures

Figure 1

5 pages, 153 KB  
Editorial
Distributed Machine Learning and Federated Edge Computing for IoT
by Demetris Trihinas and Alexandros Karakasidis
Future Internet 2026, 18(10), 516; https://doi.org/10.3390/fi18100516 - 28 Sep 2026
Abstract
The growing scale and heterogeneity of Internet of Things (IoT) environments are shifting machine learning (ML) from centralized cloud infrastructures toward distributed intelligence across the IoT–edge–cloud continuum [...] Full article
(This article belongs to the Special Issue Distributed Machine Learning and Federated Edge Computing for IoT)
20 pages, 880 KB  
Article
SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks
by Cen Chen, Tianyi Wang, Jinghong Lan, Yunpeng Li, Nuannuan Li, Yujian Zhang, Junfei Cai and Qi Wang
Future Internet 2026, 18(10), 515; https://doi.org/10.3390/fi18100515 - 28 Sep 2026
Abstract
Software-Defined Perimeter (SDP) hides protected services until communicating entities have been authenticated and authorized. In operational SDP gateways, each successful Single Packet Authorization (SPA) request creates transient authorization state that must be enforced and subsequently revoked, potentially imposing substantial rule-management overhead under high-churn [...] Read more.
Software-Defined Perimeter (SDP) hides protected services until communicating entities have been authenticated and authorized. In operational SDP gateways, each successful Single Packet Authorization (SPA) request creates transient authorization state that must be enforced and subsequently revoked, potentially imposing substantial rule-management overhead under high-churn access workloads. This paper presents SDP-FW, a dynamic firewall architecture for managing transient authorization in SDP-based Zero Trust networks. SDP-FW uses Time-Based One-Time Password (TOTP)-based dynamic SPA port selection to reduce the persistence of the SPA entry point and a remove-after-connection strategy to promptly remove temporary firewall openings after connection establishment. It further separates authorization-state tracking, implemented with a scalable counting Bloom filter, from kernel-level packet enforcement through Netfilter hooks and connection tracking. We implement an SDP-FW prototype in the Linux kernel and evaluate its security properties, runtime performance, and storage cost. Comparisons with iptables, ipset, nftables, and eBPF further characterize its performance and storage behavior. Experimental results show that SDP-FW maintains efficient insertion, lookup, and removal as the number of transient authorization states increases, while the measured remove-after-connection mechanism substantially shortens the residual exposure window. Full article
(This article belongs to the Special Issue Security of Computer System and Network)
►▼ Show Figures

Figure 1

18 pages, 3335 KB  
Article
Comparative Analysis of CNN and Hybrid CNN-LSTM Models for PQD Classification with Explainability Insights
by Sreshtamol K Gurudas, Rahul Satheesh, Sreenu Sreekumar and Hassan Haes Alhelou
Future Internet 2026, 18(10), 514; https://doi.org/10.3390/fi18100514 - 28 Sep 2026
Abstract
Power Quality Disturbances (PQDs) must be accurately detected and classified to preserve stability, efficiency, and power reliability in modern power systems as nonlinear loads and renewable energy sources become more common. Despite the excellent classification accuracy of Deep Learning (DL) models, their computational [...] Read more.
Power Quality Disturbances (PQDs) must be accurately detected and classified to preserve stability, efficiency, and power reliability in modern power systems as nonlinear loads and renewable energy sources become more common. Despite the excellent classification accuracy of Deep Learning (DL) models, their computational complexity and implementation feasibility are often overlooked. This work uses time-frequency representations obtained from the Fourier Synchrosqueezing Transform (FSST) to assess several DL architectures for PQD classification. To assess performance and efficiency, the standalone Convolutional Neural Networks (CNNs) and CNN–recurrent models are analyzed. With DenseNet-based architectures achieving the best performance, the analyzed models exhibit high, closely spaced classification accuracies, typically ranging from 98% to 99.4%. The study underlines the importance of evaluating both computational performance and efficiency, which also shows that such slight accuracy gains often come at the expense of significantly greater computational complexity. In addition to classification accuracy, this study also highlights model explainability. Gradient-weighted Class Activation Mapping (Grad-CAM) is used to show discriminative regions in FSST representations, which sheds light on the DL models’ decision-making process. Full article
(This article belongs to the Special Issue Artificial Intelligence in Smart Grids)
►▼ Show Figures

