Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (585)

Search Parameters:
Keywords = Cyber-Physical Attack

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
31 pages, 2374 KB  
Article
STAG-GuardNet: UAV-Assisted Spatio-Temporal Attack Graph Learning for Secure IoT Communication in Smart EV Charging Networks
by Abdulrahman A. Alshdadi
Sensors 2026, 26(18), 5898; https://doi.org/10.3390/s26185898 (registering DOI) - 17 Sep 2026
Viewed by 178
Abstract
Smart electric vehicle (EV) charging infrastructures are evolving into large-scale cyber-physical Internet of Things (IoT) systems that depend on distributed communication, real-time sensing, and spatially coordinated charging operations. However, their interconnected communication architecture exposes charging stations, EV communication links, and network gateways to [...] Read more.
Smart electric vehicle (EV) charging infrastructures are evolving into large-scale cyber-physical Internet of Things (IoT) systems that depend on distributed communication, real-time sensing, and spatially coordinated charging operations. However, their interconnected communication architecture exposes charging stations, EV communication links, and network gateways to coordinated distributed denial-of-service (DDoS) attacks. Existing intrusion detection approaches primarily rely on localized or static traffic analysis and therefore have limited capability to capture spatially distributed and temporally evolving attack behavior. This study proposes the Spatio-Temporal Attack Graph Guard Network (STAG-GuardNet), an unmanned aerial vehicle (UAV)-assisted spatio-temporal attack graph learning framework for DDoS detection and security monitoring in smart EV charging networks. The framework integrates spatiotemporal signal conditioning, telemetry-adaptive graph aggregation, temporal dependency learning, attack-memory encoding, and adaptive risk-aware attention to model coordinated cyber-physical attack behavior. UAV-assisted telemetry provides complementary spatial and wireless information on communication instability, signal variation, neighboring congestion, and distributed attack-related behavior. A Hybrid Hawk–Manta Adaptive Optimizer (HHMAO) is employed to improve hyperparameter selection and convergence stability under imbalanced, heterogeneous, and nonstationary traffic conditions. The framework is evaluated using a smart-city EV charging cybersecurity dataset and three benchmark IoT intrusion detection datasets, namely TON_IoT, Edge-IIoTset, and X-IIoTID. Experimental results show that STAG-GuardNet achieves 97.7% accuracy, a 97.7% weighted F1-score, and a 98.4% area under the receiver operating characteristic curve (AUC) on the primary dataset. The framework also maintains stable performance under noisy telemetry, missing observations, heterogeneous traffic distributions, and charging-node outages. These findings demonstrate the potential of STAG-GuardNet for resilient and spatially informed security monitoring in UAV-assisted IoT-enabled EV charging infrastructures. Full article
(This article belongs to the Special Issue Emerging Trends in Cybersecurity for Wireless Communication and IoT)
Show Figures

Figure 1

37 pages, 4160 KB  
Review
AI-Enabled Hardware-in-the-Loop Validation for Automotive Cybersecurity: A Review of Cyber Threats, Testbeds, and Intelligent Detection
by Farshideh Kordi, Paul Fortier and Amine Miled
Sensors 2026, 26(18), 5840; https://doi.org/10.3390/s26185840 - 15 Sep 2026
Viewed by 326
Abstract
Cybersecurity has become one of the most critical challenges in the intelligent and connected vehicle ecosystem of today. As modern vehicles become increasingly connected and intelligent, the frequency and sophistication of cyberattacks targeting automotive systems continue to grow at an alarming rate. Ensuring [...] Read more.
Cybersecurity has become one of the most critical challenges in the intelligent and connected vehicle ecosystem of today. As modern vehicles become increasingly connected and intelligent, the frequency and sophistication of cyberattacks targeting automotive systems continue to grow at an alarming rate. Ensuring robust detection and prevention mechanisms has therefore become essential to safeguard driver safety and vehicle integrity. Rapid and accurate identification of cyberthreats is critical, as such attacks can disrupt vital Electronic Control Units (ECUs) and compromise functions such as braking, steering, or communication networks. This review provides a comprehensive analysis of the major categories of cyberattacks targeting modern vehicles, including physical, remote, in-network, firmware- and software-based, cloud- and connectivity-related, and sensor-level perception attacks. Contemporary vehicle architectures, connected-vehicle technologies, software-update mechanisms, and current automotive cybersecurity standards and regulations are also considered. Although traditional cybersecurity testing approaches offer valuable insight into software vulnerabilities, they fail to capture the full cyber–physical interactions that govern vehicle behavior under malicious conditions. In this review, we highlight the essential role of Hardware-in-the-Loop (HIL) and Vehicle-in-the-Loop (VIL) platforms as realistic and safe environments for evaluating the impact of cyberattacks on automotive control systems and for generating synchronized cyber–physical data under controlled attack scenarios. We further examine how artificial intelligence (AI) techniques contribute to detecting, mitigating, and countering these cyberthreats, including supervised and unsupervised intrusion detection, deep-learning-based temporal modeling, cyber–physical anomaly detection, and the emerging challenge of adversarial attacks against AI-based detectors. By synthesizing insights from automotive cybersecurity, HIL-/VIL-based validation, automotive cybersecurity datasets, and AI-driven intrusion detection, this paper establishes a foundation for developing and evaluating more resilient and secure connected and software-defined vehicle architectures. Full article
Show Figures

