Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (687)

Search Parameters:
Keywords = ID3 algorithm

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
37 pages, 10535 KB  
Article
Explainable Intrusion and Anomaly Detection for IoT Sensor Networks Using Hybrid Feature Selection and Deep Autoencoder Learning
by Usman Ahmed, Sadiq Muhammad and Jaeyoung Choi
Sensors 2026, 26(14), 4540; https://doi.org/10.3390/s26144540 - 17 Jul 2026
Viewed by 208
Abstract
Internet of Things (IoT) environments, which are distributed and resource-constrained, present unique security challenges, making it essential to develop robust and transparent intrusion detection system (IDS) solutions. This study presents a specialized system for IoT environments that combines hybrid feature selection methods with [...] Read more.
Internet of Things (IoT) environments, which are distributed and resource-constrained, present unique security challenges, making it essential to develop robust and transparent intrusion detection system (IDS) solutions. This study presents a specialized system for IoT environments that combines hybrid feature selection methods with anomaly detection algorithms and classification strategies, alongside explainability techniques, to enhance security measures and event transparency. The novelty of this work lies in combining several modern approaches: hybrid feature selection by combining Random Forest (RF) and SelectKBest to reduce computational overhead while preserving high accuracy of detection; the application of Deep Autoencoders (DAEs) for detecting anomalous traffic deviating from learned normal behavior, enabling detection of previously unseen attack patterns under controlled experimental conditions; feedforward neural networks (FNNs) are applied to classify anomalous data with high accuracy and reduced training time, and explainability tools such as Shapley Additive Explanations (SHAP) and Local Interpretable Model-Agnostic Explanations (LIME) are incorporated to provide insights into model decisions and improve trust. We utilize the CIC-IDS2017 and EIIoT datasets to evaluate their effectiveness in identifying critical cyber threats and subsequently classifying them. This proposed framework, HDATL-XAI (Hybrid Dimension-reduction Autoencoder and Traditional Learning with Explainable Artificial Intelligence), integrates advanced techniques to offer comprehensive protection while ensuring transparency, enhancing security and trustworthiness, and serving as an essential tool for protecting IoT networks. Full article
Show Figures

Figure 1

29 pages, 2411 KB  
Article
BlockFECS: A Blockchain-Based Proof-of-Concept System for Metadata-Driven Evidence Correlation in Digital Forensics
by Oshoke Samson Igonor, Muhammad Bilal Amin and Saurabh Garg
Forensic Sci. 2026, 6(3), 59; https://doi.org/10.3390/forensicsci6030059 - 6 Jul 2026
Viewed by 295
Abstract
Background/Objectives: The rapid expansion of digital evidence in modern investigations has created pressing challenges for maintaining integrity, traceability, chain of custody, and meaningful analysis across heterogeneous forensic artefacts. Conventional evidence management approaches often fall short in scalability, transparency, and the ability to correlate [...] Read more.
Background/Objectives: The rapid expansion of digital evidence in modern investigations has created pressing challenges for maintaining integrity, traceability, chain of custody, and meaningful analysis across heterogeneous forensic artefacts. Conventional evidence management approaches often fall short in scalability, transparency, and the ability to correlate diverse digital evidence. This study presents BlockFECS, a blockchain-based proof-of-concept system for metadata-driven evidence correlation in digital forensics. Methods: BlockFECS uses Hyperledger Fabric to support auditable and tamper-resistant evidence management while capturing structured forensic metadata, including timestamps, locations, device IDs, user IDs, and file hashes. An off-chain weighted correlation algorithm assigns similarity scores between evidence pairs and classifies relationships as Related, Supplementary, Duplicate, or Unrelated. The system was evaluated using a simulated smart city accident scenario and tested for correctness, transaction latency, throughput, scalability trends, and concurrency behaviour across four computing environments. Results: Within the controlled proof-of-concept dataset, the correlation algorithm achieved 1.00 precision and recall for clear Related and Duplicate evidence relationships and high precision (0.90) for Supplementary relationships, although recall in this category was lower due to incomplete or noisy metadata. Performance testing showed that Create, Transfer, and Delete operations completed with sub-second latency, while correlation throughput exceeded 60 comparisons per second across all tested environments. Conclusions: The findings demonstrate the feasibility of combining blockchain-backed evidence integrity with lightweight metadata-driven forensic intelligence. BlockFECS contributes a proof-of-concept model for automating metadata-based evidence analysis while preserving provenance integrity and auditability, highlighting a promising direction for trustworthy and intelligent digital forensic investigation support. Full article
(This article belongs to the Special Issue Feature Papers in Forensic Sciences)
Show Figures

