Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (2,733)

Search Parameters:
Keywords = intrusion detection

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
19 pages, 2326 KB  
Article
A Task-Specific Autoencoder–CatBoost Framework for Intrusion Detection in Imbalanced IIoT
by Soumia Felkaoui, Faiza Titouna, Djalila Boughareb and Yacine Lafifi
Future Internet 2026, 18(10), 526; https://doi.org/10.3390/fi18100526 - 30 Sep 2026
Abstract
Industrial Internet of Things (IIoT) intrusion detection remains challenging because of class imbalance, rare attacks, and heterogeneous evaluation protocols. This study proposes a modular intrusion-detection framework based on task-specific autoencoder representation learning and downstream CatBoost classification. The binary branch learns a 16-dimensional representation [...] Read more.
Industrial Internet of Things (IIoT) intrusion detection remains challenging because of class imbalance, rare attacks, and heterogeneous evaluation protocols. This study proposes a modular intrusion-detection framework based on task-specific autoencoder representation learning and downstream CatBoost classification. The binary branch learns a 16-dimensional representation from benign traffic and combines it with reconstruction error, whereas the multiclass branch uses a separate 24-dimensional representation learned from malicious traffic. On ML-EdgeIIoT, the extended five-fold group-aware binary evaluation achieved ROC-AUC = 0.9925, AP = 0.9981, and F1 = 0.9829, with a benign FPR of 0.1113. A reconstruction-error ablation increased F1 from 0.9800 to 0.9829 and reduced FPR from 0.1311 to 0.1113. The complete 14-class evaluation achieved macro-F1 = 0.6175 and macro-AUC = 0.9549, while the 15-label cascade reached strict end-to-end attack-type success = 0.6584. External validation on WUSTL-IIoT-2021 yielded a five-label macro-F1 of 0.9408 and strict success of 0.9993. These results support the task-specific modular design while highlighting the remaining difficulty of fine-grained attack attribution and false-alarm reduction. Full article
►▼ Show Figures

Figure 1

49 pages, 897 KB  
Article
DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection
by Büşra Günay and Mehmet Yavuz Yağcı
Sensors 2026, 26(19), 6200; https://doi.org/10.3390/s26196200 - 30 Sep 2026
Abstract
Intrusion Detection Systems (IDSs) are essential for securing Internet of Things (IoT) and Internet of Medical Things (IoMT) environments, yet most machine learning-based IDSs assume that training and testing data follow similar distributions. In practice, domain shifts arising from differences in device characteristics, [...] Read more.
Intrusion Detection Systems (IDSs) are essential for securing Internet of Things (IoT) and Internet of Medical Things (IoMT) environments, yet most machine learning-based IDSs assume that training and testing data follow similar distributions. In practice, domain shifts arising from differences in device characteristics, communication protocols, and traffic patterns can substantially increase false positive rates (FPRs), reducing operational reliability. This study proposes DEA-IDS (Drift-aware, Explainable and Adaptive Intrusion Detection System), a unified framework integrating SHAP-based explainability, statistical drift analysis via the Kolmogorov–Smirnov statistic and Wasserstein distance, drift-aware stable feature selection, and few-shot adaptation, evaluated on a CICIoT2023-to-CICIoMT2024 cross-domain transfer scenario. Under a leakage-free protocol in which drift statistics and few-shot samples are drawn exclusively from the target training split, DEA-IDS reduces FPR from 0.5468 to 0.0004 while maintaining an F1-score of 0.9944; threshold-, sample-size-, and feature-selection-control sensitivity analyses confirm this reduction reflects drift-aware stable feature selection rather than test-set leakage or dimensionality reduction alone. A per-attack-family analysis shows this improvement is concentrated in high-volume flood-style attacks and is accompanied by reduced detection of ARP spoofing, malformed-MQTT, and reconnaissance traffic, reported here as an explicit limitation. These results demonstrate that explicitly modeling feature stability before adaptation improves operational robustness for cross-domain intrusion detection in heterogeneous IoT–IoMT environments. Full article
(This article belongs to the Section Internet of Things)
►▼ Show Figures

