Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (100)

Search Parameters:
Keywords = Indicators of Threats (IOT)

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
17 pages, 750 KB  
Article
Bridging Governance and Empirical Threat Intelligence: An Integrated Framework for Cybersecurity in Smart Farming
by Radwan Rouzky, Abdolhossein Sarrafzadeh, Evelyn Sowells-Boone, Jason Green, Hannaneh B. Pasandi and Gregory Goins
Appl. Sci. 2026, 16(18), 8943; https://doi.org/10.3390/app16188943 - 9 Sep 2026
Viewed by 186
Abstract
Modern agriculture’s integration of Internet of Things (IoT), Industrial Control Systems (ICSs), and data analytics boosts productivity but introduces significant cybersecurity and data governance challenges. Existing scholarship is divided between policy-focused governance and technical attack analyses, hindering the development of comprehensive, enforceable defenses. [...] Read more.
Modern agriculture’s integration of Internet of Things (IoT), Industrial Control Systems (ICSs), and data analytics boosts productivity but introduces significant cybersecurity and data governance challenges. Existing scholarship is divided between policy-focused governance and technical attack analyses, hindering the development of comprehensive, enforceable defenses. This paper introduces an integrated framework that bridges normative data governance in smart farming (SF) with empirical, honeynet-derived threat intelligence. Drawing on the authors’ previous systematic review of SF data governance and a honeynet simulating agricultural IoT/ICS, the study maps governance challenges to quantitative attack indicators from honeynet logs, classifying each pairing as directly supported by telemetry, indirectly supported by telemetry, or not observable using the current methodology. The findings show that the services flagged as governance concerns face sustained attack pressure: the honeynet recorded brute-force attempts against SSH/Telnet on simulated irrigation controllers (149,000 events), connection and login attempts targeting SMB (Server Message Block) and MQTT (Message Queuing Telemetry Transport) on automated machinery (67,156), credential-guessing attempts against management services (14,937), and ICS protocol probes (11,532). Geographic and protocol distributions reveal that legacy industrial protocols and weakly authenticated management interfaces, both highlighted as governance concerns, constitute the primary attack surface. This evidence supports a tiered governance model integrating protocol-level controls, identity governance, and data-sharing policy, demonstrating that effective SF cybersecurity requires empirically calibrated rather than purely policy-driven frameworks. The proposed framework offers actionable guidance for aligning technical defenses with data governance obligations. This work contributes a new methodological protocol (cross-evidentiary mapping), an empirically calibrated tiered framework, and a coherent research agenda at the intersection of governance and measurement, serving as a template for similar analyses in other critical infrastructure sectors. Full article
Show Figures

Figure 1

25 pages, 7167 KB  
Article
SHAP-Guided Feature Selection for IoT Botnet Detection: A Comparative Study with Conventional Methods
by Man Hua, Xinyue Zhang and Yanling Li
Appl. Sci. 2026, 16(17), 8840; https://doi.org/10.3390/app16178840 - 5 Sep 2026
Viewed by 141
Abstract
The widespread deployment of Internet of Things (IoT) devices has expanded the attack surface of modern networks, making IoT botnets a persistent cybersecurity threat. Although machine learning-based intrusion detection systems (IDSs) have demonstrated promising detection capability, their performance is often hindered by redundant [...] Read more.
The widespread deployment of Internet of Things (IoT) devices has expanded the attack surface of modern networks, making IoT botnets a persistent cybersecurity threat. Although machine learning-based intrusion detection systems (IDSs) have demonstrated promising detection capability, their performance is often hindered by redundant high-dimensional features and limited model interpretability. This study presents an explainability-guided feature selection framework that employs SHAP values derived from an XGBoost model to rank features and systematically compares its effectiveness with Mutual Information (MI), Analysis of Variance (ANOVA), and Principal Component Analysis (PCA) across nine machine learning classifiers using the N-BaIoT dataset. Experimental results indicate that LightGBM with SHAP-selected features achieves an accuracy of 0.9994 using only the top 10 features. Among the evaluated feature selection methods, SHAP achieves the highest classification performance on seven of the nine classifiers, while Wilcoxon signed-rank tests indicate a statistically significant difference between SHAP and ANOVA (p = 3.03 × 10−5); the difference between SHAP and MI is significant at the conventional threshold (p = 2.86 × 10−2) but does not remain significant after Bonferroni correction for multiple comparisons. Furthermore, SHAP-based analysis reveals distinct traffic statistical signatures between the Mirai and Gafgyt botnet families, offering actionable insights for explainability-aware IoT intrusion detection. The proposed framework provides a practical solution for balancing detection performance and model interpretability in IoT botnet detection. Full article
Show Figures

