Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (150)

Search Parameters:
Keywords = concept drift adaptation

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
37 pages, 2355 KB  
Article
Graph-Aware Reinforcement Learning for Adaptive APT Threat Hunting in Dynamic Enterprise Networks
by Bahar Memarpour, Kimia Memarpour, Kimia Shirini, Sina Samadi Gharehveran, Siamak Pedrammehr and Hussain Mohammed Dipu Kabir
Technologies 2026, 14(10), 624; https://doi.org/10.3390/technologies14100624 - 1 Oct 2026
Viewed by 117
Abstract
Advanced Persistent Threats (APTs) are particularly challenging for enterprise intrusion detection because they are time-evolving, distributed, and difficult to detect under changing network conditions. Conventional machine-learning-based intrusion detection systems (IDSs) often rely on node-level features and may be vulnerable to concept drift, topological [...] Read more.
Advanced Persistent Threats (APTs) are particularly challenging for enterprise intrusion detection because they are time-evolving, distributed, and difficult to detect under changing network conditions. Conventional machine-learning-based intrusion detection systems (IDSs) often rely on node-level features and may be vulnerable to concept drift, topological changes, and severe class imbalance, potentially achieving high overall accuracy while overlooking rare but critical malicious activities. This study proposes a Graph-Aware Deep Reinforcement Learning (GADRL) framework that integrates Graph Neural Networks (GNNs), Double Deep Q-Networks (DDQNs), and Prioritized Experience Replay (PER) for adaptive APT detection. Network traffic is modeled as a temporal graph to learn spatial–temporal relational representations of communication patterns and neighborhood interactions. These representations are then provided to a DDQN-based threat-hunting agent, while PER prioritizes high-severity and rare attack experiences during training. The framework is evaluated using five temporally ordered snapshots of enterprise network traffic to examine its performance under evolving network conditions. On an unseen future snapshot, GADRL achieves 100.00% recall, outperforming both a Random Forest baseline and a graph-agnostic reinforcement-learning ablation. This improvement in recall is accompanied by increased false-positive alerts, indicating a deliberate trade-off that prioritizes minimizing missed intrusions over reducing false alarms. Overall, the results demonstrate that combining topology-aware graph representation learning with priority-aware reinforcement learning can improve adaptive detection of evolving APTs under temporally changing network conditions. Full article
(This article belongs to the Special Issue Cybersecurity Challenges and Applications of AI in Engineering)
29 pages, 2040 KB  
Review
Toward Adaptive and Real-Time IIoT Intrusion Detection: A Survey of GAN-Based Augmentation, Drift-Aware Learning, and Edge Intelligence
by Adel A. Ahmed
AI 2026, 7(9), 386; https://doi.org/10.3390/ai7090386 - 21 Sep 2026
Viewed by 413
Abstract
The rapid evolution of sophisticated cyber threats has drastically increased the cybersecurity risks in Industrial Internet of Things environments due to the massive interconnection of industrial devices, sensors, programmable logic controllers, gateways, and edge computing infrastructures. Traditional intrusion detection systems are insufficient for [...] Read more.
The rapid evolution of sophisticated cyber threats has drastically increased the cybersecurity risks in Industrial Internet of Things environments due to the massive interconnection of industrial devices, sensors, programmable logic controllers, gateways, and edge computing infrastructures. Traditional intrusion detection systems are insufficient for modern IIoT networks due to challenges with dynamic attack behaviors, class imbalance, concept drift, and computational limitations of resource-constrained edge devices. Although machine learning and deep learning have significantly improved intrusion detection performance, current studies usually deal with these challenges separately and do not provide a holistic view of adaptive and real-time industrial internet of things (IIoT) cybersecurity. In this survey, we provide a structured narrative review of adaptive intrusion detection techniques, focusing on three emerging research directions, including GAN-based data augmentation, drift-aware learning, and Edge Intelligence. It provides a structured narrative review of machine learning, deep learning, and hybrid IDS models, benchmark IIoT datasets, and representative techniques addressing data imbalance, concept drift, and low-latency edge deployment. The survey further provides a comparative study of existing approaches in terms of detection capability, adaptability, computational efficiency, scalability, and deployment suitability. To fill the gap between those complementary research directions, the survey combines the literature into a unified reference architecture that merges GAN-based data augmentation, drift-aware learning, and Edge Intelligence to enable adaptive, real-time IIoT intrusion detection. Finally, we discuss key research challenges and future opportunities in autonomous, collaborative, and trustworthy IIoT cybersecurity, thus providing a practical roadmap for the development of next-generation intelligent intrusion detection systems. Full article
►▼ Show Figures