Figure 1

23 pages, 793 KB  
Article
Flow Exporter Provenance as a Major Confounder in Cross-Dataset IoT Intrusion Detection
by Murad A. Rassam and Mahfoudh Alasaly
Mathematics 2026, 14(19), 3549; https://doi.org/10.3390/math14193549 - 30 Sep 2026
Abstract
Machine-learning intrusion detection for the Internet of Things (IoT) routinely exceeds 99% accuracy on single datasets but fails when transferred to new networks or flow exporters. We formalize five failure modes, define a 23-feature canonical schema, and adapt three datasets (CICIoT2023, TON_IoT, Bot-IoT) [...] Read more.
Machine-learning intrusion detection for the Internet of Things (IoT) routinely exceeds 99% accuracy on single datasets but fails when transferred to new networks or flow exporters. We formalize five failure modes, define a 23-feature canonical schema, and adapt three datasets (CICIoT2023, TON_IoT, Bot-IoT) to build a full six-pair transfer matrix across three classifiers, each with three random seeds. Random forest attains the highest mean AUC (0.740), yet its balanced accuracy collapses to chance (0.50–0.51) exclusively on CICFlowMeter-sourced pairs while remaining strong (0.72–0.87) on Zeek- and Argus-sourced pairs. This exporter-dependent collapse is reproduced across structurally unrelated classifiers, establishing it as our central finding. A controlled synthetic test confirms that CICFlowMeter’s directional heuristic destroys variance (up to 104 reduction) and causes a small, consistent transfer cost (+0.004 AUC), though full degradation requires compounded effects. Aggregate distributional distance does not predict transfer success (r = −0.17), ruling out a simple divergence explanation. Prior correction provides the largest ablation gain. Source-domain coverage is necessary but not sufficient for transfer, and we observed no universal sample-count threshold. Flow exporter provenance emerges as a major upstream confounder and a directly implicated contributing mechanism, though exporter identity is confounded with dataset identity and is not established as the sole determinant of cross-dataset performance. Full article
►▼ Show Figures

Figure 1

18 pages, 3077 KB  
Article
Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model
by Mohamed Ali Fakri, Abdellah Najid, Rachid Ben Said and Nezha El Idrissi
Future Internet 2026, 18(10), 521; https://doi.org/10.3390/fi18100521 - 29 Sep 2026
Abstract
Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work [...] Read more.
Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget. Full article
(This article belongs to the Special Issue Anomaly and Intrusion Detection in Networks)
►▼ Show Figures

Figure 1

18 pages, 1256 KB  
Article
Conventional and Quantum Feature Selection and Federated Learning Applications for Anomaly Detection in IoT Healthcare Networks
by Emre Tokgoz and Fatemeh Mosaiyebzadeh
Electronics 2026, 15(19), 4469; https://doi.org/10.3390/electronics15194469 - 29 Sep 2026
Abstract
Privacy is a major concern in the Internet Healthcare of Things (IoHT), where threat actors may intrude systems to access personally identifiable data. Federated Learning (FL) is a well suited Machine Learning (ML) approach to preserve confidentiality, availability, and integrity in such settings [...] Read more.
Privacy is a major concern in the Internet Healthcare of Things (IoHT), where threat actors may intrude systems to access personally identifiable data. Federated Learning (FL) is a well suited Machine Learning (ML) approach to preserve confidentiality, availability, and integrity in such settings during data analysis. In this work, we introduce a Network of Quantum ML (N-QML) approach for IoHT intrusion detection, integrating quantum PCA (QPCA) with Quantum FL (QPCA+QFL), tested on a subset of the data set WUSTL-EHMS-2020 using classical and quantum computing experiments across three seeds, compared against conventional ML (CML) on three feature dimensions. Among CML techniques, the integration of PCA and ANN (PCA+ANN) attained the best mean accuracy, 76.6%, using two features. Among QML techniques, QPCA+QNN achieved the best centralized accuracy, 74.4%, when two features are used, while PCA+SVM outperformed QPCA+QSVM using ten features (70.1% versus 66.9%). As a result of the study, during federation of the quantum model, accuracy was realized to be reduced steadily from 62.9% to 54.7% as dimensionality changed and highest variance attainment occurred at the smallest dimension; this is a pattern that was not previously documented under matched, multi-seed validation. We attribute this to FedAvg interacting with the loss landscape of quantum-derived features on small client partitions, contributing this finding and the framework as groundwork for quantum-aware federated aggregation. Full article
►▼ Show Figures