Figure 1

30 pages, 3499 KB  
Article
Multi-Feature Fusion and Optimization for Micropterus salmoides Tracking and Body Length Monitoring in Complex Aquaculture Environments
by Ziyi Yin, Guanxu Li, Zhiyi Liu, Feng Liu, Mai Li and Chengguo Wang
Sensors 2026, 26(13), 4250; https://doi.org/10.3390/s26134250 - 4 Jul 2026
Viewed by 244
Abstract
To achieve non-contact and continuous monitoring of body length in Micropterus salmoides and overcome the stress damage and subjective error associated with traditional manual measurement, this paper proposes an improved YOLOv8-based multi-target tracking framework for intensive recirculating aquaculture systems. The system employs a [...] Read more.
To achieve non-contact and continuous monitoring of body length in Micropterus salmoides and overcome the stress damage and subjective error associated with traditional manual measurement, this paper proposes an improved YOLOv8-based multi-target tracking framework for intensive recirculating aquaculture systems. The system employs a geometric measurement framework based on monocular vision that achieves conversion from pixel coordinates to actual body length through camera calibration, water-surface refraction correction, and pose projection correction. Under a collaborative optimization framework integrating detection and tracking, the model incorporates multi-scale feature enhancement, lightweight re-identification (ReID), and a robust data association mechanism, which improves system stability under conditions of high fish density, variable illumination, and turbid water. A shallow feature fusion path is introduced to enhance small-target perception, and a MobileNetV3_ReID model is adopted to extract highly discriminative appearance features, which improves identity consistency while maintaining model compactness. In the data association stage, a hybrid cost matrix integrating IoU, cosine similarity, and motion consistency is constructed, and optimal matching is realized through the Hungarian algorithm. Dynamic threshold adjustment and an exponential moving-average feature-update strategy are introduced to effectively suppress identity switching. Experiments were conducted on an overhead video dataset of Micropterus salmoides collected at a recirculating aquaculture system facility. The results show that the proposed method achieves 82.7% mAP50 while maintaining a real-time throughput of 88 FPS, with MOTA reaching 76.9% and IDF1 reaching 81.5%—the latter representing an improvement of 3.2 percentage points over BoT-SORT and 5.3 percentage points over the YOLOv8 baseline tracker. The number of identity switches (IDSW) decreased from 89 in the baseline configuration to 39, a reduction of 56.2%. Crucially, these component-level improvements translate into a body length error (BLE) of 5.2 ± 1.8% (MAE = 1.35 cm, Pearson r = 0.972), representing a 38.8% improvement over the baseline BLE of 8.5% and satisfying the 5–10% tolerance required for aquaculture growth monitoring. Ablation analysis confirms that both detection enhancements (contributing −1.3% BLE) and tracking optimizations (contributing −2.0% BLE) are necessary to achieve this application-level accuracy. Full article
(This article belongs to the Section Smart Agriculture)
Show Figures

Figure 1

43 pages, 23377 KB  
Article
AHGA-SA: A Novel Adaptive Hybrid Framework for Feature Selection in IoT-Oriented Intrusion Detection with Explainable AI
by Saud Abdullah Alzughaibi, Iftikhar Ahmad and Madini Alassafi
Sensors 2026, 26(13), 4247; https://doi.org/10.3390/s26134247 - 4 Jul 2026
Viewed by 278
Abstract
The increasing connectivity of Internet of Things (IoT)-oriented environments has made them more vulnerable to cyberattacks, requiring intrusion-detection systems (IDSs) to ensure their secure and reliable operation. The feature selection (FS) process of an IDS affects its performance, as effective FS can enhance [...] Read more.
The increasing connectivity of Internet of Things (IoT)-oriented environments has made them more vulnerable to cyberattacks, requiring intrusion-detection systems (IDSs) to ensure their secure and reliable operation. The feature selection (FS) process of an IDS affects its performance, as effective FS can enhance detection accuracy and reduce the computational cost and model complexity. This paper presents Adaptive Hybrid Genetic Algorithm-Simulated Annealing (AHGA-SA) as an FS framework that integrates the global search ability of a genetic algorithm and the local exploitation ability of simulated annealing. AHGA-SA aims to find compact, informative feature subsets in high-dimensional intrusion-detection datasets at an acceptable computational cost while maintaining detection performance. The experimental results on three recent benchmarks demonstrate feature-space reduction, with classification accuracies of 99.04% on IoTID20 (using 12 features), 98.25% on WUSTL-EHMS (using seven features), and 99.18% on Edge-IIoTset (using nine features). The results also demonstrate reduced training and testing times, central processing unit usage, resident set size overhead, and subset size compared to the baseline. Furthermore, Shapley additive explanations, as an explainable artificial intelligence technique, are applied to explain the model’s predictions and to show the contribution of the selected features to the IDS decision-making process. Full article
Show Figures