Figure 1

27 pages, 2732 KB  
Article
Federated Continual Learning for Encrypted Traffic Classification at the Network Edge Under Asynchronous Concept Drift
by Abdulrahman K. Alnaim and Ahmed M. Alwakeel
Electronics 2026, 15(17), 3995; https://doi.org/10.3390/electronics15173995 - 4 Sep 2026
Viewed by 370
Abstract
Concept drift can degrade encrypted-traffic classifiers deployed at the network edge as applications, protocols, and usage patterns evolve. This paper formulates federated continual learning under asynchronous real- and virtual drift and proposes DriftGuard, a framework combining a two-level per-node detector, selective adapter-based adaptation [...] Read more.
Concept drift can degrade encrypted-traffic classifiers deployed at the network edge as applications, protocols, and usage patterns evolve. This paper formulates federated continual learning under asynchronous real- and virtual drift and proposes DriftGuard, a framework combining a two-level per-node detector, selective adapter-based adaptation with Fisher importance masking and class-balanced replay, and drift-aware server aggregation. Level 1 detects distributional changes in learned representations, while Level 2 monitors supervised prediction errors to provide evidence consistent with decision-relevant drift before selective adaptation is activated. We further derive a convergence bound under stated assumptions that explicitly incorporates environmental variation, detection delay, and false alarms. DriftGuard is evaluated in a controlled simulation using reproducible synthetic traffic-like features under sudden, gradual, virtual-only, and recurring drift. Across five independent runs, results are reported with standard deviations, 95% confidence intervals, and paired statistical comparisons. DriftGuard maintains competitive classification accuracy while limiting forgetting of stable classes, with its clearest advantage observed under gradual asynchronous drift. Results also show that immediate adaptation using ground-truth drift states does not necessarily improve performance under the evaluated adaptation policy. The findings provide controlled methodological validation rather than evidence of production-scale deployment performance. Full article
(This article belongs to the Special Issue Cybersecurity Solutions for Intelligent Systems)
►▼ Show Figures

Figure 1

20 pages, 1633 KB  
Article
Drift-Aware Continual Generative Behavioral Detection for Zero-Day Cyberattacks: Reproducible Temporal Evaluation and SIEM-Ready Alerting
by Abdalilah Alhalangy and Galal eldin Abbas Eltayeb
Information 2026, 17(9), 852; https://doi.org/10.3390/info17090852 - 3 Sep 2026
Viewed by 239
Abstract
Zero-day cyberattacks remain difficult to detect because their behavioral characteristics are not represented in the data available during model training. In addition, intrusion detection models operating in dynamic environments are vulnerable to concept drift, while continual-learning approaches may suffer from catastrophic forgetting. Many [...] Read more.
Zero-day cyberattacks remain difficult to detect because their behavioral characteristics are not represented in the data available during model training. In addition, intrusion detection models operating in dynamic environments are vulnerable to concept drift, while continual-learning approaches may suffer from catastrophic forgetting. Many published evaluations are further affected by temporal leakage, which can lead to overly optimistic performance estimates. This study proposes DC-GenAIS, a drift-aware continual generative behavioral detection framework for adaptive intrusion detection. The framework combines concept-drift monitoring, bounded model adaptation, and drift-triggered generative replay to preserve rare attack behaviors while adapting to changing traffic distributions. To improve experimental validity, a leakage-aware temporal evaluation protocol is employed, including chronological data partitioning, train-only preprocessing, and time-separated model selection. The framework also produces calibrated risk scores and structured alert metadata through a SIEM-oriented integration interface. The proposed framework was evaluated on the CICIDS2017, UNSW-NB15, and NSL-KDD benchmark datasets under static, streaming, concept-drift, and leave-one-attack-family-out (LOAFO) evaluation settings. Results indicate improved robustness under distributional shifts, lower false-alert rates, and stronger generalization to previously unseen attack behaviors compared with representative baseline approaches. The findings further demonstrate the importance of leakage-aware temporal evaluation for obtaining reliable estimates of intrusion-detection performance. Overall, the study highlights the value of integrating drift monitoring, continual adaptation, and generative replay within a reproducible framework for behavioral intrusion detection in evolving cybersecurity environments. Full article
(This article belongs to the Section Information Security and Privacy)
►▼ Show Figures