Figure 1

20 pages, 8288 KB  
Article
DeepShield-IoT: A Hybrid AI and Lotka–Volterra Model for Efficient IoT Intrusion Detection Systems
by Mohamed Bachar, Azeddine Khiat and Kamal El Guemmat
Future Internet 2026, 18(10), 519; https://doi.org/10.3390/fi18100519 - 28 Sep 2026
Abstract
Internet of Things devices introduce significant security challenges caused by their heterogeneous and resource-constrained nature in many sectors, such as healthcare, industry, education, and agriculture. Intrusion detection systems (IDSs) serve a key role in identifying malicious activities in such environments; traditional approaches cannot [...] Read more.
Internet of Things devices introduce significant security challenges caused by their heterogeneous and resource-constrained nature in many sectors, such as healthcare, industry, education, and agriculture. Intrusion detection systems (IDSs) serve a key role in identifying malicious activities in such environments; traditional approaches cannot often capture dynamic interactions and temporal correlations in network traffic. In this research, we propose a novel hybrid IDS technique utilizing Long Short-Term Memory (LSTM) networks in conjunction with Lotka–Volterra (LV) dynamic modeling. The LSTM component is employed to learn temporal patterns and estimate system states from IoT traffic, while the LV model captures the dynamic interaction between normal and malicious behavior. We introduce a mathematically based decision mechanism on an anomaly score for effective classification. The model’s results on DataSense: CIC IIoT dataset 2025 achieve an accuracy of 99.85%, outperforming other models, and have a detection time of 47 ms and a reduced-complexity algorithm. These results highlight the effectiveness of combining artificial intelligence with dynamic system modeling for intrusion detection in IoT environments, providing a promising direction for future research in intelligent cybersecurity systems. Full article
(This article belongs to the Section Cybersecurity)
►▼ Show Figures

Graphical abstract

37 pages, 4821 KB  
Article
A Dual-Stream Multi-Feature Approach to Whistle Classification Across Species for Passive Acoustic Monitoring
by Doyinsola Olatinwo, Mae Seto, Bruce Martin and Mark Thomas
Mach. Learn. Knowl. Extr. 2026, 8(10), 301; https://doi.org/10.3390/make8100301 - 28 Sep 2026
Abstract
Passive acoustic monitoring (PAM) has emerged as a non-intrusive method for detecting and classifying marine mammal vocalizations in near real time. Yet reliable classification from PAM remains challenging, particularly for whistles—transient, narrowband calls whose rapid temporal variations are difficult to capture from conventional [...] Read more.
Passive acoustic monitoring (PAM) has emerged as a non-intrusive method for detecting and classifying marine mammal vocalizations in near real time. Yet reliable classification from PAM remains challenging, particularly for whistles—transient, narrowband calls whose rapid temporal variations are difficult to capture from conventional spectral analyses alone. Consequently, existing approaches often rely on species-specific classifiers, which require extensive data collection, annotation, and computational resources, limiting their application across diverse taxa. To overcome these limitations, this study introduces a unified multi-feature framework that integrates (i) temporal, spectral, and cepstral (TSC) features and (ii) spectrogram representations for whistle classification across multiple marine mammal taxa. In addition, to fully exploit these complementary representations, a novel dual-stream architecture comprising a bidirectional long short-term memory (BiLSTM) stream and a time-distributed convolutional neural network (TCNN) + BiLSTM stream is designed to learn from both feature types, enabling richer characterization of whistle dynamics. The framework was evaluated using five-repetition group-aware Monte Carlo cross-validation (MCCV), with recording groups kept mutually exclusive across the training, validation, and test partitions within each repetition. Across beluga, dolphins, narwhal, killer whale, and pilot whale whistles, as well as noise, the proposed model achieved a macro F1 score of 0.944 ± 0.004, outperforming the LSTM (0.918 ± 0.009), CNN (0.712 ± 0.037), and ANN (0.538 ± 0.134) baselines. Paired statistical comparisons also showed higher accuracy for the proposed model than the three baselines across the five MCCV repetitions, with the corresponding differences remaining significant after Holm–Bonferroni correction. These results demonstrate the effectiveness of integrating complementary acoustic representations with bidirectional sequence modeling for robust multi-species whistle classification across unseen recording groups. The proposed framework provides an effective approach for marine mammal whistle classification in PAM applications. Full article
(This article belongs to the Section Learning)
►▼ Show Figures