Figure 1

22 pages, 10182 KB  
Article
Voltage Control of the Three-Phase Synchronous Generator Using the EMBSIN 121u Voltage Encoder
by Petru Livinti
Energies 2026, 19(13), 3141; https://doi.org/10.3390/en19133141 - 2 Jul 2026
Viewed by 216
Abstract
We carried out a study on adjusting the voltage at the output terminals of a three-phase synchronous generator using the voltage encoder EMBSIN 121u. The purpose of this study was to increase the quantity and quality of the electrical energy produced by the [...] Read more.
We carried out a study on adjusting the voltage at the output terminals of a three-phase synchronous generator using the voltage encoder EMBSIN 121u. The purpose of this study was to increase the quantity and quality of the electrical energy produced by the generator. This paper is innovative as the author generates three models in MATLAB-Simulink to study voltage adjustment in a three-phase synchronous generator with electromagnetic excitation in two distinct cases: case 1, running the three-phase synchronous generator with a variable load and constant frequency, and case 2, running this generator with a constant load and variable frequency. In the first case, the voltage is adjusted through an automatic voltage adjustment system equipped with a proportional integrative (PI) controller (model 1) or through a fuzzy logic (FL) controller (model 2). The voltage is adjusted in the second case through an automatic voltage adjustment system equipped with a PI controller (model 3). In the case of the automatic voltage adjustment system with a fuzzy logic controller, the electrical energy supplied by the three-phase synchronous generator will be higher than in the case of the automatic voltage adjustment system equipped with a PI controller (at the moment, t = 6 s: Sgen_PI=158.2 (VA) and Sgen_FL=230.7 (VA)). Moreover, to implement the adjustment algorithm of the three-phase synchronous generator voltage through the voltage encoder EMBSIN 121u, the author has created a program in the programming environment Arduino IDE. The results of this study could also be used for three-phase synchronous generators with electromagnetic excitation used to construct wind power stations. Full article
Show Figures

Figure 1

44 pages, 5352 KB  
Article
Publicly Auditable Zero-Trust Federated Learning for Privacy-Preserving Intrusion Detection in Implantable Medical Device Ecosystems
by Weam Husham Aljabbari, Sırma Yavuz and Hasan Hüseyin Balik
Appl. Sci. 2026, 16(13), 6584; https://doi.org/10.3390/app16136584 - 1 Jul 2026
Viewed by 284
Abstract
Implantable medical device (IMD) and Internet of Medical Things (IoMT) environments need intrusion detection systems that learn across distributed hospitals without centralizing sensitive data, while controlling admission, protecting shared model artifacts, filtering unreliable contributors, and supporting post-run auditability. However, many secure federated learning [...] Read more.
Implantable medical device (IMD) and Internet of Medical Things (IoMT) environments need intrusion detection systems that learn across distributed hospitals without centralizing sensitive data, while controlling admission, protecting shared model artifacts, filtering unreliable contributors, and supporting post-run auditability. However, many secure federated learning designs treat identity, privacy, robustness, and evidence verification as separate layers, leaving a gap between privacy-preserving execution and public accountability. This paper presents an implemented zero-trust hierarchical federated learning-based intrusion detection system (FL-IDS) framework for IMD/IoMT security analytics. Hospital clients train eXtreme Gradient Boosting (XGBoost) detectors; self-sovereign identity gates participation; contribution-level differential privacy (DP) perturbs exported booster leaf weights; country aggregators apply adaptive Krum-inspired selection; and the global server performs trust-weighted prediction-level fusion. The evidence layer binds artifacts using Module-Lattice-Based Digital Signature Algorithm signatures, canonical hashes, Merkle roots, decentralized publication, Ethereum Sepolia anchoring, and standalone auditor verification. The framework is evaluated on WUSTL-EHMS-2020, ECU-IoHT, and CICIoMT2024 under paired DP-disabled and DP-enabled modes. Under DP-enabled execution, CICIoMT2024 achieved an F1-score of 0.998789 and area under the receiver operating characteristic curve (AUROC) of 0.999814, ECU-IoHT achieved an AUROC of 0.999337, and WUSTL-EHMS-2020 remained DP-sensitive with an F1-score of 0.422880 and AUROC of 0.776685. All paired evidence runs passed standalone auditor verification, demonstrating that privacy-preserving learning and public accountability can be integrated within a single experimental FL-IDS pipeline. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
Show Figures