Figure 1

26 pages, 5091 KB  
Article
Microcontroller-Based Multi-Sensor IoT Testbed for Cyberattack Simulation, Data Creation, and Intrusion Detection
by Khawlah Harasheh, Satinder Gill, Kendra Brinkley, Salah Garada, Dindin Aro Roque, Hayat MacHrouhi, Janera Manning-Kuzmanovski, Jesus Marin-Leal, Melissa Isabelle Arganda-Villapando and Sayed Ahmad Shah Sekandary
Electronics 2026, 15(17), 3986; https://doi.org/10.3390/electronics15173986 - 4 Sep 2026
Viewed by 374
Abstract
The Internet of Things (IoT) continues to expand rapidly, bringing with it a new set of security concerns. Many IoT devices are lightweight and limited in processing power, which makes them vulnerable when used in critical applications. Although there are several datasets available [...] Read more.
The Internet of Things (IoT) continues to expand rapidly, bringing with it a new set of security concerns. Many IoT devices are lightweight and limited in processing power, which makes them vulnerable when used in critical applications. Although there are several datasets available for network-level intrusion detection, very few provide practical guidance on how microcontrollers and physical sensors can be combined to recreate realistic attack scenarios in a way that supports reproducible research. In this work, we present a microcontroller-based testbed that integrates multiple sensors to capture, store, and analyze data under both normal operation and simulated cyberattacks. The testbed connects environmental, motion, and network sensors to model IoT systems that are exposed to common threats including Denial-of-Service (DoS), Distributed DoS (DDoS), and Slowloris attacks. The system enables direct sensor-to-microcontroller connections, real-time logging, and synchronized event monitoring, allowing for detailed analysis of how devices behave under attack. Environmental and physical sensor measurements are included to provide synchronized cyber-physical context and baseline operational information rather than demonstrated direct indicators of the investigated network attacks. Alongside the testbed, we share a dataset containing sensor readings, system metrics, and labeled attack events. This contribution provides a practical resource for researchers and educators interested in IoT security, machine-learning-based intrusion detection, and the development of countermeasures rooted in real-world data. By combining low-level hardware experimentation with higher-level security analysis, this work creates a foundation for advancing experimental approaches to cybersecurity in IoT environments. Full article
Show Figures

Figure 1

28 pages, 599 KB  
Review
Artificial Intelligence for Anomaly Detection in Cyber Defense: A Critical Review of Methodological Trends, Datasets, and Explainability
by Paul-Vasile Vezeteu, Nicolae-Daniel Boboc and Dumitru-Iulian Năstac
Algorithms 2026, 19(9), 750; https://doi.org/10.3390/a19090750 - 3 Sep 2026
Viewed by 257
Abstract
The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with [...] Read more.
The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with the corresponding cyber defense methods. Given the new landscape, it is more difficult for classical cybersecurity systems to stay up to date with novel threats, as well as to keep track of all interconnected devices defined by various protocols and behaviors. Artificial intelligence (AI) represents a strong candidate to complement traditional cyber defense methods due to its adaptability to variation and capability to identify complex data patterns, which has led researchers to develop state-of-the-art anomaly detection systems. The current critical review aims to analyze the scientific literature on three dimensions including used algorithms and datasets, domain challenges hindering AI deployment in productive environments, and the capability of explainable artificial intelligence (XAI) to support cyber security experts with insights into the model’s inner workings and decision rationale. Compared to existing scientific reviews, this paper moves beyond algorithmic comparison by providing a methodological interpretation of AI anomaly detection landscape, demonstrating how data availability, learning paradigms, and explainability collectively influence the evolution of cyber defense research towards operational deployment. This approach revealed that AI development for cyber defense is highly heterogenous, and that the available datasets strongly influence the algorithm of choice, rather than the models being chosen methodologically based on proven performance. The analysis further indicates that operational deployment remains challenging, as the literature continues to report substantial limitations related to data quality, computational requirements, and model interpretability. Full article
Show Figures