Figure 1

46 pages, 1798 KB  
Article
Lightweight Relation-Aware Graph Neural Networks for Network Threat Detection in the Social Internet of Things
by Yifan Qin and Zheng Zhao
Symmetry 2026, 18(10), 1623; https://doi.org/10.3390/sym18101623 - 28 Sep 2026
Abstract
Network threat detection in the Internet of Things must exploit typed relations between devices: a device with unremarkable flow statistics may still be compromised relative to its ownership, co-location, and social ties. Existing graph-based intrusion detectors discard relation type, while lightweight detectors compress [...] Read more.
Network threat detection in the Internet of Things must exploit typed relations between devices: a device with unremarkable flow statistics may still be compromised relative to its ownership, co-location, and social ties. Existing graph-based intrusion detectors discard relation type, while lightweight detectors compress tabular rather than graph models. This paper presents Light-SIoT-GAD, a lightweight relation-aware graph detector that treats typed relations as first-class input. The model learns one scalar weight per relation, shares a small basis across relation transforms so that each additional relation type costs only a handful of mixing coefficients rather than a full weight matrix, and combines supervised feature selection, bounded neighbour sampling, and 8-bit post-training quantisation for gateway deployment. A dual-track evaluation isolates typed aggregation on a real 16,216-device SIoT relation graph with injected anomalies and tests attack detection on three labelled NetFlow v2 corpora against classical, deep tabular, and graph baselines, including cross-corpus transfer and ablations. Light-SIoT-GAD matches or exceeds the strongest untyped graph baselines on all three corpora, reaching an AUPRC of 0.9986 with 73,962 parameters, substantially fewer than the unshared R-GCN; on the sparsest corpus a gradient-boosted tabular ensemble still ranks better, which bounds the claim to graphs that carry usable structure. Whether the gain comes from the relation semantics or merely from having per-relation parameters is tested directly: permuting the relation labels leaves the dense corpora unchanged to four decimals and costs 0.0083 AUPRC only on the sparsest one, so the typed advantage is real there and is a capacity effect elsewhere. On the social track, where the anomalies are injected under a stated protocol rather than observed, removing message passing collapses AUPRC from 0.9990 to 0.4869 under that same injection, isolating propagation over the relation graph as the source of the gain; this track measures whether relational structure carries signal, not accuracy against real SIoT attacks. The quantised model occupies 85.4 KB at 14.38 ms per 1000 edges on CPU. The learned relation gates are shown to be identified only up to a per-relation rescaling, and a leave-one-relation-out intervention finds no relation of the SIoT taxonomy to be load-bearing under the injection protocol, so the social track supports the typed parameterisation and not a ranking of the relations. Full article
►▼ Show Figures