Figure 1

9 pages, 2252 KB  
Proceeding Paper
A Discrete Consensus Protocol with Algebraic-Connectivity-Based Fault Tolerance for Decentralized Multi-Agent Communication Networks
by Amina Mukasheva, Nurgul Karymsakova, Ainur Kassymova, Nurshat Utelyeva and Assem Nurgizat
Eng. Proc. 2026, 154(1), 78; https://doi.org/10.3390/engproc2026154078 - 11 Sep 2026
Viewed by 165
Abstract
Decentralized coordination of multi-agent communication networks underpins autonomous UAV swarms, sensor meshes, and cyber-physical systems that must operate without a single point of failure, yet quantitative design rules linking topology degradation to coordination collapse are still lacking. This paper aims to characterize the [...] Read more.
Decentralized coordination of multi-agent communication networks underpins autonomous UAV swarms, sensor meshes, and cyber-physical systems that must operate without a single point of failure, yet quantitative design rules linking topology degradation to coordination collapse are still lacking. This paper aims to characterize the fault tolerance of a discrete linear consensus protocol that drives mobile agents’ scalar states toward a common value over a time-varying communication graph. The convergence rate and fault tolerance budget of the protocol are explicitly tied to the algebraic connectivity λ2 of the graph Laplacian, and three failure regimes—random independent failures (M1), sequential staged failures (M2), and targeted attacks on the highest-degree hubs (M3)—are analyzed using a full-factorial Monte-Carlo experiment of 1620 runs implemented in Python with the Mesa framework and NetworkX. Critical failure thresholds φc are 0.42–0.51 for M1, 0.38–0.48 for M2, and 0.28–0.38 for M3; a Kruskal–Wallis test (p < 0.001) confirms the ordering φcM3<φcM2<φcM1, providing quantitative design rules for fault-tolerant consensus-driven networks. Full article
Show Figures

Figure 1

60 pages, 7942 KB  
Review
The Efficiency-Decentralization-Security Trilemma: A Co-Design Framework for Lightweight, Decentralized AI in Cyber-Physical Systems
by Montaser N. A. Ramadan and Hasan Saygin
AI 2026, 7(9), 358; https://doi.org/10.3390/ai7090358 - 10 Sep 2026
Viewed by 518
Abstract
Smart systems, the Industrial Internet of Things, and cyber-physical networks increasingly make decisions on the devices where data is generated, on nodes short of memory, compute, energy, and bandwidth, and exposed to real adversaries. Two research currents have grown to meet this: one [...] Read more.
Smart systems, the Industrial Internet of Things, and cyber-physical networks increasingly make decisions on the devices where data is generated, on nodes short of memory, compute, energy, and bandwidth, and exposed to real adversaries. Two research currents have grown to meet this: one makes artificial intelligence small and distributed (quantization, pruning, distillation, TinyML, federated and split learning), the other makes it safe (defenses against poisoning, backdoors, inversion, and evasion). This review argues that the two are entangled rather than parallel. Operators that shrink a model or scatter it across nodes also redraw its attack surface, each carrying a security dividend and a security liability, and because a node’s resources are finite and shared, model capacity and defense strength compete for one multi-dimensional budget. We formalize this as an efficiency-decentralization-security (EDS) design tension, explicitly a tension and not an impossibility, and show with published measurements that the coupling is non-monotonic. Around this thesis we build three artifacts, following an explicit design-science research process: an evidence-graded scoring matrix that separates each operator’s security dividend from its liability across seven axes and reports the direction of every effect separately from the confidence in the evidence behind it; a resource-aware threat model that judges attack and defense feasibility against a tiered device, gateway, network, and server budget with stated units; and a co-design framework whose decision workflow terminates in a defense-selection program and a verification step under adaptive attack. We work the framework through an industrial predictive-maintenance scenario with the resource arithmetic computed line by line, and evaluate it retrospectively against six published edge-AI systems. The result is a decision-support guide for building edge AI that is efficient, decentralized, and secure at once. Full article
Show Figures