Figure 1

37 pages, 16235 KB  
Article
Privacy-Preserving and Quantum-Resilient Blockchain Infrastructures for MuReQua Federated Micro Data Centers
by Gerardo Iovane
Electronics 2026, 15(16), 3575; https://doi.org/10.3390/electronics15163575 - 11 Aug 2026
Viewed by 556
Abstract
The rapid growth of AI-driven workloads, IoT ecosystems, and distributed digital services has exposed fundamental limitations in existing cloud and edge infrastructures, particularly in guaranteeing robust data privacy under emerging quantum threats. Current blockchain-based systems provide integrity and decentralization but rely predominantly on [...] Read more.
The rapid growth of AI-driven workloads, IoT ecosystems, and distributed digital services has exposed fundamental limitations in existing cloud and edge infrastructures, particularly in guaranteeing robust data privacy under emerging quantum threats. Current blockchain-based systems provide integrity and decentralization but rely predominantly on computational cryptography and access-control mechanisms, leaving them vulnerable to future quantum adversaries and large-scale inference attacks. In this paper, we introduce Data Communities as a novel paradigm for privacy-preserving, blockchain-enabled cooperative digital infrastructures, formalized within the Cooperative Digital Infrastructure (CDI) framework. Our approach integrates three complementary privacy protection layers: (i) MuReQua, a quantum-resilient blockchain consensus mechanism leveraging CQKD for cryptographic robustness against Shor-type attacks; (ii) DeSSE, an information-theoretically secure distributed storage model based on n × m fragmentation, ensuring zero information leakage below reconstruction thresholds; and (iii) a multi-tier data sovereignty model (C0–C3) enforcing policy-driven data locality and regulatory compliance across federated nodes. We formalize privacy guarantees through an adversarial model encompassing classical, quantum, insider, and governance-level threats, and demonstrate that the proposed architecture achieves information-theoretic confidentiality, forward secrecy, and attack-resilient distributed governance. A privacy leakage analysis shows that the probability of data reconstruction under sub-threshold compromise is identical to zero, outperforming conventional blockchain storage models based on encryption alone. Simulation and case study results indicate that Data Communities achieve up to 99.999% service availability, 55% reduction in external data exposure, and 22–35% carbon-aware optimization, while maintaining strict privacy guarantees across distributed environments. Compared with existing blockchain systems (e.g., Ethereum, Hyperledger Fabric), the proposed framework shifts privacy protection from access-control and pseudonymity to structural, information-theoretic privacy by design. Overall, the results establish Data Communities as a scalable and quantum-resilient foundation for next-generation privacy-preserving blockchain infrastructures, bridging distributed AI, secure storage, and cooperative governance under a unified formal model. Full article
(This article belongs to the Special Issue Data Privacy Protection in Blockchain Systems)
Show Figures

Figure 1

29 pages, 10432 KB  
Article
A Physical-Layer Threat Detection Framework for Secure IoT and Smart Grid Networks Using HHT-Based Multimodal Deep Learning
by Jie Ren, Chunhai Zhou, Chuyang Tan and Yan Wang
Technologies 2026, 14(7), 423; https://doi.org/10.3390/technologies14070423 - 11 Jul 2026
Viewed by 318
Abstract
Secure IoT and smart grid networks depend on reliable hardware operation to maintain continuous service and system availability. Physical-layer abnormalities such as partial discharge (PD) can weaken infrastructure components and disrupt connected systems before conventional monitoring methods detect the problem. PD is one [...] Read more.
Secure IoT and smart grid networks depend on reliable hardware operation to maintain continuous service and system availability. Physical-layer abnormalities such as partial discharge (PD) can weaken infrastructure components and disrupt connected systems before conventional monitoring methods detect the problem. PD is one of the earliest indicators of abnormal hardware activity in electrical infrastructure. If it is not detected in time, it can damage equipment, reduce system reliability, and increase the risk of service interruption in intelligent network environments. Existing detection methods often struggle with PD signals because these signals are non-stationary, vary over time, and frequently contain noise. This limits reliable physical-layer threat detection in secure IoT and smart grid networks. This study presents an integrated physical-layer threat-detection framework for secure IoT and smart grid networks that combines adaptive HHT-based signal decomposition with multimodal deep learning for early hardware threat identification. The framework first applies the Hilbert–Huang Transform (HHT) to decompose PD signals and extract time–frequency features that describe discharge behavior. A convolutional neural network with an attention-based fusion mechanism then learns patterns from electrical and acoustic signals. The model classifies hardware condition into normal operation, early abnormal activity, and critical discharge states associated with potential hardware threats. The framework is evaluated using two public datasets: the Dataset of Partial Discharge and Noise Signals and the Partial Discharge Localization (PD-Loc) dataset available through the IEEE DataPort. Experimental evaluation shows that the proposed framework achieves 97.8% detection accuracy, a 97.0% F1-score, and an average AUC of 0.98. The framework maintains 94.6% accuracy under severe noise conditions (10 dB SNR) and performs inference in approximately 12 ms per sample. Furthermore, component-wise analysis further shows that HHT-based feature extraction improves detection accuracy from 91.8% to 95.6%, while multimodal learning increases the final accuracy to 97.8%. Full article
(This article belongs to the Special Issue Research on Security and Privacy of Data and Networks)
Show Figures