Figure 1

27 pages, 2491 KB  
Article
Adaptive-Augmented Cyber-Physical Detection of Evasive DNS Tunneling Attacks in Electric Vehicle Charging and Vehicle-to-Grid Networks
by Krutthika Hirebasur Krishnappa and Sudhir Trivedi
World Electr. Veh. J. 2026, 17(10), 503; https://doi.org/10.3390/wevj17100503 - 28 Sep 2026
Abstract
Electric vehicle (EV) charging stations and vehicle-to-grid (V2G) systems depend on outbound Domain Name System (DNS) resolution for firmware retrieval, backend discovery, and fleet synchronization, making DNS tunneling an attractive covert command-and-control and data-exfiltration channel in charging infrastructure. Machine learning detectors trained on [...] Read more.
Electric vehicle (EV) charging stations and vehicle-to-grid (V2G) systems depend on outbound Domain Name System (DNS) resolution for firmware retrieval, backend discovery, and fleet synchronization, making DNS tunneling an attractive covert command-and-control and data-exfiltration channel in charging infrastructure. Machine learning detectors trained on lexical and statistical DNS features achieve excellent in-distribution accuracy, yet they are rarely stress-tested against adaptive adversaries that deliberately reshape query characteristics toward benign traffic. This paper presents a station-independent evaluation framework and an adaptive-augmented, cyber-physical detection architecture for evasive DNS tunneling in EV charging and V2G networks. Using a 200-station synthetic dataset that couples 24 DNS features with 16 EV/Open Charge Point Protocol (OCPP)/V2G telemetry features and 14 cross-modal consistency features, we evaluate every detector over ten repeated grouped station-level splits and across three attack regimes: an adaptive-strength sweep (β = 0.25–0.95) of the interpolation mechanism used in training, a separately held-out constraint-aware adaptive mechanism excluded from all training and model selection, and multiplicative perturbation of the physical-anchor telemetry at relative scales of 5–20%. Under strong interpolation-based evasion at the training strength (β = 0.90), detectors relying on DNS evidence retain almost no detection capability at their original operating point (mean F1 = 0.041 ± 0.023), although part of their threshold-free ranking ability survives, and recalibrating the decision threshold alone does not repair the collapse. We propose a safe EV-anchored fusion detector that treats physical telemetry as a protected anchor, hardens a cross-modal branch with adaptive examples drawn only from training stations, and admits DNS evidence only through a bounded, validation-selected correction. Across the ten splits, the proposed detector sustains F1 = 0.909 ± 0.013 at β = 0.90 and F1 = 0.923 ± 0.016 under the held-out mechanism, retaining approximately 94–96% of its original F1 of 0.964 ± 0.006 at a false-positive rate near 5.5% (about 55 false alarms per 1000 benign windows), and it degrades gracefully (F1 ≥ 0.911) when the anchor telemetry is perturbed at up to 20% relative scale. The results indicate that anchoring detection in physical-side telemetry, with bounded and adaptively hardened cross-modal evidence, provides consistent performance across the evaluated repeated station partitions and is computationally feasible under the evaluated conditions. Full article
(This article belongs to the Section Charging Infrastructure and Grid Integration)
►▼ Show Figures

Figure 1

25 pages, 7701 KB  
Article
ASIF: A Resource-Aware Selective Network Traffic Inspection Framework Integrating Certificate Screening, Targeted Decryption, and Feature Fusion
by Liangbin Yang, Lulu Liu, Xiaomei Liu, Jing Bai and Lizhen Liu
Network 2026, 6(4), 82; https://doi.org/10.3390/network6040082 - 28 Sep 2026
Abstract
The widespread use of TLS in IoT and networked systems increases inspection cost while restricting direct access to payload content. This paper presents the Adaptive Secure Inspection Framework (ASIF), a resource-aware selective network traffic inspection framework that coordinates certificate-based routing, authorized targeted decryption, [...] Read more.
The widespread use of TLS in IoT and networked systems increases inspection cost while restricting direct access to payload content. This paper presents the Adaptive Secure Inspection Framework (ASIF), a resource-aware selective network traffic inspection framework that coordinates certificate-based routing, authorized targeted decryption, known-signature matching, and learned flow classification. ASIF contains three components: (1) a Certificate Screening Module (CSM), which applies configured checks of root trust, chain integrity, and leaf-certificate validity as an early routing signal; (2) a Targeted Decryption and Signature Matching Module (TDSMM), which directs certificate-suspicious traffic to authorized Mitmproxy interception and Snort inspection; and (3) an Attentive Feature Fusion Network (AFFN), which combines global and local representations for network-flow classification. The evaluation covers controlled certificate cases, selective-decryption overhead, known-signature matching, learned classification on three intrusion datasets, a supplementary VPN/non-VPN task, held-out attack families, and the integrated pipeline. The intrusion-dataset labels do not establish that every flow is encrypted. Several models obtain near-ceiling scores under the balanced grouped protocol, while AFFN achieves a macro-F1 of 0.639 ± 0.149 on the supplementary ISCX VPN/non-VPN task and does not outperform all baselines. Across held-out attack families, recall averages 0.527 ± 0.466, indicating strong family dependence. In the controlled end-to-end experiment, complete ASIF decrypts 50% of requests and reduces mean latency from 278.78 to 164.19 ms/request relative to full decryption, while malicious-class recall decreases to 0.500 and macro-F1 to 0.733 because valid-certificate malicious traffic bypasses deeper inspection. These results characterize ASIF as a resource-aware selective inspection strategy with explicit coverage limitations rather than a universal encrypted-malicious-traffic detector. Full article
►▼ Show Figures