Figure 1

23 pages, 3695 KB  
Article
AI-Enhanced Anomaly Detection in Water Treatment Plants
by Ahmad Ihsan Akmal Izram, Mohamed Hadi Habaebi and Mohammed Abdullah Salem Al-Hussaini
Electronics 2026, 15(18), 4102; https://doi.org/10.3390/electronics15184102 - 10 Sep 2026
Viewed by 160
Abstract
Industrial water treatment plants are increasingly dependent on cyber–physical systems (CPS) and automated control processes for their operational safety and efficiency. However, the embedding of digital control networks exposes these critical infrastructures to sophisticated cyber–physical attacks, including malicious tampering with chemical dosing units [...] Read more.
Industrial water treatment plants are increasingly dependent on cyber–physical systems (CPS) and automated control processes for their operational safety and efficiency. However, the embedding of digital control networks exposes these critical infrastructures to sophisticated cyber–physical attacks, including malicious tampering with chemical dosing units and physical actuators. This paper proposes a robust, AI-enhanced anomaly detection framework designed to identify multi-stage malicious activities in water treatment systems using real-world industrial datasets. The proposed system is developed and validated on the Secure Water Treatment (SWaT) dataset, which contains multivariate sensor and actuator time-series data collected from a fully operational physical testbed under both normal operations and targeted cyber–physical attacks. First, high-frequency sensor noise is filtered, and cross-channel measurement reliability is maximized using a Kalman filter-based sensor fusion module. Subsequently, the fused-state vector is analyzed using an unsupervised Isolation Forest algorithm optimized for high-dimensional boundary isolation. To eliminate false negatives caused by stealthy, low-amplitude data injections that bypass purely statistical models, a deterministic, rule-based verification layer derived from physical process control logic is integrated. By integrating a discrete linear Kalman filter with an unsupervised Isolation Forest and deterministic physical rules, the framework effectively suppresses high-frequency sensor noise, achieving a 67.8% reduction in root mean square error (RMSE), while maintaining high detection accuracy across complex industrial attack scenarios. Experimental results demonstrate that the proposed hybrid framework yields superior detection capability, achieving a Precision of ≈95%, a Recall of ≈93%, a scenario-level F1-score of 94.1% (alongside a sample-level F1-score of 21.5%) and an edge inference latency of 0.6 ms, effectively demonstrating its suitability for deployment within simulated real-time industrial edge computing environments. The findings further confirm that combining statistical machine learning, state-space sensor fusion, and invariant physical process logic provides a resilient defense paradigm for securing critical industrial infrastructure against modern cyber–physical threats. Full article
Show Figures

Figure 1

22 pages, 6647 KB  
Article
Data-Driven Detection of Stealthy IA Attacks in Industrial Cyber-Physical Systems via DGM Quantification
by Jingzhao Chen, Bin Liu and Zhiqun Jiang
Sensors 2026, 26(18), 5750; https://doi.org/10.3390/s26185750 - 10 Sep 2026
Viewed by 168
Abstract
Industrial cyber-physical systems face increasing security threats from sophisticated cyber attacks. Traditional anomaly detectors generally require exact system models and noise statistics, which are often unavailable in practical industrial environments. To address this, this paper proposes a data-driven security detection framework based on [...] Read more.
Industrial cyber-physical systems face increasing security threats from sophisticated cyber attacks. Traditional anomaly detectors generally require exact system models and noise statistics, which are often unavailable in practical industrial environments. To address this, this paper proposes a data-driven security detection framework based on the quantification of differences in generalized models (DGM). Utilizing only accessible operational data from the control layer, the method employs closed-loop subspace orthogonal projections to construct two detection variables: a static innovation sequence estimator and an extended dynamic Markov matrix estimator. The static estimator identifies fundamental model mismatches caused by standard denial-of-service and essential false data injection attacks. Meanwhile, the dynamic estimator successfully captures the structural distortions induced by advanced stealthy attacks that typically deceive Kullback–Leibler divergence detectors. The proposed methods were validated using a hardware-in-the-loop platform featuring a two degree-of-freedom robot and a DC servo motor. Experimental results confirm that the DGM framework effectively detects multiple types of stealthy integrity and availability (IA) attacks without relying on system parameters or degrading optimal control performance. Full article
(This article belongs to the Section Industrial Sensors)
Show Figures