Figure 1

27 pages, 7061 KB  
Article
Risk-Aware Hierarchical Meta-Reinforcement Learning with Quantile Regression LSTM Framework for Adaptive Task Prioritization and Congestion Avoidance Offloading in Fog–Cloud Systems
by Vivekananda Potti and M. Rajasekhara Babu
Future Internet 2026, 18(10), 513; https://doi.org/10.3390/fi18100513 - 28 Sep 2026
Abstract
Fog–cloud systems allow distributed and latency-sensitive IoT applications to share edge, fog, and cloud resources for efficient computation, storing and delivering services. Nonetheless, the current methods of task scheduling and resource allocation tend to be based on deterministic prediction, heuristic schedules, or response [...] Read more.
Fog–cloud systems allow distributed and latency-sensitive IoT applications to share edge, fog, and cloud resources for efficient computation, storing and delivering services. Nonetheless, the current methods of task scheduling and resource allocation tend to be based on deterministic prediction, heuristic schedules, or response optimization, restricting risk sensitivity and responsiveness to dynamic workloads. To address these issues, we propose a graph network with a reinforcement learning framework to avoid congestion and schedule tasks with a low makespan in fog–IoT systems. The work starts with real-time monitoring of queue states, delay, bandwidth, energy and deadline properties of upcoming IoT tasks. Quantile Regression Long Short-Term Memory (QR-LSTM) predicts a normal task flow and congestion based on the task queue. The congestion tasks are further scheduled using a Delay-Aware Influence Reinforced-Graph Neural Network (DAIR-GNN). Then, Topology-Sensitive Resource Influence Propagation is used to map and analyze the relationship between the task sender and receiver within a network. After that, Dual-Stage Risk-Aware Hierarchical Policy (DRHP) combines Proximal Policy Optimization (PPO) to select the kinds of sources, like fog or cloud, based on the topology. Similarly, Model-Agnostic Meta-Learning (MAML) with Soft Actor–Critic allocates the resources of each tasks within the selected server. Both RL models are trained using Few-Shot Adaptive Policy Transfer to make better predictions. Lastly, Confidence-Uncertainty Regulated Exploration (CURE) is used to compute the prediction score for task allocation improvement. The proposed framework achieves a variance ratio of 80.6%, latency is 0.626 s, and the success rate is 98% in the prediction of congestion, scheduling and allocation of resources. These results demonstrate the improved ability to ensure reliable and effective fog–cloud allocation in response to dynamically changing workloads. Full article
►▼ Show Figures