Figure 1

24 pages, 3910 KB  
Article
Mechanical Performance, Crack Resistance and Microstructural Evolution of Engineered Cementitious Composites Reinforced with Multiscale Hybrid Fibers
by Yuxin Huang, Chonggen Pan, Danna Su, Baolin Peng and Chuansheng Xiong
J. Compos. Sci. 2026, 10(10), 510; https://doi.org/10.3390/jcs10100510 - 27 Sep 2026
Viewed by 3
Abstract
To further enhance the mechanical performance and early-age crack resistance of engineered cementitious composites (ECC), an ECC-based multiscale hybrid-fiber system was investigated. The system used carbon nanotube-modified polyethylene (M-PE) fibers as the primary reinforcement together with polypropylene (PP) and basalt (BF) fibers. The [...] Read more.
To further enhance the mechanical performance and early-age crack resistance of engineered cementitious composites (ECC), an ECC-based multiscale hybrid-fiber system was investigated. The system used carbon nanotube-modified polyethylene (M-PE) fibers as the primary reinforcement together with polypropylene (PP) and basalt (BF) fibers. The effects of fiber hybridization on compressive strength, uniaxial tensile behavior, flexural performance, early-age crack resistance, and microstructure were systematically evaluated. Mixtures retaining at least 60% M-PE exhibited a clear post-cracking strain-hardening response, whereas lower M-PE fractions led to crack localization and loss of strain hardening. At 28 days, BF-0 (1.5 vol.% M-PE + 0.3 vol.% BF) reached compressive, tensile, and flexural strengths of 85.3, 7.35, and 36.38 MPa, respectively. A six-indicator entropy-weighted TOPSIS evaluation identified BF-0 as the best-balanced mixture among the investigated groups. Increasing PP or BF content improved early-age plate crack resistance; BF-5 (1.5 vol.% BF) achieved the highest crack reduction coefficient of 67.98%, with a nominal total crack area of 27.6 mm2. Scanning electron microscopy (SEM) observations were used only as qualitative morphological evidence, whereas mercury intrusion porosimetry (MIP) revealed quantitative pore-structure trends and X-ray diffraction (XRD) indicated that fiber hybridization did not generate new detectable crystalline phases. The results reveal the performance trade-offs among strength, ductility, and early-age crack control in multiscale hybrid-fiber cementitious composites. Full article
(This article belongs to the Section Composites Applications)
►▼ Show Figures