Figure 1

26 pages, 436 KB  
Article
Threat Model for Hybrid Cloud–Edge Cyber–Physical Systems: Mapping STRIDE to MITRE ATT&CK for ICS
by Mieszko Cichoń, Andrzej Mycek and Paweł Pławiak
Electronics 2026, 15(18), 4097; https://doi.org/10.3390/electronics15184097 - 10 Sep 2026
Viewed by 257
Abstract
Hybrid cyber–physical systems (CPS) integrate cloud services used in enterprise environments with operational technology (OT), which controls physical processes. However, most threat models applied to such systems implicitly assume that an adversary necessarily causes any loss of process availability. This perspective is reflected [...] Read more.
Hybrid cyber–physical systems (CPS) integrate cloud services used in enterprise environments with operational technology (OT), which controls physical processes. However, most threat models applied to such systems implicitly assume that an adversary necessarily causes any loss of process availability. This perspective is reflected in both the STRIDE model and the MITRE ATT&CK for ICS knowledge base, which primarily focus on adversarial activities. As a result, they do not explicitly account for a scenario that is becoming increasingly relevant in hybrid architectures: the intentional shutdown of a physical process by the organization defending the system. The loss of availability resulting from the activation of protective mechanisms is not, in itself, a new problem. The concept of a spurious trip has been recognized in safety engineering for decades and is addressed in standards such as IEC 61511. Related dependencies are also considered within the STPA-Sec methodology. Therefore, the objective of this work is not to introduce a new type of threat, but rather to demonstrate that this phenomenon is not adequately represented in widely used threat-modeling taxonomies that are primarily attacker-centric. In addition, a specific trust boundary within the hybrid architecture at which this problem manifests itself is identified. This makes it possible to incorporate the phenomenon into the risk analysis of systems in which a compromise of the IT layer alone can ultimately lead to the shutdown of physical processes. The proposed threat model is based on trust-boundary analysis. The reference hybrid architecture was divided into seven trust boundaries, and each STRIDE category was subsequently mapped to the corresponding MITRE ATT&CK techniques for ICS, based on the trust boundary crossed by a given attack scenario. The resulting threat vectors were then ranked using the fundamental metrics defined in CVSS v4.0. The attack vector was derived from the trust boundary crossed by each scenario and, where applicable, was correlated with published CVE vulnerability assessments. The model was validated against four widely documented industrial cybersecurity incidents: Stuxnet, Triton, Industroyer, and Colonial Pipeline. Full article
Show Figures

Figure 1

49 pages, 4802 KB  
Review
Threats, Defences, and Governance in Cyber–Physical Systems Security: A Structured Review of the 2020–2026 Literature
by Petru Grigore Urs and Vlad Muresan
J. Cybersecur. Priv. 2026, 6(5), 158; https://doi.org/10.3390/jcp6050158 - 9 Sep 2026
Viewed by 305
Abstract
When a water treatment plant, power grid, or pipeline is compromised, the consequences extend beyond data loss: a manipulated sensor reading can trigger physical damage, and a disabled safety interlock can endanger lives. Cyber–physical systems (CPSs) sit at this intersection of digital control [...] Read more.
When a water treatment plant, power grid, or pipeline is compromised, the consequences extend beyond data loss: a manipulated sensor reading can trigger physical damage, and a disabled safety interlock can endanger lives. Cyber–physical systems (CPSs) sit at this intersection of digital control and physical process, yet existing security reviews treat threats and defences in separate silos, leaving practitioners without a clear picture of which defences fail against which attacks, and why. This paper fills that gap with a structured narrative review of 82 sources (70 from the primary window January 2020 to April 2026, plus 12 foundational pre-2020 works), organised through the CPS Defence-Gap Taxonomy (CPS-DGT)—a framework that classifies 14 attack mechanisms by architectural layer and physical impact, evaluates six defensive technology categories against documented failure modes, and maps five governance dimensions to the institutional conditions required for deployment. Across five intrusion detection system (IDS) studies that differ in dataset, attack selection, training regime and evaluation scope, reported F1 scores lie between 0.796 and 0.969 under each study’s own standard conditions; these values are not a controlled comparison and are reported descriptively. For the one architecture evaluated under adversarial evasion, F1 falls by 37.4 percentage points in absolute terms, a relative reduction of 38.6%. The defence-gap matrix identifies seven entries with insufficient coverage. Five of the 14 attack mechanisms are uncovered: A03, A09, A10, A11 and A14. Two further mechanisms, A01 and A12, have only partial defences. Adversarial evasion of learned detectors is reported separately as a transversal failure mode of one defensive category rather than as an attack mechanism. The uncovered mechanisms cluster at the cyber–physical boundary and in supply-chain channels. We conclude with five concrete research challenges, each with a direct path from the identified gap to a tractable research agenda. Full article
(This article belongs to the Section Security Engineering & Applications)
Show Figures