Figure 1

19 pages, 6228 KB  
Article
A Low-Latency Mobile Robot Target Following Method Based on Improved YOLO-World
by Yanlong Sun, Kai Miao, Mingxi Zhang, Rixing Zhu and Shougang Huang
Symmetry 2026, 18(7), 1117; https://doi.org/10.3390/sym18071117 - 30 Jun 2026
Viewed by 263
Abstract
This paper addresses the challenges of high latency and the lack of an effective recovery strategy in mobile robot target following tasks. In this paper, a low-latency mobile robot target tracking method based on the improved YOLO-World algorithm is proposed. The process primarily [...] Read more.
This paper addresses the challenges of high latency and the lack of an effective recovery strategy in mobile robot target following tasks. In this paper, a low-latency mobile robot target tracking method based on the improved YOLO-World algorithm is proposed. The process primarily consists of three parts: target detection, target tracking, and motion control. First, for target detection, we introduce a tailored lightweight backbone network, GSS, within the YOLO-World framework, which progressively expands the receptive field through cascaded convolutional operations and enhances cross-group feature interaction via a channel mixing mechanism, significantly improving model efficiency with minimal loss in detection accuracy. Additionally, depthwise separable convolution is applied to the detection head to reduce computational redundancy. Secondly, in the target tracking part, a lightweight target tracking algorithm based on improved BoT-SORT is adopted, and the tracking delay is effectively reduced by optimizing the ReID feature extraction backbone network. Then, the motion control part adopts an active search strategy based on visual servo control. When the tracked target is lost, the strategy utilizes a camera motion compensation-based tracker to predict the target motion state and controls the robot to actively search for the target accordingly. Subsequently, feature tracking is resumed through target re-recognition, thus re-establishing target following. Experiments on public datasets and real-world scenarios demonstrate that the proposed method achieves strong robustness and real-time performance. Full article
(This article belongs to the Section Computer)
Show Figures

Figure 1

21 pages, 3311 KB  
Article
A Hybrid CNN–LSTM Model for IoT Intrusion Detection: A Robustness Analysis Across Datasets
by Amir Muhammad Hafiz Othman, Mohd Faizal Ab Razak, Ahmad Firdaus, Hamid Tahaei and Mehdi Gheisari
Future Internet 2026, 18(7), 345; https://doi.org/10.3390/fi18070345 - 30 Jun 2026
Viewed by 349
Abstract
The rapid growth of Internet of Things (IoT) devices has led to security concerns due to increasing IoT attacks. Traditional intrusion detection systems (IDS) struggle to effectively detect attacks due to the evolving nature of threats and heterogeneous traffic patterns. Therefore, this study [...] Read more.
The rapid growth of Internet of Things (IoT) devices has led to security concerns due to increasing IoT attacks. Traditional intrusion detection systems (IDS) struggle to effectively detect attacks due to the evolving nature of threats and heterogeneous traffic patterns. Therefore, this study presents a structured and reproducible intrusion detection approach that integrates preprocessing and deep learning-based classification for binary detection in IoT networks. The datasets used are ToN_IoT and UNSW-NB15 datasets, which contain IoT network traffic data. This study deploys a meta-heuristic algorithm called Gray Wolf Optimizer (GWO) for feature selection. SMOTE is used for balancing the class sample, and MinMax and standard normalization for data scaling during preprocessing. A comparative analysis is performed across multiple deep learning models, including Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM), Multi-Layer Perceptron (MLP), Deep Neural Network (DNN), Convolutional Neural Network (CNN), and Recurrent Neural Network (RNN). Results show that the CNN–LSTM model demonstrates strong performance consistency across datasets, achieving 99.68% and 92.05% accuracy on ToN_IoT and UNSW-NB15, respectively. Threshold sensitivity analysis reveals key detection and false-positive trade-offs for edge IDS. Through extensive performance evaluation and sensitivity analysis, this study highlights the importance of combining preprocessing, model evaluation, and threshold analysis for reliable IoT intrusion detection. Full article
(This article belongs to the Special Issue Security and Privacy Issues in the Internet of Cloud—2nd Edition)
Show Figures

