Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (209)

Search Parameters:
Keywords = security orchestration

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
48 pages, 12096 KB  
Article
A Simulation-Based Quantum-Synchronized Ephemeral Encryption Framework for QKD-Secured IoT Networks with Transformer-Based Cyber-Quantum Attack Detection
by Mohammad Sameer Aloun, Ala Mughaid, Bashar S. Khassawneh and Mahmoud AlJamal
Computation 2026, 14(9), 207; https://doi.org/10.3390/computation14090207 - 7 Sep 2026
Abstract
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer [...] Read more.
This paper presents a simulation-based cyber-quantum Internet of Things (IoT) security framework for modeling, securing, and detecting attacks in QKD-secured IoT communication environments. The proposed framework integrates heterogeneous IoT traffic generation, gateway-assisted routing, edge processing, QKD key-pool management, Quantum-Synchronized Ephemeral Encryption (Q-SEE), cross-layer adversarial attack injection, and AI-based multiclass detection. Unlike conventional IoT intrusion datasets that mainly capture packet- or flow-level abnormalities, the generated dataset represents the joint behavior of IoT sessions, network delay, queue pressure, QKD state, key consumption, encryption-mode transitions, ciphertext metadata, and cyber-quantum risk. A Python/SimPy/NetworkX simulation was developed using 80 IoT devices, 3 gateways, 2 edge servers, 4 cyber-quantum control-plane nodes, and 1 adversarial orchestrator. The final simulation produced 46,351 records with 76 features covering normal traffic, five traditional IoT attacks, and six novel cyber-quantum attacks, including QKD key-pool starvation, QBER camouflage, false QKD-health injection, encryption downgrade induction, queue–key coupling, and multi-vector cyber-quantum orchestration. Q-SEE adaptively selects among QKD-OTP, QKD-synchronized AES-256 ephemeral mode, PQC fallback, degraded mode, and blocked mode according to QBER, secret key rate, key availability, device criticality, downgrade pressure, and risk. A leakage-aware Quantum-Aware Kolmogorov–Arnold Network (QKAN) was then trained using deployable cyber-quantum evidence. The final nonrisk QKAN achieved 98.79% test accuracy, 98.61% macro-F1, 98.85% weighted-F1, and 99.78% macro-AUC, demonstrating effective detection of traditional and cyber-quantum IoT attacks. Full article
(This article belongs to the Section Computational Intelligence)
40 pages, 7091 KB  
Article
TrustEdge-V2X: Deployment-Aware Edge Intelligence for V2X/IoV Intrusion and Misbehavior Detection
by Hesham A. Sakr, Mina Shenouda, Nadeem Sarwar, Ibrahim Elewah, Vitalii Lapin and Maria Lapina
Computers 2026, 15(9), 577; https://doi.org/10.3390/computers15090577 - 2 Sep 2026
Viewed by 208
Abstract
Most studies on vehicular cybersecurity focus on classification accuracy but fail to evaluate the applicability of the models to the edge. This paper proposes a secure edge intelligence framework for V2X/IoV intrusion and misbehavior detection, called TrustEdge-V2X, which is deployment-aware. The framework combines [...] Read more.
Most studies on vehicular cybersecurity focus on classification accuracy but fail to evaluate the applicability of the models to the edge. This paper proposes a secure edge intelligence framework for V2X/IoV intrusion and misbehavior detection, called TrustEdge-V2X, which is deployment-aware. The framework combines dataset-role qualification, attack taxonomy, AI model benchmarking, feature-budget analysis, deployment ranking based on EdgeScore, offline risk-aware orchestration, external validation, robustness testing, explainable AI, repeated-run statistical analysis and ablation studies. Three datasets are assigned different experimental roles: VeReMi_NextGen is used for core V2X/VANET misbehavior detection, CICIoT2023 is used for supporting edge/IoT intrusion experiments and HCRL_CarHacking is used for external IoV/CAN validation. LightGBM outperformed all other AI models in EdgeScore (0.9383), F1-score (0.9878), MCC (0.9758), and inference latency (0.009419 ms per sample) across all eight AI models and six scenarios on VeReMi_NextGen for binary detection. In five dataset-task cases, the accuracy-best model was different from the EdgeScore-best model, which is the most important point to note: the best model in terms of accuracy is not necessarily the best model in terms of EdgeScore. Compact feature subsets were competitive, and robustness testing demonstrated an average F1 decrease of 0.1423 when tested under stress. The orchestration layer was found to be beneficial for the tasks, but it did not always perform better than the best fixed policy. As a whole, TrustEdge-V2X offers a systematic approach to the assessment and selection of vehicular cybersecurity models based on the operational and deployment conditions, not only on the classification accuracy. Full article
Show Figures