Figure 1

25 pages, 9873 KB  
Article
EviGuard: Machine-Verifiable Evidence Grounding for LLM-Based Industrial Incident Reasoning
by Haozhe Zhou, Hang Lei and Maolin Yang
Appl. Sci. 2026, 16(18), 8925; https://doi.org/10.3390/app16188925 - 8 Sep 2026
Viewed by 243
Abstract
Large language models (LLMs) can turn a flood of cross-layer industrial logs into a fluent incident narrative, but a narrative that cites only real, resolvable events can still be wrong in every relation that matters: the login came from a different workstation, the [...] Read more.
Large language models (LLMs) can turn a flood of cross-layer industrial logs into a fluent incident narrative, but a narrative that cites only real, resolvable events can still be wrong in every relation that matters: the login came from a different workstation, the write command occurred after the physical change it supposedly caused, the action fell inside a planned maintenance window, and the controller does not even actuate the affected process. A cited event is not necessarily supporting evidence. When such a narrative drives automated response, the error propagates into isolating the wrong controller or revoking a legitimate operator. We present EviGuard, a system that decides when an LLM’s understanding is trustworthy enough to act on. EviGuard stores auditable cross-layer evidence in a provenance graph, lets the LLM propose only hypotheses, compiles each hypothesis into atomic machine-checkable claims in an Incident Claim Language, and has an ensemble of deterministic verifiers label every claim supported, contradicted, or unknown against the graph—honoring interval time, event-time policy and credential versions, network reachability, and physical control dependencies. A response gate forbids any high-impact action whose critical preconditions are not all supported. On EviCPS-Bench (42 hardware-in-the-loop attack chains, 9600 claim-level labels, κ=0.87), EviGuard cuts the unsupported-claim rate from 12.6% to 1.7%, raises relation-edge F1 from 0.64 to 0.89, holds prompt-injection success to 0.4%, and executes zero unverified high-impact actions across 3200 response decisions, at a median end-to-end latency of 0.44 s. Full article
Show Figures

Figure 1

35 pages, 16668 KB  
Article
A Provenance-Driven Trust Framework with Physics-Consistent Validation for Secure Wireless Sensor Networks
by Eman Abouelkheir
Sensors 2026, 26(18), 5695; https://doi.org/10.3390/s26185695 - 8 Sep 2026
Viewed by 298
Abstract
Wireless sensor networks (WSNs) play a critical role in cyber-physical applications such as industrial monitoring, environmental sensing, and critical infrastructure management. In these environments, security mechanisms must not only detect malicious activities but also explain how compromised measurements propagate through sensing, aggregation, and [...] Read more.
Wireless sensor networks (WSNs) play a critical role in cyber-physical applications such as industrial monitoring, environmental sensing, and critical infrastructure management. In these environments, security mechanisms must not only detect malicious activities but also explain how compromised measurements propagate through sensing, aggregation, and decision processes while operating under stringent resource constraints. Existing approaches typically address intrusion detection, trust management, provenance analysis, or blockchain-based integrity independently, providing limited support for integrated and explainable security. This paper presents PhyProvTrust-WSN, a physics-aware framework that combines physics-consistency validation, dynamic provenance graphs, evidence-based trust propagation, multi-factor risk fusion, and selective evidence anchoring to improve the transparency and auditability of secure sensor data aggregation. The framework models sensing, forwarding, aggregation, validation, and response events as a bounded provenance directed acyclic graph (DAG), enabling causal tracing of suspicious activities while maintaining low memory and communication overhead. A weighted risk fusion mechanism integrates anomaly evidence, domain-consistency assessment, trust evolution, and inherited provenance risk to support explainable security decisions. Rather than continuously recording all events, only high-risk or decision-relevant evidence hashes are anchored to a permissioned audit layer, reducing storage and communication costs. To avoid overclaiming, the proposed framework is evaluated using a hybrid methodology that combines attack-labeled WSN datasets, real sensor measurements for physics-consistency validation, and simulation-based overhead analysis. The results demonstrate that the integrated framework provides strong detection capability while improving explainability, supporting root-cause analysis, and maintaining bounded communication and storage overhead suitable for resource-constrained WSN deployments. Full article
(This article belongs to the Special Issue Advances and Challenges in Sensor Security Systems)
Show Figures