Figure 1

20 pages, 537 KB  
Article
A Distributed Island-Based Feature Selection Framework for IoT Intrusion Detection Systems
by Jamil Al-Sawwa and Aws A. Magableh
Big Data Cogn. Comput. 2026, 10(7), 208; https://doi.org/10.3390/bdcc10070208 - 27 Jun 2026
Viewed by 315
Abstract
The widespread deployment of Internet of Things (IoT) environments has led to an increasing number of cyberattacks, highlighting the need for efficient and accurate intrusion detection systems. Over the last few decades, Intrusion Detection Systems (IDSs) have been proposed to tackle this challenge. [...] Read more.
The widespread deployment of Internet of Things (IoT) environments has led to an increasing number of cyberattacks, highlighting the need for efficient and accurate intrusion detection systems. Over the last few decades, Intrusion Detection Systems (IDSs) have been proposed to tackle this challenge. However, IDSs face challenges when dealing with high-dimensional IoT data that include redundant or irrelevant features, which can lead to increased false positives and decreased detection performance. An optimization-based IDS framework is one of the solutions for reducing data dimensionality and improving detection accuracy. However, the serial implementation of this type of IDS suffers from high computational time as the volume of data and its dimensionality increase. In this paper, we propose a scalable distributed island-based feature selection IDS using Apache Spark (version 3.5.6), called DISFS-IDS. DISFS-IDS follows a two-level partitioning strategy—data and population—to distribute the workload across worker nodes in order to identify the most informative features while achieving high detection accuracy. Using binary and multiclass IoT datasets, the experimental results demonstrate that DISFS-IDS achieves statistically comparable detection performance to the serial SFOA-based IDS while selecting a smaller subset of features. Moreover, DISFS-IDS provides effective feature reduction and competitive or superior performance compared with Spark-based filter feature selection methods. In the scalability analysis, DISFS-IDS achieves significant speedup as the number of islands increases while maintaining high parallel efficiency. Full article
(This article belongs to the Section Big Data)
Show Figures

Figure 1

28 pages, 11154 KB  
Article
Topology-Independent SHAP-Based Explainable Intrusion Detection for ROS Networks
by Burak Ağgül and Kaan Arık
Electronics 2026, 15(12), 2707; https://doi.org/10.3390/electronics15122707 - 18 Jun 2026
Viewed by 369
Abstract
The Robot Operating System (ROS) is widely used in modern robotics, but its open architecture makes it vulnerable to numerous cyber threats. Although machine learning (ML)-based intrusion detection systems (IDSs) demonstrate strong classification performance on ROS-specific datasets, reliance on topology-dependent identifiers such as [...] Read more.
The Robot Operating System (ROS) is widely used in modern robotics, but its open architecture makes it vulnerable to numerous cyber threats. Although machine learning (ML)-based intrusion detection systems (IDSs) demonstrate strong classification performance on ROS-specific datasets, reliance on topology-dependent identifiers such as source and destination IP addresses, port numbers, and Flow IDs remains a critical limitation in current research. This reliance may encourage algorithms to exploit scenario-specific endpoint signatures instead of relying primarily on transferable behavioral patterns. Consequently, classification scores may be artificially inflated due to data leakage. This study addresses this issue by quantitatively measuring the impact of data leakage and introducing a topology-independent, explainable ROS framework that provides a more realistic, leakage-aware, and topology-independent evaluation framework. The evaluation involved testing the LightGBM, XGBoost, and CatBoost algorithms on ROSIDS23. Additionally, Random Forest and Gradient Boosting were included to verify the presence of data leakage. In our ablation study, models that included topology features achieved near-perfect Macro-F1 values of 0.999 to 1.000. In contrast, removing topology-dependent features reduced the Macro-F1 score to about 0.66. This finding shows that topology descriptors, rather than just transferable attack behaviors, can significantly influence the near-perfect scores seen with topology-preserving protocols. Even without topology data, ML models effectively captured temporal behavioral patterns and detected DoS attacks with nearly perfect performance, reaching F1 scores of 0.99 or higher. However, semantic attacks like Unauthorized Subscribe remained tough to classify, with F1 scores of 0.43 or lower. Additionally, SHapley Additive exPlanations (SHAP) analysis improves the interpretability of IDSs by identifying the main behavioral features that drive model decisions and suggesting feature-level directions for rule-based defense configurations in ROS environments. Full article
(This article belongs to the Special Issue AI in Network Security: Recent Advances and Prospects)
Show Figures