Figure 1

39 pages, 1803 KB  
Article
A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity
by Carl L. Anderson
Information 2026, 17(9), 846; https://doi.org/10.3390/info17090846 - 31 Aug 2026
Viewed by 327
Abstract
Recent industry reporting indicates that meantime to exploit has become negative in several observed datasets, implying that exploitation may occur before patch availability for some classes of vulnerabilities. Adversarial use of artificial intelligence (AI) is a documented accelerant of this trend. This paper [...] Read more.
Recent industry reporting indicates that meantime to exploit has become negative in several observed datasets, implying that exploitation may occur before patch availability for some classes of vulnerabilities. Adversarial use of artificial intelligence (AI) is a documented accelerant of this trend. This paper addresses the operational problem that follows in healthcare cybersecurity: the volume and velocity of vulnerability disclosure exceed human analytic capacity, which leads practitioners to under-prioritize, or defer entirely, individual Common Vulnerabilities and Exposures (CVEs) at precisely the moment their risk is rising. The study develops and evaluates a purposeful information technology artifact intended to resolve this problem within a mid-sized United States healthcare system. The artifact is a three-application automated CVE intelligence, prioritization, and remediation-tracking pipeline implemented in Microsoft Azure Logic Apps, integrating the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities (KEV) catalog, the Microsoft Security Response Center (MSRC) CVRF API, Microsoft Defender, Claroty xDome, Microsoft Security Copilot, and ServiceNow, and operationalizing the four risk factors codified in CISA Binding Operational Directive (BOD) 26-04. In naturalistic operations across six CISA Weekly Vulnerability Summary bulletins, the artifact processed 12,855 unique CVE references and reduced them to 1640 environment-relevant findings, an 87.2 percent exposure-first reduction, before expensive per-CVE enrichment and ticketing. The findings indicate that governed automation demonstrably increases CVE coverage, reduces low-value enrichment volume, and produces a deterministic, BOD 26-04-conformant prioritization that is fully traceable in the SharePoint tracker, where every assigned tier is reconstructable from its KEV, ransomware, xDome-exploited, EPSS, CVSS, and exposure inputs. Because no controlled before-and-after time-and-motion study was conducted and no independent ground-truth exploitation labels were collected, three distinct outcomes remain future validation targets rather than demonstrated results: analyst productivity, comparative predictive prioritization accuracy against independent ground-truth exploitation outcomes, and remediation speed. The contribution reported here is therefore operational scale, coverage, and auditable prioritization traceability, not measured improvement in analyst decision-making or patient-safety outcomes. Full article
(This article belongs to the Special Issue Digital Privacy and Security, 3rd Edition)
Show Figures

Graphical abstract

18 pages, 1353 KB  
Article
Secure Adaptive Resource Orchestration for Cloud Management with Deep Reinforcement Learning: An Extended Evaluation on Real Traces
by Usaid Alibrahem, Priyadarsi Nanda and Hoang Dinh
Electronics 2026, 15(17), 3916; https://doi.org/10.3390/electronics15173916 - 31 Aug 2026
Viewed by 175
Abstract
Cloud platforms must hold utilisation and latency targets while demand shifts and attack traffic arrive together. Reactive threshold scaling meets neither pressure, and an autoscaler blind to attacks funds the load an adversary requested. Recent work shows adversaries can drive this loop into [...] Read more.
Cloud platforms must hold utilisation and latency targets while demand shifts and attack traffic arrive together. Reactive threshold scaling meets neither pressure, and an autoscaler blind to attacks funds the load an adversary requested. Recent work shows adversaries can drive this loop into economic denial of sustainability, so the controller sits inside the attack surface. No prior orchestrator couples workload forecasting, unsupervised anomaly detection and learned scaling in one loop, and none reports multi-seed significance testing. This article extends SARO, presented at IMCOM 2026, to close that gap. We formalise the problem as a Markov decision process with a corrected multi-objective reward, and replace the tabular agent with SARO-DQN, a continuous-state controller trained by three-step Double Q-learning. Across ten held-out days and five seeds, SARO-DQN reaches the highest composite reward (200.1 ± 16.5) and the highest utilisation (68.2%) against eight alternatives, and every reward difference is significant under Welch tests (p<0.05). Ablations attribute 23.6 reward points to the detector (p=1.4×106) and 8.9 to the forecast (p=0.016). On UNSW-NB15, the detector attains an AUC of 0.888. Two principles follow. Detectors must consume exogenous traffic-shape signals, and detector and policy must be trained as a coupled system. Full article
Show Figures