Figure 1

45 pages, 2480 KB  
Article
Cross-Platform Performance and Security Evaluation of Post-Quantum Cryptographic Algorithms on Resource-Constrained Devices
by Daiana-Larisa Lucaciu and Daniela Elena Popescu
Appl. Sci. 2026, 16(12), 5781; https://doi.org/10.3390/app16125781 - 8 Jun 2026
Viewed by 1609
Abstract
The rapid advancement of quantum computing poses a fundamental threat to classical public-key cryptographic systems, necessitating the transition to post-quantum cryptography (PQC). While significant progress has been made in the standardization of quantum-resistant algorithms, their practical deployment in heterogeneous environments—particularly resource-constrained Internet of [...] Read more.
The rapid advancement of quantum computing poses a fundamental threat to classical public-key cryptographic systems, necessitating the transition to post-quantum cryptography (PQC). While significant progress has been made in the standardization of quantum-resistant algorithms, their practical deployment in heterogeneous environments—particularly resource-constrained Internet of Things (IoT) devices—remains a critical challenge. This study presents a comprehensive experimental evaluation of four NIST-standardized PQC algorithms: CRYSTALS-Kyber (ML-KEM), CRYSTALS-Dilithium (ML-DSA), FALCON, and SPHINCS+. The scope of these findings is bounded by an empirical analysis conducted across two specific testing platforms, a high-performance x86-64 workstation (AMD Ryzen 7 5700U) and a resource-constrained embedded microcontroller (ESP32-WROOM), utilizing dedicated software environments implemented in Native C, Go, and Python. The evaluation isolates key performance indicators, including computational latency, memory consumption, communication overhead, and temporal determinism, based on benchmarking over 1000 iterations. Within this experimental setup, results demonstrate clear trade-offs between target security categories, execution performance, and structural memory limits. Lattice-based schemes such as Kyber and Falcon exhibit optimal efficiency and scalability on the tested embedded platform, while the specific memory limits of the ESP32 platform introduce architectural stability constraints for higher-tier Dilithium variants. In contrast, SPHINCS+ provides structural robustness at the cost of higher computational hashing latency within these evaluation environments. The findings highlight the critical role of hardware-specific constraints and language runtime design choices in enabling practical PQC deployment, providing context-specific insights supporting the secure migration of IoT infrastructures toward quantum-resilient systems. Full article
(This article belongs to the Special Issue Quantum Communication and Applications)
Show Figures