Figure 1

23 pages, 3704 KB  
Article
Optimization of BLE-Based Autonomous Identification Parameters for UAVs Under Collision Probability Constraints
by Jiale Yang, Yarong Wu, Guhao Zhao and Zhichong Zhou
Appl. Sci. 2026, 16(12), 5995; https://doi.org/10.3390/app16125995 - 13 Jun 2026
Viewed by 193
Abstract
The rapid proliferation of low-altitude unmanned aerial vehicle (UAV) applications has made autonomous identification technology critical for flight safety and collaborative operations. In this paper, we propose and systematically analyze an autonomous identification scheme based on Bluetooth Low Energy (BLE) technology. We formulate [...] Read more.
The rapid proliferation of low-altitude unmanned aerial vehicle (UAV) applications has made autonomous identification technology critical for flight safety and collaborative operations. In this paper, we propose and systematically analyze an autonomous identification scheme based on Bluetooth Low Energy (BLE) technology. We formulate a comprehensive system model that integrates link budget, packet collision, identification success probability, and power consumption. By incorporating safety interval constraints and a three-channel integrated reception probability, we employ an exhaustive search algorithm to optimize monitoring strategy parameters, thereby achieving an optimal trade-off between the Recognition Success Rate (RSR) and power consumption. Simulation results indicate that, at a PHY 1 Mbps rate, the optimal monitoring strategy theoretically approaches the Target Level of Safety (TLS) requirements for civil UAVs under the defined model assumptions, with a power consumption of 19.24 mW and an Average First Identification Delay (AFID) of 105 ms. Furthermore, simulation analysis verifies the scheme’s feasibility under dynamic topology, interference, and multi-UAV scenarios, providing a solid theoretical and technical reference for the practical implementation of autonomous UAV identification. Full article
(This article belongs to the Section Aerospace Science and Engineering)
Show Figures

Figure 1

30 pages, 17440 KB  
Article
AI-Driven Discovery of Prototype CLEC4M Inhibitors Targeting Marburg Virus Entry via Integrated Machine Learning and Molecular Modeling
by Mohammed Almaghrabi and Mansour S. Alturki
Int. J. Mol. Sci. 2026, 27(12), 5324; https://doi.org/10.3390/ijms27125324 - 12 Jun 2026
Viewed by 436
Abstract
Marburg virus (MARV), a highly pathogenic member of the Filoviridae family, causes severe hemorrhagic fever with a high case fatality rate and currently lacks effective therapeutics. The viral entry process, mediated by the interaction between the MARV glycoprotein (GP) and host receptor C-type [...] Read more.
Marburg virus (MARV), a highly pathogenic member of the Filoviridae family, causes severe hemorrhagic fever with a high case fatality rate and currently lacks effective therapeutics. The viral entry process, mediated by the interaction between the MARV glycoprotein (GP) and host receptor C-type lectin domain family 4 member M (CLEC4M) (L-SIGN), represents a critical target for early-stage intervention. The active compounds from BindingDB and the decoy from DUDE were used. The RDKit was used for feature engineering. Machine learning models were trained on an initial dataset consisting of 56 active chemicals and 1232 decoys. Among the tested algorithms, the Random Forest model demonstrated superior performance, achieving the highest discriminative ability (AUC = 0.93, MCC = 0.88) on the test set. Virtual screening of 11,032 phytochemicals resulted in 120 predicted actives, of which 42 compounds satisfied drug-likeness criteria. Subsequent molecular docking identified three lead compounds (PubChem IDs: 42608095, 5281601, and 11243993) with moderate-to-promising binding affinities (−6.3 to −6.5 kcal/mol) toward the CLEC4M binding site. ADMET analysis revealed favorable pharmacokinetic and toxicity profiles for the selected lead compounds. DFT calculations of the three compounds highlighted their electronic stability and reactive nature, indicating that PubChem IDs 42608095 and 5281601 possess particularly stable electronic properties conducive to favorable target interactions. Combining machine learning models with molecular docking and Molecular Dynamics (MD) simulations worked well in finding promising phytochemical inhibitors. The MM/GBSA binding free energy calculations further confirmed binding affinities, with values of −10.83 and −11.08 kcal/mol, respectively, suggesting favorable complex stability. These findings provide a pathway for developing new antiviral agents against MARV, pending further experimental validation and optimization. Full article
Show Figures