Figure 1

45 pages, 5316 KB  
Review
The Regulatory Army of Plant Defense: Transcription Factors in the War for Plant Immunity
by José Ribamar Costa Ferreira-Neto, Agnes Angélica Guedes de Barros, Ana Luíza Trajano Mangueira de Melo, Lidiane Lindinalva Barbosa Amorim, Madson Allan de Luna Aragão, João Pacífico Bezerra-Neto, Laiane Silva Maciel, Manassés Daniel da Silva, Paulo Vitor Galdino da Silva and Ana Maria Benko-Iseppon
Int. J. Mol. Sci. 2026, 27(16), 7315; https://doi.org/10.3390/ijms27167315 - 16 Aug 2026
Viewed by 349
Abstract
Plant diseases impose major constraints on global crop productivity and pose a major threat to food security. Here, we review transcription factors (TFs) as central orchestrators of plant defense, consolidating recent advances in how these regulators connect pathogen perception to immune signaling, transcriptional [...] Read more.
Plant diseases impose major constraints on global crop productivity and pose a major threat to food security. Here, we review transcription factors (TFs) as central orchestrators of plant defense, consolidating recent advances in how these regulators connect pathogen perception to immune signaling, transcriptional reprogramming, and durable defense responses. Initially, we combined a literature-based synthesis with a natural language processing (NLP) analysis of 1647 PubMed abstracts published between 2021 and 2026 to map dominant and underexplored TF families associated with plant immunity. WRKY, MYB, AP2/ERF, bHLH/MYC, and NAC dominated the recent literature, whereas families such as NF-Y, Trihelix, PLATZ, TCP, and GRAS represent emerging regulatory actors. Across these and other families, TFs integrate pattern- and effector-triggered immunity, hormone crosstalk, chromatin dynamics, non-coding RNA regulation, post-translational modifications, and metabolic remodeling, in addition to cell-type-specific expression. Further evidence indicates that pathogens frequently manipulate TFs to weaken host defense, underscoring their central position in plant molecular physiology and plant-pathogen coevolution. The data emphasize that TF function is context-dependent and influenced by multilayered regulation, cell type, pathogen lifestyle, and host genetic background. This review provides a framework for understanding TFs in plant immune control and highlights TF-centered strategies for engineering durable crop resistance, along with future challenges. Full article
Show Figures

Figure 1

15 pages, 4123 KB  
Data Descriptor
A Device-Level IoT Network Traffic Dataset with Distributed Capture and Non-IID Characteristics
by Othmane Belarbi, Theodoros Spyridopoulos, Eirini Anthi, Omer Rana, Pietro Carnelli and Aftab Khan
Data 2026, 11(8), 207; https://doi.org/10.3390/data11080207 - 14 Aug 2026
Viewed by 445
Abstract
The development of intrusion detection and network security solutions for securing Internet of Things (IoT) networks is constrained by the limited availability of representative network security datasets. Many existing datasets rely on centralised traffic collection and do not capture the non-Independent and Identically [...] Read more.
The development of intrusion detection and network security solutions for securing Internet of Things (IoT) networks is constrained by the limited availability of representative network security datasets. Many existing datasets rely on centralised traffic collection and do not capture the non-Independent and Identically Distributed (non-IID) characteristics inherent to edge environments. To address this limitation, this work presents a device-level IoT network dataset generated using the open-source Gotham testbed, a virtualised smart city environment. Network traffic is collected in a distributed manner at the interfaces of 78 heterogeneous IoT devices operating across multiple protocols, including MQTT, CoAP, and RTSP. The dataset comprises over 31.8 million packet-level records, each described by 22 features. It includes both benign traffic and multiple attack classes, namely Network Scanning, Brute Force, Infection, Denial of Service (DoS), and Command and Control (C&C) Communication. Ground-truth labels are assigned using a deterministic process based on orchestration logs. The dataset preserves device-level traffic distributions and captures non-IID characteristics without artificial partitioning. It is publicly available and can be used to support reproducible evaluation of intrusion detection approaches and network analysis tasks in both centralised and distributed learning settings. Full article
(This article belongs to the Section Information Systems and Data Management)
Show Figures