Figure 1

41 pages, 1711 KB  
Article
CA-AFiD: A Context-Aware Adaptive Federated Intrusion Diagnosis for Heterogeneous IoT–Fog–Cloud Environments
by Ashutosh Shankhdhar, Vanitha Murugesan, Thenmozhi Elumalai, Samia Kouki, Sumendra Yogarayan and Prabu Kaliyaperumal
Future Internet 2026, 18(10), 510; https://doi.org/10.3390/fi18100510 - 26 Sep 2026
Viewed by 64
Abstract
The increasing heterogeneity of Internet of Things (IoT) environments makes intrusion diagnosis challenging because device behaviours, traffic patterns, and attack distributions can vary across deployment conditions, while data-locality requirements limit centralized access to network data. This study proposes CA-AFiD (Context-Aware Adaptive Federated Intrusion [...] Read more.
The increasing heterogeneity of Internet of Things (IoT) environments makes intrusion diagnosis challenging because device behaviours, traffic patterns, and attack distributions can vary across deployment conditions, while data-locality requirements limit centralized access to network data. This study proposes CA-AFiD (Context-Aware Adaptive Federated Intrusion Diagnosis), a framework designed to support adaptive and interpretable intrusion diagnosis across IoT–Fog–Cloud environments. CA-AFiD combines behaviour-aware representation learning using Transformer, BiLSTM, and attention mechanisms with a context-aware adaptive ensemble that adjusts learner contributions according to behavioural complexity, attack density, and device context. Federated learning is used to coordinate model updates across distributed Fog nodes without sharing raw traffic data, while attention-based interpretation, SHAP feature attribution, and ATT&CK-oriented contextualization provide explanatory information for diagnostic decisions. The framework was evaluated on the CIC-IoT-DIAD 2024 dataset across device-aware learning, imbalanced attack diagnosis, temporal sensitivity, federated learning, explainability, and operational-efficiency scenarios. Under the controlled homogeneous evaluation, the complete CA-AFiD framework achieved a 99.22% F1-score, while the heterogeneous evaluation achieved an overall 99.03% F1-score across the evaluated attack categories. Across the four evaluated minority attack categories, the average F1-score was 98.79%. Under federated learning, the global model achieved an average device-identification accuracy of 98.90% and an average anomaly-diagnosis F1-score of 98.90% across the participating Fog nodes, while ATT&CK mapping achieved 88–98% coverage. These results demonstrate the potential of CA-AFiD to provide adaptive, data-local, and interpretable intrusion diagnosis for heterogeneous IoT–Fog–Cloud environments. Full article
28 pages, 3265 KB  
Article
XGB-AGMoE: A Validation-Adaptive XGBoost-Anchored Granular Mixture-of-Experts Framework for Multi-Class Intrusion Detection in IoMT WiFi–MQTT Traffic
by Madallah Alruwaili, Fawaz J. Alruwaili and Mahmood Mohamed
Sensors 2026, 26(19), 6096; https://doi.org/10.3390/s26196096 - 25 Sep 2026
Viewed by 38
Abstract
The Internet of Medical Things (IoMT) environment is based on WiFi and MQTT communication, which results in highly imbalanced intrusion-detection data with a high degree of heterogeneity. In this study, XGB-AGMoE is proposed, a validation-adaptive XGBoost-anchored Granular Mixture-of-Experts framework that combines the quantile-derived [...] Read more.
The Internet of Medical Things (IoMT) environment is based on WiFi and MQTT communication, which results in highly imbalanced intrusion-detection data with a high degree of heterogeneity. In this study, XGB-AGMoE is proposed, a validation-adaptive XGBoost-anchored Granular Mixture-of-Experts framework that combines the quantile-derived granular descriptors and experts of CatBoost, LightGBM, XGBoost, class-wise post hoc sigmoid calibration, leakage-free logistic-regression stacking, and an XGBoost-anchored probability fusion stage. The official test partition was set aside for final evaluation after disjoint development subsets were used for preprocessing, calibration, stacking, and anchor selection. The value of 0.80 was chosen for the anchor weight for the calibrated XGBoost, and 0.20 was chosen for the calibrated stack for the canonical seed-42 experiment. The resulting model achieved 0.993887 accuracy, 0.993681 weighted-F1, 0.851256 macro-F1, 0.999634 macro-ROC-AUC, and 0.921352 macro-PR-AUC on a 150,000-record official test sample. The Brier score, negative log-likelihood, and expected calibration error were 0.007531, 0.015309, and 0.001775, respectively. Across seeds 42, 52, and 62, accuracy was 0.9926±0.0012 and macro-F1 was 0.8238±0.0251. Recall was higher for the top denial of service classes and lower for DDoS Publish Flood and Recon VulScan. The results corroborate with expert anchoring and validation-controlled evaluation; they also highlight that there are fusion gains that depend on the data split and that they should be evaluated in the light of robust component baselines. Full article
(This article belongs to the Special Issue Advances in Intrusion Detection for IoT Sensor Networks)
►▼ Show Figures