Figure 1

33 pages, 4102 KB  
Article
Real-Time Explanation Intrusion Detection: An XAI-Enriched Hybrid CNN-LSTM Architecture for Operational Cybersecurity
by Ayman Alnsour, Jamal Zarqou and Ahmad Shalaldeh
Mathematics 2026, 14(11), 1977; https://doi.org/10.3390/math14111977 - 3 Jun 2026
Viewed by 496
Abstract
Deep learning-based intrusion detection systems offer world-class accuracy in threat classification. They are also generally not easily explainable to security analysts, which represents a major hurdle in their use in real-world Security Operations Centers (SOCs) where explainability and trust are critical. This operational [...] Read more.
Deep learning-based intrusion detection systems offer world-class accuracy in threat classification. They are also generally not easily explainable to security analysts, which represents a major hurdle in their use in real-world Security Operations Centers (SOCs) where explainability and trust are critical. This operational challenge is tackled with a systems-engineered approach combining the CNN-LSTM architecture with the computationally optimized SHAP and LIME approaches for enabling real-time, interpretable threat detection. Unlike novel mathematical formulations, we concentrate on practical innovations in systems engineering that we believe are required to generate explanations in real-time: quantization of the numbers to INT8, execution of explanation algorithms in parallel, asynchronously, and caching of similar traffic patterns. CNN-LSTM combines the convolutional function to capture spatial dependencies and the recurrent function to capture temporal dynamics of network traffic, and SHAP and LIME capture global and local feature attributions, respectively. One of the major innovations is the parallel execution which brings the latency of explanation down from 117 ms (sequential SHAP + LIME) to 46 ms (parallel, cache-miss) and 39 ms (average with caching) and 46 ms (without caching), which is sufficient for operational “real-time” requirements. The framework is evaluated on CICIDS2017 and NSL-KDD benchmark datasets, and results show that it can achieve 98.7% accuracy with 98.6% F1-score and sub-50 ms explanation latency. The results here show that explainability and operational efficiency can be attained with the same level of accuracy in the detection of abnormal events, through careful systems engineering. This paper presents a systems-engineered framework demonstrating the feasibility of real-time, interpretable IDS for deployment in Security Operations Centers (SOCs) and addresses the challenges of combining high-performance deep learning with operational transparency in cybersecurity. Full article
Show Figures