Figure 1

10 pages, 1511 KB  
Proceeding Paper
Cyber Response Automation with Dedicated AI Agents
by Stanimir Kabaivanov and Veneta Markovska
Eng. Proc. 2026, 150(1), 106; https://doi.org/10.3390/engproc2026150106 - 3 Aug 2026
Viewed by 183
Abstract
Proactive cyber security has moved from being an innovative approach to an essential requirement for business success, especially considering the large number of new tools and technologies that organizations need to learn and use. In this paper, we discuss and demonstrate the possibility [...] Read more.
Proactive cyber security has moved from being an innovative approach to an essential requirement for business success, especially considering the large number of new tools and technologies that organizations need to learn and use. In this paper, we discuss and demonstrate the possibility of automating important cyber security and immediate response steps with the use of dedicated artificial intelligence agents. We focus on local-first solutions that are able to keep sensitive data private and at the same time fit well with existing data protection policies and infrastructure. Using a minimalist AI agent addressing a local large language model, we experiment with skills aimed at running cyber security tools and processing their output in support of cyber incident response. Full article
Show Figures

Figure 1

29 pages, 4578 KB  
Article
Designing an AI-Assisted Cyber Threat Intelligence Framework for Industry 4.0: A Human-in-the-Loop Design Science Approach
by Majed Albarrak and Sandeep Jagtap
Appl. Sci. 2026, 16(15), 7646; https://doi.org/10.3390/app16157646 - 1 Aug 2026
Viewed by 439
Abstract
The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly [...] Read more.
The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments. Full article
(This article belongs to the Special Issue Recent Trends in Cybersecurity, Privacy, and Digital Trust)
Show Figures

Figure 1

25 pages, 1006 KB  
Article
Network Orchestration Framework Design Using AI-Driven Automation and Cybersecurity
by Tasneem Annahdi, Albandari Alsumayt and Majid Alshammari
Future Internet 2026, 18(8), 394; https://doi.org/10.3390/fi18080394 - 27 Jul 2026
Viewed by 399
Abstract
This paper addresses human error in network orchestration systems and the high cost and resource requirements of integrating artificial intelligence (AI) for network orchestration. It proposes a framework for implementing an AI decision-maker and automation. Data are fed into the AI decision-maker to [...] Read more.
This paper addresses human error in network orchestration systems and the high cost and resource requirements of integrating artificial intelligence (AI) for network orchestration. It proposes a framework for implementing an AI decision-maker and automation. Data are fed into the AI decision-maker to trigger designated automation robots’ tasks or notify IT specialists to gradually implement automated robots, ensuring efficient resource use, reducing costs, and enhancing productivity. We evaluated the proposed method in a simulation with genuinely uncertain outcomes, across 20 independent runs: the AI decision-maker reached 78.3% accuracy against an estimated 79.1% achievable ceiling, and the proposed framework reduced operational cost by 61.4 ± 0.7% relative to fully manual operation—the best of six operating policies in the training environment—while an explicit sensitivity guard, rather than the learned model, accounts for the absence of security incidents; under distribution shift, the framework retains 43.2 ± 0.8% savings, second only to a hand-tuned rule-based router that requires environment-specific threshold calibration. However, the proposed method requires an IT specialist to implement it properly, and the AI model’s accuracy depends on the amount of input data. In the end, we recommend that future work conduct a study focused on AI decision-makers, test the proposed method on real-world companies, and implement AI decision-makers across various departments to cover a broader range of the company’s systems. Full article
(This article belongs to the Special Issue AI-Driven Security, Privacy, and Trust for the Internet of Things)
Show Figures