Figure 1

3 pages, 132 KB  
Editorial
Editor for the Special Issue on: Task Offloading and Resource Allocation for IoT in Next-Generation Networking
by Khoa Nguyen, Steve Drew, Qihao Li and Jinhua Guo
Future Internet 2026, 18(10), 512; https://doi.org/10.3390/fi18100512 - 27 Sep 2026
Abstract
The proliferation of the Internet of Things (IoT) has created a hyper-connected ecosystem where devices communicate, compute, and collaborate under stringent CPU capacity, memory, energy, and latency constraints [...] Full article
28 pages, 609 KB  
Article
Hybrid Content- and Session-Based Anomaly Detection for Web Server Logs
by Abdul Rehman, Mouhammad Nouman and Muhsin Hassanu
Future Internet 2026, 18(10), 511; https://doi.org/10.3390/fi18100511 - 26 Sep 2026
Abstract
Rule-based inspection of web server logs cannot detect attacks it has not already been told to look for, and most anomaly-detection studies validate their methods on a single dataset, which risks overstating how well a method generalises to new traffic. This paper presents [...] Read more.
Rule-based inspection of web server logs cannot detect attacks it has not already been told to look for, and most anomaly-detection studies validate their methods on a single dataset, which risks overstating how well a method generalises to new traffic. This paper presents a hybrid framework that fuses a content-based autoencoder, which scores individual HTTP requests, with a session-based variational LSTM autoencoder, which scores per-client request sequences. The framework is evaluated across eight datasets spanning three log formats, including the public CSIC 2010 HTTP dataset, under both within-dataset and cross-dataset threshold-transfer protocols. Correcting a session-construction fault that had mixed different clients’ requests into the same window raises the session branch’s AUC on CSIC 2010 from 0.63 to 0.98, evaluated on a held-out split disjoint from the requests the corrected model was trained on; the branch depends on genuine multi-request sessions and produces no score where the traffic does not contain them. Fusion under raw score averaging is not uniformly beneficial: on CSIC 2010, weighting fully toward the session branch outperforms every blended raw-average weight tested, though normalising each branch’s score against its own training-score distribution before averaging largely closes this gap. A threshold calibrated once on normal CSIC 2010 traffic and transferred unchanged to three attack-heavy datasets raises fused F1 six- to seven-fold over a threshold tuned separately on each dataset, because those datasets contain too much attack traffic for self-calibration to represent normal behaviour. The framework also achieves a lower false positive rate than a labelled Random Forest baseline, at comparable or better AUC than unsupervised baselines, and runs fast enough for near-real-time use. Taken together, these results show that session structure and threshold calibration can matter as much as model choice. Full article
(This article belongs to the Topic Addressing Security Issues Related to Modern Software)
►▼ Show Figures

Figure 1

41 pages, 1711 KB  
Article
CA-AFiD: A Context-Aware Adaptive Federated Intrusion Diagnosis for Heterogeneous IoT–Fog–Cloud Environments
by Ashutosh Shankhdhar, Vanitha Murugesan, Thenmozhi Elumalai, Samia Kouki, Sumendra Yogarayan and Prabu Kaliyaperumal
Future Internet 2026, 18(10), 510; https://doi.org/10.3390/fi18100510 - 26 Sep 2026
Abstract
The increasing heterogeneity of Internet of Things (IoT) environments makes intrusion diagnosis challenging because device behaviours, traffic patterns, and attack distributions can vary across deployment conditions, while data-locality requirements limit centralized access to network data. This study proposes CA-AFiD (Context-Aware Adaptive Federated Intrusion [...] Read more.
The increasing heterogeneity of Internet of Things (IoT) environments makes intrusion diagnosis challenging because device behaviours, traffic patterns, and attack distributions can vary across deployment conditions, while data-locality requirements limit centralized access to network data. This study proposes CA-AFiD (Context-Aware Adaptive Federated Intrusion Diagnosis), a framework designed to support adaptive and interpretable intrusion diagnosis across IoT–Fog–Cloud environments. CA-AFiD combines behaviour-aware representation learning using Transformer, BiLSTM, and attention mechanisms with a context-aware adaptive ensemble that adjusts learner contributions according to behavioural complexity, attack density, and device context. Federated learning is used to coordinate model updates across distributed Fog nodes without sharing raw traffic data, while attention-based interpretation, SHAP feature attribution, and ATT&CK-oriented contextualization provide explanatory information for diagnostic decisions. The framework was evaluated on the CIC-IoT-DIAD 2024 dataset across device-aware learning, imbalanced attack diagnosis, temporal sensitivity, federated learning, explainability, and operational-efficiency scenarios. Under the controlled homogeneous evaluation, the complete CA-AFiD framework achieved a 99.22% F1-score, while the heterogeneous evaluation achieved an overall 99.03% F1-score across the evaluated attack categories. Across the four evaluated minority attack categories, the average F1-score was 98.79%. Under federated learning, the global model achieved an average device-identification accuracy of 98.90% and an average anomaly-diagnosis F1-score of 98.90% across the participating Fog nodes, while ATT&CK mapping achieved 88–98% coverage. These results demonstrate the potential of CA-AFiD to provide adaptive, data-local, and interpretable intrusion diagnosis for heterogeneous IoT–Fog–Cloud environments. Full article
Back to TopTop