Figure 1

19 pages, 4469 KB  
Article
Construction of an Extended-Reach Well Torque Prediction Model Based on Multi-Source Drilling Data Fusion and Analysis of Dominant Factors
by Junrui Ge, Pengbo Li, Wei Liu, Bin Cai, Yanfei Li, Xuyue Chen, Xiujin Yuan and Penglei Tang
Processes 2026, 14(17), 2801; https://doi.org/10.3390/pr14172801 - 31 Aug 2026
Viewed by 438
Abstract
Extended-reach wells contain long, highly inclined intervals in which drill-string/wellbore contact and cumulative friction evolve continuously with depth, making torque prediction strongly nonstationary. This study develops a multi-source torque-prediction framework using 5977 field samples from a deepwater extended-reach well in the East China [...] Read more.
Extended-reach wells contain long, highly inclined intervals in which drill-string/wellbore contact and cumulative friction evolve continuously with depth, making torque prediction strongly nonstationary. This study develops a multi-source torque-prediction framework using 5977 field samples from a deepwater extended-reach well in the East China Sea. To eliminate the optimistic bias caused by randomly mixing adjacent depth samples, all records were ordered by measured depth; preprocessing and feature screening were fitted only on historical data; hyperparameters were selected with forward-chaining TimeSeriesSplit; and model performance was assessed using both a fixed deep-depth stress test and expanding-window rolling-origin prediction. Training-only correlation screening and variance inflation factor analysis reduced multicollinearity before comparing ExtraTrees, XGBoost, LightGBM, BPNN, and time-aware ensemble regression. Static extrapolation to the deepest 15% of the well revealed severe distribution shift and poor long-range generalization. In contrast, 50 m rolling-forward updating produced reliable prediction: ExtraTrees achieved an MAE of 1.121, RMSE of 1.643, MAPE of 2.750%, R2 of 0.907, and Pearson correlation of 0.964, while LightGBM achieved the lowest MAE of 1.090. ExtraTrees R2 decreased from 0.927 at a 25 m horizon to 0.711 at 200 m, demonstrating progressive concept drift with prediction distance. SHAP analysis identified measured depth as the dominant predictive proxy, whereas WOB, flow rate, and RPM were more relevant to operational intervention. The revised framework therefore emphasizes leakage-free validation, adaptive updating, and separation of predictive from controllable factors rather than random-split interpolation accuracy. Full article
(This article belongs to the Special Issue Modeling, Simulation and Intelligentization in Offshore Drilling)
►▼ Show Figures

Figure 1

74 pages, 8253 KB  
Article
A Systematic Multi-Paradigm Evaluation Framework for Network Intrusion Detection in Fog-IoT Environments: Deep Learning, Transformer, and Ensemble Methods Across Deployment Tiers
by Khalil M. Abdelnaby
Symmetry 2026, 18(9), 1438; https://doi.org/10.3390/sym18091438 - 27 Aug 2026
Viewed by 287
Abstract
This paper presents the Adaptive Confidence-Gated Ensemble (ACGE) framework for Network Intrusion Detection Systems (NIDSs) in resource-heterogeneous fog-IoT deployments. No single algorithmic paradigm simultaneously achieves high minority-class detection accuracy, sub-millisecond inference latency, and generalization across heterogeneous IoT traffic at resource-constrained fog-IoT nodes. To [...] Read more.
This paper presents the Adaptive Confidence-Gated Ensemble (ACGE) framework for Network Intrusion Detection Systems (NIDSs) in resource-heterogeneous fog-IoT deployments. No single algorithmic paradigm simultaneously achieves high minority-class detection accuracy, sub-millisecond inference latency, and generalization across heterogeneous IoT traffic at resource-constrained fog-IoT nodes. To address this challenge, ACGE integrates a Sequence Transformer Encoder with LightGBM via a learned and sample-adaptive gating network trained on inter-model error complementarity, formally specified within a three-mode tiered deployment architecture. Both models execute in parallel for every sample; the gating network assigns transformer-dominant weight (α ≈ 1) to 18% of samples where attention-based processing yields the greatest architectural advantage. Under true parallel inference, ACGE latency is 1.45 ms (bounded by the transformer); the measured wall-clock latency under CPU-GPU pipeline parallelism is 1.52 ms. The framework is evaluated under 5-fold stratified cross-validation with McNemar’s significance testing on IoTID20 (primary IoT benchmark) and NSL-KDD (reproducibility anchor) and validated through zero-shot transfer on CICIoT2023 and Edge-IIoTset. Notably, the Sequence Transformer Encoder and ACGE process L = 5 consecutive flow records per decision, providing five times the information available to single-flow baseline models; approximately 57% of the transformer’s performance advantage is attributable to architectural design rather than extended input access. On IoTID20 multiclass classification, ACGE is the only evaluated configuration yielding a negative accuracy-to-macro-F1 gap (−0.51 pp), reaching 99.12 ± 0.03% accuracy and 98.67 ± 0.08% balanced accuracy, demonstrating genuine minority-class improvement. LightGBM achieves the optimal fog-tier profile (0.97 ms latency, concept drift sensitivity of −0.53 pp over three months). On Edge-IIoTset zero-shot transfer, ACGE achieves 93.89% binary accuracy and 85.78% multiclass macro-F1. Ransomware detection (12.34–66.34% F1 across all models) is identified as the primary capability gap; targeted data collection, few-shot adaptation, and federated learning are recommended as the most critical future directions. All inter-paradigm performance differences are reported as the mean ± SD and verified by McNemar’s test with Bonferroni correction. Full article
(This article belongs to the Section A: Computer Science)
►▼ Show Figures