Figure 1

20 pages, 1271 KB  
Article
Hybrid Watermarking and Adaptive Misinformation for Protection Against AI Model Extraction in Edge-Deployed Cyber-Physical Security
by Fatimah Azzahrah binti Razali, Mohamed Hadi Habaebi and Mohammed Abdullah Salem Al-Hussaini
Network 2026, 6(3), 73; https://doi.org/10.3390/network6030073 - 8 Sep 2026
Viewed by 145
Abstract
Artificial intelligence (AI) models are increasingly deployed in edge-deployed cyber-physical security systems for tasks encompassing monitoring, threat classification, and automated decision-making. While these models offer robust performance, their deployment through open or semi-open Machine Learning as a Service (MLaaS) interfaces exposes them to [...] Read more.
Artificial intelligence (AI) models are increasingly deployed in edge-deployed cyber-physical security systems for tasks encompassing monitoring, threat classification, and automated decision-making. While these models offer robust performance, their deployment through open or semi-open Machine Learning as a Service (MLaaS) interfaces exposes them to severe security threats, prominently model extraction attacks. In such attacks, an adversary systematically queries a target API to replicate the victim model’s behavior. This study proposes a novel hybrid defense framework combining Adaptive Misinformation (AM) and Trigger-Based Watermarking (WM) to protect AI models against black-box extraction. Utilizing a LeNet architecture, the victim model was trained on the MNIST dataset, while a simulated attack utilized 50,000 EMNIST samples to train a clone model. The framework employs Maximum Softmax Probability (MSP) for out-of-distribution (OOD) detection to identify suspicious queries and strategically inject misleading responses, alongside a fine-tuned embedded watermark for ownership verification. Experimental evaluations using 10-fold cross-validation reveal that the baseline extraction attack yielded a clone model accuracy of 96.32%. Upon implementing the AM + WM framework, clone model accuracy degraded significantly to 53.67%, while the victim model maintained an accuracy of 98.97%. Furthermore, the protected model achieved a 100% Trigger Match Rate (TMR), ensuring reliable intellectual property verification. The proposed framework provides a prototype validation for lightweight edge architectures to balance security, model utility, and ownership protection in cyber-physical deployments. Full article
Show Figures