Figure 1

30 pages, 506 KB  
Review
Artificial Intelligence for Cybersecurity in IoT-Edge Systems: A Structured Review of Methods, Datasets, Evaluation, and Deployment Challenges
by Qingshui Xue, Pandong Xue, Zhimin Wang and Haifeng Ma
Electronics 2026, 15(11), 2409; https://doi.org/10.3390/electronics15112409 - 1 Jun 2026
Cited by 1 | Viewed by 1571
Abstract
The convergence of the Internet of Things (IoT), edge computing, and artificial intelligence (AI) is reshaping cyber defense in distributed cyber–physical environments. IoT-edge systems expose heterogeneous, resource-constrained, and intermittently connected devices to threats that unfold close to sensing and control processes, making purely [...] Read more.
The convergence of the Internet of Things (IoT), edge computing, and artificial intelligence (AI) is reshaping cyber defense in distributed cyber–physical environments. IoT-edge systems expose heterogeneous, resource-constrained, and intermittently connected devices to threats that unfold close to sensing and control processes, making purely signature-based or rule-based defenses increasingly insufficient. This article presents a structured review of AI for cybersecurity in IoT-edge systems from a systems-oriented perspective. Rather than surveying AI for IoT security in general, it organizes the literature around four practical lenses: AI methods, datasets and benchmarks, evaluation practice, and deployment constraints. The review reconstructs a workspace-verifiable corpus of 96 references, emphasizes literature published between January 2023 and April 2026 while retaining foundational benchmark papers, and uses a conservative 26-paper empirical subset for paper-level gap coding. Because this subset was purposively sampled and the original retrieval logs were not preserved, coded counts are interpreted as recoverable reporting signals and comparability indicators rather than field-level prevalence estimates. The revised synthesis further stratifies the coded evidence by task, model family, dataset, application scenario, metric type, and deployment signal, and translates deployment feasibility into a minimum reporting checklist and edge-hardware decision matrix. Within this evidence boundary, recent work remains dominated by intrusion and anomaly detection, with continued use of traditional machine learning, deep learning, federated learning, explainable AI, and graph-based approaches. However, experimentation remains concentrated around a small set of public benchmarks, while latency, memory, energy, communication overhead, operational robustness, and reproducibility are reported inconsistently. The field is therefore constrained less by classifier novelty than by benchmark concentration, weak deployment reporting, limited response-and-mitigation analysis, undercoverage of authentication, access-control, and trust-management tasks, and limited reproducible edge-aware evaluation. Full article
Show Figures

Figure 1

24 pages, 8097 KB  
Article
A Symmetric XOR-Based Dynamic Multiple Secret Sharing Visual Cryptography Framework
by Sona G and Purusothaman T
Symmetry 2026, 18(5), 802; https://doi.org/10.3390/sym18050802 - 7 May 2026
Viewed by 584
Abstract
The increasing trend in the transmission of image-based data across various ecosystems like telemedicine, multimedia communication, Internet of Things (IoT), and cloud storage demands a strong security system that can withstand both classical and emerging computational threats. Classical cryptographic solutions require complex processing, [...] Read more.
The increasing trend in the transmission of image-based data across various ecosystems like telemedicine, multimedia communication, Internet of Things (IoT), and cloud storage demands a strong security system that can withstand both classical and emerging computational threats. Classical cryptographic solutions require complex processing, and hence, meeting the real-time processing requirements is challenging. In contrast, visual cryptography (VC) provides a lightweight security solution. This study proposes a new XOR-based Dynamic Multiple Secret Sharing Visual Cryptography Scheme (XDMSSVCS) designed to share multiple binary image secrets with resistance to emerging computational threats. This work introduces a novel base share creation algorithm designed to generate statistically independent shares while maintaining the symmetric reconstruction property inherent in XOR-based visual cryptography. Also, a lightweight chaotic scrambling mechanism is integrated to address the information leakage problem during transmission. The experimental results indicate pixel-perfect reconstruction (MSE = 0, PSNR = ∞, SSIM = 1), near-ideal entropy, near-zero correlation between shares, high key sensitivity (10−14 variation leading to decorrelated outputs), and a large key space exceeding 2128, ensuring resistance against brute-force attacks. The framework also exhibits low computational overhead (XOR: ~0.90 ms, scrambling: ~383.72 ms, memory: ~15.58 MB), and strong resistance to attacks, establishing the XDMSSVCS as a secure and scalable framework for dynamic multi-secret sharing. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