Figure 1

20 pages, 4783 KB  
Article
An Online Updating Robust Soft Sensor for Nonstationary Industrial Processes Based on Bidirectional Long Short-Term Memory and Integrated Gradients
by Xiuliang Wu, Changchun Pan, Maoyong Cao and Kai Sun
Appl. Syst. Innov. 2026, 9(9), 175; https://doi.org/10.3390/asi9090175 - 26 Aug 2026
Viewed by 437
Abstract
In modern process industries, data-driven soft sensors have become indispensable for monitoring critical process variables that are inaccessible to direct measurement. Nevertheless, the accurate modeling of industrial processes remains challenging due to their intrinsic complexities, such as time-series behaviors, measurement outliers, redundant variables, [...] Read more.
In modern process industries, data-driven soft sensors have become indispensable for monitoring critical process variables that are inaccessible to direct measurement. Nevertheless, the accurate modeling of industrial processes remains challenging due to their intrinsic complexities, such as time-series behaviors, measurement outliers, redundant variables, and potential concept drift. Existing approaches can address subsets of these challenges but generally lack a unified mechanism that integrates robust offline modeling, variable-importance analysis, and efficient online adaptation. To address these issues, this study proposes an online-updating robust soft sensor framework based on bidirectional long short-term memory (BiLSTM) with integrated gradients (IG) and smoothed quantile loss (SQLoss). During offline modeling, a soft-sensing model is constructed using a BiLSTM, and the proposed SQLoss is introduced to reduce the influence of outliers; the IG method is then employed to evaluate the importance of input variables, enabling input variable selection. During online operation, model parameters associated with significant variables are selectively updated based on IG-derived variable importance, thereby addressing concept drift. Finally, experimental results on an industrial desulfurization process demonstrate that, compared with the best-performing competing basic learner, the proposed SQLoss-BiLSTM-IG reduces the average root mean squared error (RMSE) and mean absolute percentage error by 5.26% and 1.87%, respectively, while increasing the average correlation coefficient by 1.94%; in the online evaluation, the proposed updating strategy achieves a mean RMSE of 2.441, demonstrating its effectiveness in handling concept drift. Moreover, the analysis of key variable importance is consistent with field experience, offering valuable insights for optimizing the desulfurization control system. Full article
(This article belongs to the Section Control and Systems Engineering)
►▼ Show Figures