Figure 1

38 pages, 19248 KB  
Systematic Review
Sustainability–Resilience Trade-Offs in Edge-Enabled Systems: A Comprehensive Survey
by Nithya Nedungadi and Sriram Sankaran
Future Internet 2026, 18(9), 472; https://doi.org/10.3390/fi18090472 - 8 Sep 2026
Viewed by 290
Abstract
Edge-enabled Internet of Things (IoT) systems are rapidly becoming the operational substrate of mission-critical infrastructure spanning industrial automation, smart healthcare, vehicular ecosystems, and cyber–physical environments. The distributed, resource-constrained, and physically exposed nature of these systems makes them persistent targets for a diverse and [...] Read more.
Edge-enabled Internet of Things (IoT) systems are rapidly becoming the operational substrate of mission-critical infrastructure spanning industrial automation, smart healthcare, vehicular ecosystems, and cyber–physical environments. The distributed, resource-constrained, and physically exposed nature of these systems makes them persistent targets for a diverse and evolving spectrum of cyber attacks. Critically, cyber attacks on edge-enabled IoT systems do not merely threaten data confidentiality; they simultaneously erode two interdependent operational objectives: sustainability, the ability of the system to maintain continuous, energy-efficient operation within its resource envelope and resilience, the ability to absorb adversarial disruptions, recover operational continuity, and adapt to prevent recurrence. The structural conflict between defending sustainability and maintaining resilience under active cyberattack conditions constitutes a research gap that prior surveys have not systematically addressed. This survey introduces a cyber attack-driven Sustainability–Resilience (S-R) framework that positions cyber threats as the primary stressor forcing a bilateral trade-off between operational efficiency and continuity in edge-enabled IoT systems. A five-layer, attack-centric taxonomy is developed spanning: network-layer attacks (DDoS, MitM, routing manipulation, jamming); device and firmware attacks (malware injection, firmware compromise, sensor spoofing); data and AI/ML attacks (adversarial inputs, data poisoning, model inversion); federated and Byzantine attacks (gradient poisoning, backdoor injection, free-riding); and advanced persistent threats (APT-class intrusions, ransomware, LLM prompt injection, zero-day exploitation). For each attack class, the survey systematically analyses the impact on sustainability and resilience objectives, the resulting S-R conflict, and the state-of-the-art defensive strategies. The framework is formalised as a maximin optimisation over the joint S-R objective surface, incorporating the adaptive, goal-directed nature of the adversary through a game-theoretic formulation. Cross-domain analysis spanning Industrial IoT, smart healthcare, Internet of Vehicles, UAV-assisted IoT, smart grids, and tactical edge networks establishes domain-specific S-R operating constraints under representative attack scenarios. The survey concludes with a structured characterisation of open research challenges and forward-looking directions, providing a prioritised research agenda for advancing simultaneously sustainable and adversarially resilient edge-enabled IoT ecosystems. Full article
(This article belongs to the Special Issue Security and Privacy Issues in the Internet of Cloud—2nd Edition)
Show Figures

Figure 1

26 pages, 601 KB  
Article
Distributed Fusion Filtering with Prediction Compensation for Multi-Sensor Systems Subject to DoS-Attack-Induced Packet Dropouts
by Fengtao Hu and Jing Ma
Sensors 2026, 26(17), 5633; https://doi.org/10.3390/s26175633 - 4 Sep 2026
Viewed by 245
Abstract
This paper investigates the distributed fusion estimation problem for multi-sensor cyber-physical systems (CPSs), where the communication channels from local estimators to the fusion center are subject to random packet dropouts. Packet dropouts induced by either network congestion or intermittent denial-of-service (DoS) attacks are [...] Read more.
This paper investigates the distributed fusion estimation problem for multi-sensor cyber-physical systems (CPSs), where the communication channels from local estimators to the fusion center are subject to random packet dropouts. Packet dropouts induced by either network congestion or intermittent denial-of-service (DoS) attacks are modeled as Bernoulli random variables. When a local estimate is lost, a prediction compensation strategy is adopted at the fusion center, where the missing data are replaced by their one-step predictors. By constructing an augmented state consisting of the original state, local prediction errors, and virtual measurements, the multi-sensor system is transformed into a stochastic system with random parameter matrices and one-step autocorrelated noises. Based on the transformed system, a distributed state fusion (DSF) filter is proposed via the innovation analysis method, whose filter gain depends on the successful-reception probabilities. The stability of the proposed DSF filter is analyzed, and a sufficient condition for the existence of a steady-state filter is obtained. The steady-state gain can be pre-computed offline, thereby reducing the online computational burden. Simulation results validate the effectiveness of the proposed algorithm. Full article
(This article belongs to the Section Intelligent Sensors)
Show Figures