20 pages, 3072 KB  
Article
Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study
by Rajkumar Banoth, Santosh Reddy Addula, Aruna Kranthi Godishala, Rithwik Sannapu, Guna Sekhar Sajja, Deepak Kumar, Vinay Kumar Kasula and Chaitanya Tumma
J. Cybersecur. Priv. 2026, 6(3), 82; https://doi.org/10.3390/jcp6030082 - 2 May 2026
Viewed by 1345
Abstract
The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated [...] Read more.
The rapid proliferation of Internet of Things (IoT) devices has significantly increased the attack surface for large-scale botnet operations. While previous research, including detailed analyses using Cowrie and IoTPOT frameworks, has studied IoT botnet behavior, these studies often rely on retrospective datasets, isolated protocol analyses, or hard-to-replicate setups. This paper addresses that gap with two main contributions: a structured review of ten influential IoT security studies from the USENIX Security Symposium and a confirmatory empirical experiment deploying Cowrie and IoTPOT honeypots simultaneously on a Microsoft Azure cloud-based virtual machine. Unlike earlier studies that focus on single protocols or large-scale environments, this work acts as a validation study, confirming well-known IoT botnet behaviors, including credential brute-force attacks, Mirai-style commands, and Telnet dominance, using real-time attack data collected from a reproducible, affordable cloud environment that simulates known IoT vulnerabilities (such as CVE-2016-10401, CVE-2017-17215, and CVE-2014-9222). Rather than revealing new attack methods, this study explicitly verifies the persistence of behaviors first documented almost ten years ago. The data indicates that attackers continue to exploit basic authentication flaws and reuse long-standing command sequences, confirming that core IoT vulnerabilities remain prevalent despite a decade of security research. It also highlights the ongoing gap between research progress and industry implementation. The analysis situates these findings within the broader evolution of IoT botnets, from early centralized command-and-control structures like Mirai to more resilient peer-to-peer networks that use anonymized channels and target high-wattage devices for power-grid manipulation. This study shows that small, cloud-based honeypots are valuable for continuous threat monitoring, model validation, and security assessments, providing a practical, reproducible approach for ongoing IoT security research. Full article
Show Figures

Figure 1

21 pages, 604 KB  
Article
Security-Aware Task Offloading in IoT Edge Networks Using Software-Defined Networking
by Ahmed Raoof Tawfeeq Al-Hasani, Ali Broumandnia and Hamid Haj Seyyed Javadi
Math. Comput. Appl. 2026, 31(3), 72; https://doi.org/10.3390/mca31030072 - 1 May 2026
Cited by 1 | Viewed by 904
Abstract
The rapid proliferation of Internet of Things (IoT) devices increases the demand for task offloading mechanisms that satisfy strict latency constraints while limiting security exposure in edge computing environments. This paper proposes a security-aware task offloading framework for IoT edge networks, using Software-Defined [...] Read more.
The rapid proliferation of Internet of Things (IoT) devices increases the demand for task offloading mechanisms that satisfy strict latency constraints while limiting security exposure in edge computing environments. This paper proposes a security-aware task offloading framework for IoT edge networks, using Software-Defined Networking (SDN) as a centralized control plane. The SDN controller combines real-time monitoring, threat-aware risk estimation, and a lightweight heuristic decision engine to assign tasks to heterogeneous edge nodes according to latency constraints, resource availability, and task security sensitivity. To avoid optimistic scalability assumptions, the evaluation explicitly models contention through load-dependent queueing delay at edge nodes and reduced effective bandwidth on shared links. Simulation results with realistic IoT task parameters and heterogeneous edge capacities show that the proposed framework achieves an average latency of approximately 125±5 ms, a task completion ratio (TCR) of about 92±2%, and a security success rate (SSR) near 95±1.5%, compared to the considered baselines. These results indicate that incorporating risk assessment into SDN-based offloading decisions can improve security-related outcomes while maintaining practical performance under contention. Limitations include the use of an analytical risk model and a single-controller SDN setting; future work will investigate multi-controller deployments, attack-trace-driven evaluation, and energy-aware extensions. Full article
(This article belongs to the Special Issue Applied Optimization in Automatic Control and Systems Engineering)
Show Figures