Figure 1

21 pages, 659 KB  
Perspective
Rethinking Continual Learning Through Self-Adaptive Learning
by Ehsan Hallaji and Roozbeh Razavi-Far
Mach. Learn. Knowl. Extr. 2026, 8(9), 257; https://doi.org/10.3390/make8090257 - 25 Aug 2026
Viewed by 452
Abstract
Continual learning has made significant progress toward enabling adaptive machine learning under evolving environments, yet real-world deployment increasingly exposes systems to persistent harsh conditions, including distributional shifts, feature evolution, delayed or scarce supervision, imbalance, noise, and recurring or novel classes. While prior research [...] Read more.
Continual learning has made significant progress toward enabling adaptive machine learning under evolving environments, yet real-world deployment increasingly exposes systems to persistent harsh conditions, including distributional shifts, feature evolution, delayed or scarce supervision, imbalance, noise, and recurring or novel classes. While prior research has largely addressed these challenges in isolation, growing environmental complexity motivates a broader rethinking of continual adaptation as a self-regulating process rather than solely a parameter update problem. Building upon the emerging framework of Self-Adaptive Learning (SAL), this perspective explores how learning systems may progress beyond reactive adaptation toward autonomous recognition, policy selection, and context-sensitive regulation of learning behavior under persistent uncertainty. Rather than proposing a specific algorithmic solution, we position SAL as a conceptual systems framework for organizing future research on resilient, long-lived machine learning systems. We discuss key implications for deployment robustness, evaluation, safety, and adaptive governance, while outlining major open challenges in developing practical self-regulating learners. By strengthening SAL as a forward-looking framework, this work aims to advance the broader conversation on machine learning systems capable of sustained autonomy in dynamic real-world environments. Full article
(This article belongs to the Section Learning)
►▼ Show Figures

Figure 1

41 pages, 1231 KB  
Article
Coverage-Constrained Selective Prediction for Short-Horizon Cryptocurrency Event Contracts via Adaptive Quantile Thresholds
by Zehui Hao, Hang Chen and Rui Qi
Algorithms 2026, 19(8), 704; https://doi.org/10.3390/a19080704 - 21 Aug 2026
Cited by 1 | Viewed by 757
Abstract
A fixed-odds contract on short-horizon price direction has a positive expected value only when its win probability exceeds the break-even rate implied by the payout ratio. A deployable predictor must also produce signals at a sufficiently stable rate. We formulate this setting as [...] Read more.
A fixed-odds contract on short-horizon price direction has a positive expected value only when its win probability exceeds the break-even rate implied by the payout ratio. A deployable predictor must also produce signals at a sufficiently stable rate. We formulate this setting as selective prediction with a coverage constraint and combine a five-seed gradient-boosting ensemble over a 90-dimensional causal feature panel with daily adaptive quantile thresholds, each estimated from the preceding 14 to 28 days of model scores, with parameters selected on training data alone. Configurations are frozen after three chronological pseudo-out-of-sample folds and evaluated on a held-out period from 1 January to 10 June 2026, and the whole procedure is then repeated on a quarterly re-freezing cadence over seven successive windows. Across BTC and ETH at 5- and 10-min horizons, with a payout of 0.8 and a 55.56% break-even rate, the models execute 10.4 to 11.0 trades per day, and all four selective win rates exceed break-even. Under a dependence-aware block bootstrap, three of four remain significant, and within a 32-test confirmatory family, two survive Holm–Bonferroni correction. Coverage stays inside the operational band in 26 of 28 re-frozen windows. Compared under one execution protocol, a fixed calibration slice drifts out of band while a trailing window does not, and adaptive conformal inference (ACI) matches the proposed rule on coverage when its step size is tuned but not otherwise, whereas an outcome-driven conformal controller reduces coverage by more than an order of magnitude. The expected value is insensitive to exchange fees, which consume under 5% of the measured edge, and sensitive to the payout term. Under matched feature sets, training pools, and coverage, most of the apparent cross-asset difference does not persist. This paper presents a proof of concept for the framework rather than making any claim about cryptocurrency predictability. Full article
►▼ Show Figures