Figure 1

32 pages, 47363 KB  
Article
A Phenology-Guided Multi-Source Framework for In-Season Rice Mapping in Cloud-Prone and Complex Agroecosystems
by Wei Wang, Shiqiang Liu, Huijin Yang, Ning Li, Jianhui Zhao, Wenfu Wu and Wenkui Zheng
Remote Sens. 2026, 18(11), 1828; https://doi.org/10.3390/rs18111828 - 3 Jun 2026
Viewed by 477
Abstract
Rice is one of the world’s most important food crops, feeding over half of the global population and being crucial for food security. Accurate, timely mapping of rice fields is essential for precision agriculture, yet conventional methods relying on static samples fail to [...] Read more.
Rice is one of the world’s most important food crops, feeding over half of the global population and being crucial for food security. Accurate, timely mapping of rice fields is essential for precision agriculture, yet conventional methods relying on static samples fail to capture dynamic farmers’ planting decisions. To address this, we propose the Multi-Source Dynamic Sample Generation and Phenology-Guided Feature Selection Framework for In-Season Rice Identification (MSDF-RiceID) using multi-source remote sensing imagery. It incorporates two key innovations: (i) a rule-based sample updating mechanism based on historical rice maps and a dynamic threshold algorithm, and (ii) phenology-guided feature optimization through exponential weighting. Developed specifically to handle complex cropping patterns and high cloud cover in Hunan Province, MSDF-RiceID integrates these innovations within a grid-search-optimized Random Forest classifier to produce reliable monthly rice distribution maps. In-season samples corresponding to transplanting dates in April (DOY 100, 120), June (DOY 160), and July (DOY 184), differentiated as early-, middle-, and late-rice crops. The optimal feature set combined Sentinel-1 (PRI, VH, VH_VV), Sentinel-2 (NDYI, PSRI, NDBI, NDWI), and MODIS (NDVI, EVI, NDBI, LSWI) indices. Accuracy increased seasonally, with F1-score rising from 0.82 in May to 0.97 at harvest. Cross-region validation in Taishan (Guangdong) and Panjin (Liaoning) showed that the earliest identifiable stage (F1-score > 0.9) occurred earlier than in Hunan due to Hunan’s more complex triple-cropping phenology, highlighting the model’s strong transferability. Furthermore, MSDF-RiceID outperformed existing products (TWDTW-Rice and EARice10), increasing overall accuracy by 0.12–0.18, Kappa by 0.23–0.35, and F1-score by 0.09–0.15. These results demonstrate its effectiveness for in-season, large-scale, and dynamic rice mapping under persistent cloud cover, thereby providing direct support for precision agricultural management in heterogeneous cropping systems. Full article
(This article belongs to the Section Remote Sensing in Agriculture and Vegetation)
Show Figures

Figure 1

23 pages, 619 KB  
Article
A Transformer-Based Intrusion Detection System for Zero-Day Attack Detection in IoT Networks
by Murtadha D. Hssayeni and Imadeldin Mahgoub
Future Internet 2026, 18(6), 282; https://doi.org/10.3390/fi18060282 - 25 May 2026
Cited by 1 | Viewed by 659
Abstract
The possibility of zero-day attacks on Internet of Things (IoT) networks is high, particularly in dynamic and heterogeneous IoT environments, including emerging battlefield scenarios (IoBT). Detecting these attacks requires adaptive and generalizable security mechanisms. Due to the unique and unknown signatures of these [...] Read more.
The possibility of zero-day attacks on Internet of Things (IoT) networks is high, particularly in dynamic and heterogeneous IoT environments, including emerging battlefield scenarios (IoBT). Detecting these attacks requires adaptive and generalizable security mechanisms. Due to the unique and unknown signatures of these attacks, they go undetected using signature-based Intrusion Detection Systems (IDSs) on the one side. On the other side, current anomaly-based IDSs that employ traditional machine learning on statistical features struggle to adapt and generalize to unknown networks, which is the case in IoBT. Transformer-based deep learning models have shown the capability of learning complex sequential patterns. This ability can be leveraged to analyze packet payloads that encompass opcodes capable of executing malicious patterns within an IoT network. In this work, we propose a dual-stage Transformer IDS that operates on the raw payload of network packets to detect zero-day attacks. Due to the lack of IoBT datasets, we evaluate the algorithm on three comprehensive IoT traffic benchmarks—MQTT-IoT, IoT-23, and CIC-IoT-2022—which have a high number of IoT devices and various attacks. Importantly, model evaluation is performed in two cross-validation settings to address the key operational challenges associated with unseen scenarios and networks. The evaluation settings are split-at-scenario to evaluate the detection ability of zero-day attacks and split-at-dataset to evaluate the model’s generalizability to new environments. In the former, the average increase in the F1-score of the proposed algorithm over the baseline model is 44% in detecting four zero-day attacks presented in the MQTT-IoT dataset. In the latter, the average increase in the F1-score is 16% in detecting malicious attacks across the three datasets. These results show the benefit of advanced AI in securing the next generation of IoT systems in future Internet applications. Full article
(This article belongs to the Special Issue State-of-the-Art Future Internet Technology in USA 2026–2027)
Show Figures

Graphical abstract

Back to TopTop