Figure 1

23 pages, 2625 KB  
Article
An Enhanced XGBoost-Based Framework for Efficient Multi-Class Cyber Threat Detection in Industrial IoT Networks
by Adel A. Ahmed and Talal A. A. Abdullah
Technologies 2026, 14(5), 274; https://doi.org/10.3390/technologies14050274 - 1 May 2026
Cited by 3 | Viewed by 1618
Abstract
Securing Industrial IoT (IIoT) network environments remains a significant challenge due to the increasing complexity of interconnected sensors, actuators, gateways, and control systems, which are frequent targets of cyberattacks. These threats can lead to operational disruptions, financial losses, and safety risks. This paper [...] Read more.
Securing Industrial IoT (IIoT) network environments remains a significant challenge due to the increasing complexity of interconnected sensors, actuators, gateways, and control systems, which are frequent targets of cyberattacks. These threats can lead to operational disruptions, financial losses, and safety risks. This paper proposes an efficient multi-stage intrusion detection framework based on an enhanced Extreme Gradient Boosting (XGBoost) model for IIoT environments. The proposed framework integrates data preprocessing, class imbalance handling, hyperparameter optimization, probability calibration, and class-specific decision thresholds within a unified pipeline. In addition, calibrated probability outputs are utilized as continuous indicators of prediction confidence, enabling more reliable and risk-aware decision-making. The hierarchical multi-stage design decomposes the detection task into progressively refined classification levels, improving discrimination among complex and overlapping attack categories. The framework is evaluated using the Edge-IIoTset benchmark dataset, which reflects realistic IIoT network traffic under both normal and malicious conditions. Experimental results demonstrate that the proposed approach achieved significant performance improvements, including up to 21% increase in recall and 15% improvement in macro F1 score compared to the baseline models. Furthermore, the model exhibits low inference latency and supports efficient deployment in time-sensitive IIoT monitoring scenarios. These results indicate that the proposed framework provides an effective and scalable solution for multi-class cyber threat detection in IIoT networks. Full article
(This article belongs to the Special Issue IoT-Enabling Technologies and Applications—2nd Edition)
Show Figures

Figure 1

14 pages, 1608 KB  
Proceeding Paper
Explainable Intrusion Detection System Using Prototypical Network and Recursive Feature Elimination
by Wessam F. Abouzaid, Ebrahim A. Ramadan and Nermeen G. Rezk
Comput. Sci. Math. Forum 2026, 13(1), 12; https://doi.org/10.3390/cmsf2026013012 - 22 Apr 2026
Viewed by 431
Abstract
This study explores the use of traditional machine learning and deep learning algorithms to develop efficient Intrusion Detection Systems (IDSs). It evaluates data using the NSL-KDD dataset, which contains both normal and attack traffic. The research compares the performance of various classifiers, including [...] Read more.
This study explores the use of traditional machine learning and deep learning algorithms to develop efficient Intrusion Detection Systems (IDSs). It evaluates data using the NSL-KDD dataset, which contains both normal and attack traffic. The research compares the performance of various classifiers, including Random Forest, Extreme Gradient Boosting, LightGBM, and Prototypical Networks. Recursive Feature Elimination is used for feature selection to enhance decision-making and model performance. The models are assessed using multiple metrics, such as accuracy, precision, recall, F-score, ROC curves, and confusion matrices. In addition, Explainable AI techniques like SHAP and LIME are employed to interpret predictions, making the IDS more transparent and reliable. Results indicate that few-shot learning models, particularly Prototypical Networks, combined with Recursive Feature Elimination techniques, outperform traditional models, achieving up to 98% accuracy. This approach enhances IDS applications in IoT by enabling more accurate threat detection, improving decision-making, and identifying key intrusion parameters. Full article
(This article belongs to the Proceedings of The 1st International Conference on Emerging Tech & Innovation (ICETI))
Show Figures