Figure 1

25 pages, 4145 KB  
Article
H-StreamQ: An Entity-Aware Framework for Data Quality Assessment and Drift Monitoring in Electronic Health Records
by Gul Muhammad Soomro, Zaira Hassan Amur, Said Krayem, Bronislav Chramcov, Roman Jasek and Ismail Nooraddin Ismail Allahwerdi
Information 2026, 17(8), 786; https://doi.org/10.3390/info17080786 - 17 Aug 2026
Viewed by 380
Abstract
Entity-aware quality assessment may reduce false interpretations of electronic health record (EHR) data, but evidence from small, rule-aligned benchmarks cannot establish operational effectiveness. We revised H-StreamQ as a proof-of-concept framework and evaluated its laboratory component using the complete MIMIC-IV v3.1 labevents file (158,374,764 [...] Read more.
Entity-aware quality assessment may reduce false interpretations of electronic health record (EHR) data, but evidence from small, rule-aligned benchmarks cannot establish operational effectiveness. We revised H-StreamQ as a proof-of-concept framework and evaluated its laboratory component using the complete MIMIC-IV v3.1 labevents file (158,374,764 events; 313,442 patients). Ten thousand patients were sampled across laboratory-activity quintiles and split at patient level into training (6000), threshold-calibration (2000), and test (2000) groups. The independent test set contained 918,651 numeric laboratory events. Without excluding naturally alerted records, 54,788 mutually exclusive defects were introduced using subtle value shifts, unit/scale errors, mapping errors, delayed records, and patient-clustered correlated defects. Rules, a context-aware Isolation Forest, their union (Hybrid), a context-free Isolation Forest, Local Outlier Factor (LOF), and linear and radial-basis-function (RBF) One-Class support vector machines (OCSVMs) were compared at a threshold fixed by a 2.5% calibration alert budget. Patient-cluster bootstrap intervals and event-micro and patient-macro results were reported. Rules alone achieved the highest event-micro F1-score (0.637; 95% confidence interval [CI] 0.547–0.722), followed by Hybrid (0.576; 0.484–0.668) and RBF One-Class SVM (0.559; 0.433–0.670). Hybrid increased recall over rules by only 0.004 (95% CI 0.003–0.006) while reducing F1 by 0.061 and increasing the background-alert rate by 0.015. Context conditioning did not improve aggregate Isolation Forest performance. In six batch-level drift simulations, an exponentially weighted moving average (EWMA) and a fixed-window monitor detected 97–100% and 98–100% of changes, respectively, whereas a custom Hoeffding adaptive-window detector was more conservative and often missed smaller or recurrent changes. These results support H-StreamQ as an explainable research framework, not as a validated clinical or production system. Patient-macro F1, which weights every patient equally, was substantially lower than event-micro F1 for every method (rules 0.395 versus 0.637; Hybrid 0.320 versus 0.576), indicating that event-level performance is weighted towards high-activity patients. Precision and F1 are computed relative to injected synthetic labels and are not clinically adjudicated estimates. The entity-aware architecture spans patients, admissions, diagnoses, transfers, and dictionaries, but the quantitative detection benchmark evaluates the numeric laboratory component only; other entities are used for linkage and contextual attachment and are audited descriptively rather than evaluated against labels. Full article
(This article belongs to the Special Issue Data Mining and Healthcare Informatics)
►▼ Show Figures

Graphical abstract

26 pages, 685 KB  
Article
Systemically Mediated Leadership in AI-Enabled Organizations: A Socio-Technical Systems Theory of Distributed Judgment, Feedback, and Accountability
by Haris Alibašić
Systems 2026, 14(8), 984; https://doi.org/10.3390/systems14080984 - 13 Aug 2026
Cited by 1 | Viewed by 691
Abstract
Artificial intelligence (AI) increasingly mediates leadership-relevant judgment through models, dashboards, metrics, decision-support systems, and autonomous agents. This conceptual article develops a socio-technical systems theory of systemically mediated leadership, defined as a nested system-level condition and recurrent process configuration through which human actors, AI [...] Read more.
Artificial intelligence (AI) increasingly mediates leadership-relevant judgment through models, dashboards, metrics, decision-support systems, and autonomous agents. This conceptual article develops a socio-technical systems theory of systemically mediated leadership, defined as a nested system-level condition and recurrent process configuration through which human actors, AI systems, organizational routines, governance institutions, and affected stakeholders jointly produce and revise direction, meaning, consequential judgment, legitimacy, and accountability through recursive feedback. A problem-driven conceptual synthesis was updated through 3 August 2026. A structured discovery pass yielded 97 candidate records; 85 sources were retained after relevance screening, citation chaining, concept mapping, and comparison of eight candidate mechanism families. Four proposed qualification conditions jointly define the construct within the present framework: AI mediation, leadership relevance, distributed judgment, and recurrent institutional embedding. Five mechanism families explain transformations in responsibility, legitimacy, control, attention, and feedback timing: moral delegation, interpretive laundering, ceremonial oversight, metric-driven sensemaking, and ethical latency. A causal-loop model specifies justificatory reinforcement, capability atrophy, power insulation, and accountable correction. Their relative dominance produces three ideal-type dynamic regimes: accountable adaptation, stabilized trade-offs, and destructive drift. The theory predicts that organizations using equally accurate models may produce divergent leadership and accountability outcomes because their feedback, power, and oversight architectures differ. Responsible AI leadership thus depends on system architecture and contestable institutional practice, not leader intention, formal human approval, or model accuracy alone. Full article
►▼ Show Figures