Figure 1

26 pages, 5091 KB  
Article
Microcontroller-Based Multi-Sensor IoT Testbed for Cyberattack Simulation, Data Creation, and Intrusion Detection
by Khawlah Harasheh, Satinder Gill, Kendra Brinkley, Salah Garada, Dindin Aro Roque, Hayat MacHrouhi, Janera Manning-Kuzmanovski, Jesus Marin-Leal, Melissa Isabelle Arganda-Villapando and Sayed Ahmad Shah Sekandary
Electronics 2026, 15(17), 3986; https://doi.org/10.3390/electronics15173986 - 4 Sep 2026
Viewed by 422
Abstract
The Internet of Things (IoT) continues to expand rapidly, bringing with it a new set of security concerns. Many IoT devices are lightweight and limited in processing power, which makes them vulnerable when used in critical applications. Although there are several datasets available [...] Read more.
The Internet of Things (IoT) continues to expand rapidly, bringing with it a new set of security concerns. Many IoT devices are lightweight and limited in processing power, which makes them vulnerable when used in critical applications. Although there are several datasets available for network-level intrusion detection, very few provide practical guidance on how microcontrollers and physical sensors can be combined to recreate realistic attack scenarios in a way that supports reproducible research. In this work, we present a microcontroller-based testbed that integrates multiple sensors to capture, store, and analyze data under both normal operation and simulated cyberattacks. The testbed connects environmental, motion, and network sensors to model IoT systems that are exposed to common threats including Denial-of-Service (DoS), Distributed DoS (DDoS), and Slowloris attacks. The system enables direct sensor-to-microcontroller connections, real-time logging, and synchronized event monitoring, allowing for detailed analysis of how devices behave under attack. Environmental and physical sensor measurements are included to provide synchronized cyber-physical context and baseline operational information rather than demonstrated direct indicators of the investigated network attacks. Alongside the testbed, we share a dataset containing sensor readings, system metrics, and labeled attack events. This contribution provides a practical resource for researchers and educators interested in IoT security, machine-learning-based intrusion detection, and the development of countermeasures rooted in real-world data. By combining low-level hardware experimentation with higher-level security analysis, this work creates a foundation for advancing experimental approaches to cybersecurity in IoT environments. Full article
Show Figures

Figure 1

50 pages, 14774 KB  
Article
QKD-Secured Industrial Smart-Grid Cyber-Physical Systems: Simulation and Q-MambaKAN Detection of Adaptive Side-Channel Attacks
by Ayoub Alsarhan, Bashar S. Khassawneh, Laith Alzboon, Kholoud Alkayid, Mahmoud AlJamal, Eslam Al Maghayreh, Fiyad Ahmad Alenazi and Hussein Al-Ofeishat
Future Internet 2026, 18(9), 468; https://doi.org/10.3390/fi18090468 - 3 Sep 2026
Viewed by 341
Abstract
The increasing interconnection of smart-grid operational technology, industrial-edge services, and utility information systems creates a critical need for resilient and continuously monitored industrial cyber-physical communication. Although quantum key distribution (QKD) can strengthen session-key establishment for advanced metering infrastructure, distributed energy resources, substation automation, [...] Read more.
The increasing interconnection of smart-grid operational technology, industrial-edge services, and utility information systems creates a critical need for resilient and continuously monitored industrial cyber-physical communication. Although quantum key distribution (QKD) can strengthen session-key establishment for advanced metering infrastructure, distributed energy resources, substation automation, supervisory control, and utility-core services, practical QKD deployments remain vulnerable to implementation-level side-channel attacks that can compromise the cryptographic protection layer without directly targeting conventional network packets. This paper presents a QKD-secured industrial smart-grid cyber-physical system framework for simulating and detecting adaptive side-channel attacks. The proposed 36-node industrial communication architecture integrates AMI devices, DER controllers, PMU and substation automation components, industrial-edge gateways, QKD modules, key-management services, SCADA and utility-core servers, security-operation-center components, and adversarial access points. A 100,000-record cyber-quantum dataset is generated across 12 operating conditions comprising normal communication and 11 adaptive QKD side-channel attacks: detector blinding, time shift, wavelength switching, Trojan-horse probing, photon-number splitting, decoy-state spoofing, RNG bias, calibration manipulation, local-oscillator manipulation, synchronization spoofing, and combined adaptive quantum hacking. Each scenario introduces coupled primary and secondary perturbations across optical, detector, timing, synchronization, randomness, calibration, photon-statistical, leakage, key-generation, encryption, and industrial-network-performance features. To support intelligent industrial security monitoring, the proposed Quantum-aware Mamba–Kolmogorov–Arnold Network (Q-MambaKAN) organizes device, network, QKD, side-channel, encryption, and risk evidence into an ordered cyber-quantum representation processed through selective state-space learning, side-channel attention, nonlinear KAN mapping, adaptive fusion, and multi-task prediction heads. Results show that the QBER increases from 0.071 during normal operation to 0.426 under combined adaptive quantum hacking, while encryption success decreases from 98.1% to 0%. Q-MambaKAN achieves a 99.48% binary detection accuracy, a 99.70% binary F1-score, a 97.60% multiclass macro-F1, and a risk RMSE of 0.021. Full article
(This article belongs to the Special Issue Cyber-Physical Systems in Industrial Communication Systems)
Show Figures

Figure 1

Back to TopTop