Figure 1

26 pages, 1940 KB  
Article
Industry 4.0 in the Sustainable Maritime Sector: A Componential Evaluation with Bayesian BWM
by Mahmut Mollaoglu, Bukra Doganer, Hakan Demirel, Abit Balin and Emre Akyuz
Sustainability 2026, 18(8), 4078; https://doi.org/10.3390/su18084078 - 20 Apr 2026
Viewed by 774
Abstract
The rapid diffusion of industry 4.0 technologies has substantially transformed the maritime transportation sectors by enabling data-driven operations, enhanced connectivity, and more intelligent decision-making processes. Digital technologies such as the Internet of Things (IoT), simulation systems, and advanced data analytics are increasingly reshaping [...] Read more.
The rapid diffusion of industry 4.0 technologies has substantially transformed the maritime transportation sectors by enabling data-driven operations, enhanced connectivity, and more intelligent decision-making processes. Digital technologies such as the Internet of Things (IoT), simulation systems, and advanced data analytics are increasingly reshaping operational structures in maritime logistics, positioning technological transformation as a strategic priority for firms. However, the weighting and prioritization of components emerging with industry 4.0 technologies remain an underexplored area in the literature. The primary motivation of this study is to determine the weights of these industry 4.0 components using the Bayesian Best Worst Method (BWM) and to reveal their corresponding credal ranking levels. In this context, the present study aims to evaluate and prioritize the critical industry 4.0 components influencing technological transformation processes using the Bayesian BWM. Bayesian BWM is preferred over alternative Multi Criteria Decision Making (MCDM) approaches due to its ability to explicitly model uncertainty within a probabilistic framework, generate more consistent weighting results, and flexibly incorporate decision-makers’ judgments. The findings reveal that safety and security (0.2945) constitute the most influential main component, underscoring the necessity of robust digital infrastructures and reliable systems within highly digitalized operational environments. Among the sub-components, data privacy (0.1301) demonstrates the highest global weight, highlighting the growing importance of safeguarding sensitive information in data-intensive digital systems. The results further indicate that autonomous operation and coordination play significant roles in facilitating efficient digital operations, particularly through real-time equipment monitoring and IoT-based operational visibility. Moreover, sustainability (0.1968) emerges as the second most important component, suggesting that organizations increasingly assess technological investments not only in terms of operational efficiency but also with respect to long-term resilience. Within this dimension, continuous training (0.0614) is identified as the most influential component, indicating that the success of digital transformation depends not only on technological infrastructure but also on the development of human capabilities. With the increasing digitalization of the maritime industry, protection against cyber threats has become essential for ensuring operational continuity and safeguarding data integrity. In this regard, adopting proactive cybersecurity strategies and continuously monitoring and updating systems are of critical importance. In the digital transformation of maritime transportation, integrating sustainability considerations is essential to ensure long-term operational efficiency and environmental responsibility. These practical implications are particularly relevant for policymakers, port authorities, and shipping companies seeking to enhance both digital capabilities and sustainable performance. Full article
(This article belongs to the Section Sustainable Oceans)
Show Figures

Figure 1

25 pages, 2809 KB  
Article
E-PTES-S: Enhanced Trust Evaluation via Multidimensional Spatiotemporal Fusion and Variance-Based Stability Sequence Extraction in IoT Sensing Networks
by Jinze Liu, Yongtao Yao, Xiao Liu, Jining Chen, Shaoxuan Li and Jiayi Lin
Sensors 2026, 26(8), 2382; https://doi.org/10.3390/s26082382 - 13 Apr 2026
Viewed by 518
Abstract
Mobile data collectors (MDCs) play a very important role in Internet of Things (IoT) sensing networks. However, ensuring their trustworthiness against insider threats, such as on–off attacks and spatiotemporal fabrication, remains a critical challenge. Existing trust evaluation methods frequently struggle with these threats [...] Read more.
Mobile data collectors (MDCs) play a very important role in Internet of Things (IoT) sensing networks. However, ensuring their trustworthiness against insider threats, such as on–off attacks and spatiotemporal fabrication, remains a critical challenge. Existing trust evaluation methods frequently struggle with these threats due to insufficient evidence dimensions and the inability to quantify behavioral stability. To address these limitations, this paper proposes an enhanced proactive trust evaluation system based on stability sequence extraction (E-PTES-S). E-PTES-S improves the evaluation accuracy by integrating five factors of evidence, stability-computation mechanisms, and an adaptive weight allocation scheme to maintain robustness even when proactive verification data is scarce. In addition to the usual interaction and proactive verification indicators, regional consistency (TRC) and task timeliness (TTT) are introduced to mitigate location falsification and transmit-time deviations more rigorously. Then, a sliding window technique is used to obtain an integrated evidence sequence, which includes a new continuous stability sequence (FCSS) and traditional credible, untrustworthy, and uncertain sequences. This continuous stability sequence adds a variance-based incentive scheme to measure behavioral stability. Finally, the normalized trust value is derived from multiple indicators including multidimensional spatiotemporal evidence and stability metrics. Experimental results show that the proposed E-PTES-S achieves a normal node detection rate of 98.7% under complex dynamic conditions, outperforming the baseline PTES and Trust-SIoT algorithms by approximately 9% and 1%, respectively, while also improving the cumulative data collection profit by 4.8%. Furthermore, robustness analysis demonstrates that E-PTES-S exhibits excellent robustness against physical-layer uncertainties, successfully sustaining an 84.4% detection rate even under severe environmental shadowing. Full article
(This article belongs to the Special Issue Security, Trust and Privacy in Internet of Things)
Show Figures

Figure 1

Back to TopTop