Figure 1

21 pages, 3394 KB  
Article
Hybrid Intrusion Detection System with Real-Time Concept Drift Detection for Enhanced IoT Security
by Muath A. Obaidat, Meryem Abouali and Aneeza Shakeel
Sensors 2026, 26(16), 5117; https://doi.org/10.3390/s26165117 - 12 Aug 2026
Viewed by 723
Abstract
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication [...] Read more.
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication bandwidth, making conventional security mechanisms difficult to deploy consistently at scale. Intrusion detection systems (IDSs) provide an important defensive layer; however, many machine-learning-based IDSs are developed under static assumptions and may experience performance degradation as traffic distributions evolve due to firmware changes, device onboarding, protocol updates, user behavior variation, or adaptive attacks. This paper presents a hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring. In the experimental pipeline, Isolation Forest is trained exclusively on benign traffic to ensure that the anomaly detector models normal behavior rather than an attack-dominated training distribution. The evaluation uses a large-scale chronologically sampled subset of the CICIoT2023 dataset containing 3,890,621 records while preserving the natural class distribution of 2.35% benign traffic and 97.65% attack traffic. The chronological 80/20 train/test split is established first at the file level, followed by systematic sampling within each split to reduce the risk of leakage across the evaluation boundary. On the 746,094-record test set, the proposed hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, and a false positive rate of 4.77%. The corresponding confusion matrix contains TN = 16,683, FP = 836, FN = 1205, and TP = 727,370, yielding 95.23% specificity and 97.53% balanced accuracy. Standalone Random Forest marginally outperformed the hybrid model in raw accuracy and false positive rate; therefore, the contribution of the proposed framework is centered on deployment-oriented anomaly monitoring, drift awareness, and generalization rather than absolute superiority in static classification metrics. A leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training showed that the hybrid model detected 85.26% of the unseen attack-family samples, compared with 85.18% for Random Forest alone and 7.05% for Isolation Forest alone. These findings provide initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability. The framework is therefore positioned as a competitive IDS that combines supervised detection with anomaly monitoring and concept drift awareness for deployment-oriented IoT security. Full article
(This article belongs to the Special Issue Sensor Security and Beyond)
►▼ Show Figures

Figure 1

27 pages, 2255 KB  
Article
An Online Drift-Adaptive Framework for Semantic Representation and Classification of HPC Jobs
by Xiaotao Xi, Gongju Guo and Jianxiang Gu
Electronics 2026, 15(15), 3419; https://doi.org/10.3390/electronics15153419 - 2 Aug 2026
Viewed by 309
Abstract
With the rapid advancement of computing technologies, high-performance computing (HPC) systems have continued to expand in scale and have been widely applied across various domains. To improve resource utilization, existing studies commonly employ offline-trained models based on historical resource usage data to classify [...] Read more.
With the rapid advancement of computing technologies, high-performance computing (HPC) systems have continued to expand in scale and have been widely applied across various domains. To improve resource utilization, existing studies commonly employ offline-trained models based on historical resource usage data to classify HPC jobs as compute-bound or memory-bound. However, such methods typically rely on static historical data and struggle to adapt to dynamically changing workloads over time, resulting in degraded prediction performance and reduced stability under concept drift. To address this issue, this paper proposes an online drift-adaptive framework for HPC job semantic representation and classification (DA-HJSC). The framework employs a hybrid mechanism that combines offline semantic learning with online dynamic adaptation. Specifically, an offline classification model is first trained using semantic representations of job descriptions together with user historical behavioral features (UHBF). During the inference stage, an exponentially weighted moving average (EWMA) mechanism is further introduced to dynamically fuse the output probabilities of the classification model, thereby producing the final classification results for HPC jobs. Experimental results on the publicly available F-DATA dataset covering the period from 1 May 2023 to 30 April 2024 demonstrate that DA-HJSC consistently improves HPC job classification performance across different pre-trained language models and base classifiers, achieving a maximum F1macro (overall) score of 0.9272. Compared with the corresponding baselines, DA-HJSC reduces the number of low- and medium-performance days by up to 11 and 35 days, respectively, across all experimental configurations. Overall, the DA-HJSC framework achieves an effective balance among classification accuracy, performance stability, and online adaptability, providing a solution with practical deployment potential for dynamic HPC workload classification. Full article
►▼ Show Figures