Figure 1

26 pages, 7748 KB  
Article
VRGAN: A Deep Generative Framework for Unsupervised Anomaly Detection in Multivariate Time-Series Data
by Joung Min Choi, Connor L. Brown, Amy Pruden and Liqing Zhang
Appl. Sci. 2026, 16(19), 9556; https://doi.org/10.3390/app16199556 - 25 Sep 2026
Viewed by 42
Abstract
Time-series anomaly detection holds value across various research fields and application domains, serving purposes such as fault diagnosis, identification of unexpected system intrusions, or signaling the onset of new disease outbreaks. To identify anomalous timepoints in a practical manner, unsupervised learning methods have [...] Read more.
Time-series anomaly detection holds value across various research fields and application domains, serving purposes such as fault diagnosis, identification of unexpected system intrusions, or signaling the onset of new disease outbreaks. To identify anomalous timepoints in a practical manner, unsupervised learning methods have been introduced. These methods leverage normality’s feature representations to reconstruct data, determining anomalies through the calculation of anomaly scores based on reconstruction errors. Still, recent approaches assume the use of a normal dataset for model training, implicitly necessitating true anomaly labels. Furthermore, the absence of guidelines for determining anomaly thresholds hinders the easy application of current detection methods in diverse research fields. In this paper, we propose VRGAN, a deep generative anomaly detection framework designed for unsupervised multivariate time-series analysis. VRGAN stands out by eliminating the need for assumptions or true label information. Through the training of variational recurrent neural network and GAN modules on a training dataset masked for anomaly candidates, VRGAN reconstructs the dataset based on learned normal data distribution and calculates anomaly scores to identify anomalies. Evaluation on seven benchmark datasets demonstrates VRGAN’s performance improvement compared with recent unsupervised anomaly detection methods. The proposed model is further tested on a time-series metagenomic dataset, showcasing its applicability in fully unsupervised settings for wastewater-based surveillance to monitor and track patterns of antibiotic resistance genes that are prevalent among bacteria carried by a given human community. Full article
(This article belongs to the Section Computing and Artificial Intelligence)
►▼ Show Figures

Figure 1

28 pages, 752 KB  
Systematic Review
Cybersecurity and Privacy in AI-Enabled Agricultural IoT Ecosystems: A Systematic Review of Threats, Safeguards, and Resilience Gaps
by Emmanuel Kojo Gyamfi, Jess Kropczynski, Jacques Bou Abdo, Joseph S. Johnson, Mustapha Awinsongya Yakubu, Anthony K. Tsetse and Gertrude Kaneah Abagale
Algorithms 2026, 19(10), 827; https://doi.org/10.3390/a19100827 - 25 Sep 2026
Viewed by 90
Abstract
Agricultural Internet of Things (IoT) ecosystems increasingly connect sensors, drones, edge devices, and cloud platforms to support precision farming, yet cybersecurity, privacy, and the real-world readiness of proposed safeguards remain fragmented across the literature. This study systematically reviewed cybersecurity threats, privacy concerns, AI-driven [...] Read more.
Agricultural Internet of Things (IoT) ecosystems increasingly connect sensors, drones, edge devices, and cloud platforms to support precision farming, yet cybersecurity, privacy, and the real-world readiness of proposed safeguards remain fragmented across the literature. This study systematically reviewed cybersecurity threats, privacy concerns, AI-driven and traditional safeguards, and evidence gaps in agricultural IoT research published between 2015 and 2025. Following the Kitchenham and Charters methodology, 103 studies were selected from 2535 records retrieved across five databases. STRIDE and LINDDUN were retrospectively applied as complementary frameworks for threat and privacy classification. Because the coding scheme was multi-label, reliability was assessed at the category level using presence/absence decisions on a 20-study sample and observed agreement ranged from 75% to 95% for STRIDE and 95% to 100% for LINDDUN, with interpretable Cohen’s κ values ranging from 0.348 to 0.794 and 0.875 to 1.000, respectively. All included studies also underwent quality appraisal and a supplementary ecological-validity assessment. Denial-of-service, tampering, and spoofing were the most frequently reported threats, concentrated at the device, network, and cloud layers, while the edge layer remained underexamined. AI- and machine-learning-based intrusion detection and privacy-preserving methods such as federated learning emerged as prominent safeguards, but adversarial manipulation of agricultural AI models received limited attention. Privacy research remained oriented toward confidentiality, with 90.3% of studies referencing no applicable regulatory framework. Most importantly, only 8 of 103 studies (7.8%) received a High ecological-validity rating, showing how rarely the evidence base is grounded in real agricultural field conditions. The review identifies field-grounded evaluation, adversarially robust AI, privacy governance, and cyber resilience as priorities for future agricultural IoT security research. Full article
►▼ Show Figures

Figure 1

Back to TopTop