Figure 1

32 pages, 5046 KB  
Article
Scalable Machine Learning on IoT Edge Devices Through Adaptive Coreset Selection with Differentiable Greedy Sampling
by Fatema A. Albalooshi and M. R. Qader
Technologies 2026, 14(8), 476; https://doi.org/10.3390/technologies14080476 - 2 Aug 2026
Viewed by 419
Abstract
The rapid growth of Internet of Things (IoT) devices generates high-dimensional, high-velocity data streams that demand real-time machine learning (ML) inference under strict hardware constraints. We propose the Adaptivecoreset Selection Engine (ACS-Engine), a unified framework for adaptive, differentiable, and resource-aware coreset selection on [...] Read more.
The rapid growth of Internet of Things (IoT) devices generates high-dimensional, high-velocity data streams that demand real-time machine learning (ML) inference under strict hardware constraints. We propose the Adaptivecoreset Selection Engine (ACS-Engine), a unified framework for adaptive, differentiable, and resource-aware coreset selection on streaming IoT data. ACS-Engine introduces three tightly integrated innovations: (i) Differentiable Greedy Sampling (DGS), which relaxes discrete subset selection via Gumbel-Softmax reparameterization to enable end-to-end gradient-based optimization; (ii) Entropy-Aware Regularization (EAR), which promotes coreset diversity and provides implicit concept drift detection through a self-calibrating entropy threshold; and (iii) Resource-Aware Memory Management (RAMM), which dynamically adjusts the target coreset size based on real-time hardware telemetry—available memory, CPU utilization, remaining energy, and sampling frequency. Evaluated on eight real-world IoT datasets spanning three heterogeneous edge platforms, ACS-Engine achieves 15× memory reduction and a 20% energy efficiency improvement while retaining 98% of full-dataset accuracy, with a per-sample latency of 2 ms that satisfies real-time edge deployment requirements. Full article
►▼ Show Figures

Figure 1

22 pages, 65019 KB  
Article
Reliability Analysis of Agricultural Foundation Models Under Distribution Shift
by Shayan Nejadshamsi, Yuanyuan Zhang, Brock Porth, Shadi Zaki, Lysa Porth and Vahab Khoshdel
Remote Sens. 2026, 18(14), 2416; https://doi.org/10.3390/rs18142416 - 21 Jul 2026
Viewed by 541
Abstract
Recent geospatial foundation models (GFMs) have shown strong performance for crop yield prediction across regions and spatial scales, but operational deployment requires reliable performance under distribution drift. In agricultural settings, distribution drift may arise through temporal, label, concept, domain, or representation shifts, each [...] Read more.
Recent geospatial foundation models (GFMs) have shown strong performance for crop yield prediction across regions and spatial scales, but operational deployment requires reliable performance under distribution drift. In agricultural settings, distribution drift may arise through temporal, label, concept, domain, or representation shifts, each of which can alter the relationship between incoming data and model behavior. This paper extends the previously published Fine-Tuning Agricultural Regression Models (FARM) framework, which adapts the Prithvi-EO-2.0-600M Vision Transformer for dense canola yield estimation over the Canadian Prairies, by introducing a systematic drift monitoring and reliability analysis pipeline. The proposed framework measures Mahalanobis, cosine, and Euclidean distances in both input and latent spaces. These distances characterize distributional shifts and allow us to evaluate their relationship with prediction error. Experiments on county-level and 30 m precision-agriculture datasets, spanning a normal growing season (2022) and a drift growing season (2021), show that both input-space and latent-space distances provide a useful signal of drift with latent-space metrics offering the clearest separation of anomalous conditions. At the same time, the results show that large drift scores do not necessarily correspond to large prediction errors. Some out-of-distribution samples are predicted accurately, while some in-distribution samples incur high error. These findings identify a critical gap between drift detection and uncertainty estimation and demonstrate that distributional distance alone is insufficient for operational reliability assessment. The results therefore motivate reliability-aware monitoring strategies for agricultural foundation models that combine drift detection with explicit uncertainty or error estimation in non-stationary environments. Full article
►▼ Show Figures

Figure 1

Back to TopTop