Graphical abstract

23 pages, 953 KB  
Review
Large Language Models for Future Internet Ecosystems: A Taxonomy-Based Review of Smart IoT, Edge Intelligence, and Autonomous AI
by Sahar Ahmadzadeh, Gayathri Karthick and Tariq Alsafi
Future Internet 2026, 18(8), 393; https://doi.org/10.3390/fi18080393 - 26 Jul 2026
Viewed by 805
Abstract
Large Language Models (LLMs) are emerging as key enablers of Future Internet ecosystems, supporting intelligent, adaptive, and context-aware services across distributed cyber-physical environments. Beyond traditional natural language processing, LLMs are increasingly integrated into Smart Internet of Things (SIoT) systems to enable semantic interoperability, [...] Read more.
Large Language Models (LLMs) are emerging as key enablers of Future Internet ecosystems, supporting intelligent, adaptive, and context-aware services across distributed cyber-physical environments. Beyond traditional natural language processing, LLMs are increasingly integrated into Smart Internet of Things (SIoT) systems to enable semantic interoperability, edge intelligence, multimodal interaction, and autonomous service orchestration. This paper presents a taxonomy-based review of LLM architectures, training paradigms, deployment strategies, and emerging applications within Future Internet infrastructures. The review classifies existing studies by deployment environment, architecture, training strategy, accessibility, and application scope, and analyses the role of LLMs in intelligent IoT environments, with emphasis on edge-based reasoning, agentic AI, human-centric automation, and context-aware decision-making. Key challenges are examined, including scalability, inference latency, privacy, trustworthiness, security, hallucination, and energy efficiency in resource-constrained environments. A comparative analysis of representative LLMs is presented, based on deployment feasibility, multimodal capability, accessibility, and suitability for distributed intelligent services. The originality of the review lies in conceptualizing LLMs as cognitive middleware that provides semantic, reasoning, and coordination capabilities across Smart IoT infrastructures. Finally, future research directions are highlighted, including decentralized AI architectures, digital twins, the Model Context Protocol, retrieval-augmented generation, multimodal sensing, and autonomous agent-based ecosystems. Full article
(This article belongs to the Special Issue Future and Smart Internet of Things)
Show Figures

Figure 1

18 pages, 316 KB  
Article
Hardware Accountability for Energy-Efficient Stream-Oriented Data-Plane Processing in 5G/6G Edge Telecommunication Nodes
by Yurii Herman, Oleh Krulikovskyi, Dmytro Vovchuk and Vjaceslavs Bobrovs
Electronics 2026, 15(15), 3263; https://doi.org/10.3390/electronics15153263 - 24 Jul 2026
Viewed by 334
Abstract
Continuous stream-oriented data-plane processing in 5G/6G edge nodes increases the energy and latency cost of CPU-centered execution. This paper studies this boundary on an Intel Cyclone V SoC FPGA and proposes Hardware Accountability: a partitioning discipline in which Linux performs supervisory control while [...] Read more.
Continuous stream-oriented data-plane processing in 5G/6G edge nodes increases the energy and latency cost of CPU-centered execution. This paper studies this boundary on an Intel Cyclone V SoC FPGA and proposes Hardware Accountability: a partitioning discipline in which Linux performs supervisory control while high-rate payload processing remains in programmable logic. The evaluation uses the Strumok stream cipher, adopted as the Ukrainian national standard DSTU 8845:2019, as a secure fronthaul/payload workload with XOR- and shift-dominated logic. On the evaluated USB 2.0/Cortex-A9/Linux path, the software-driven stream approaches saturation near 20 MSPS. In contrast, the RTL core reaches 9.6 Gbps at 150 MHz and occupies less than 6% of the available logic. Quartus Prime vectorless power analysis estimates 24.00 mW dynamic power for the RTL computational core, corresponding to approximately 2.5 pJ/bit. Control-plane measurements show P99 orchestration jitter below 1 ms under Spatial Isolation, conservative full context reloads near 1290 per second, and more than 7200 shadow-register context/state update operations per second. A design-space exploration then projects an 83.2 Gbps multi-core data path when external DDR traffic is avoided through internal stream aggregation and elastic buffering. Full article
Show Figures

Figure 1

30 pages, 22181 KB  
Article
Next-Gen Security Operation Center Services for Critical National Infrastructures
by Alexios Lekidis, Yagmur Yigit, Leandros A. Maglaras, Konstantinos Karantzalos and George Spanoudakis
Electronics 2026, 15(15), 3248; https://doi.org/10.3390/electronics15153248 - 23 Jul 2026
Viewed by 526
Abstract
Critical National Infrastructures (CNIs) have evolved over the last years through the digitization of their services, which simultaneously led to an increase of their threat surface. Meanwhile, the exponential rise of Artificial Intelligence (AI) technologies has given the means to adversaries to perform [...] Read more.
Critical National Infrastructures (CNIs) have evolved over the last years through the digitization of their services, which simultaneously led to an increase of their threat surface. Meanwhile, the exponential rise of Artificial Intelligence (AI) technologies has given the means to adversaries to perform targeted attacks against high impact systems as the ones found in CNIs. Current regulation directives as the NIS2 or the Cyber Resilience Act (CRA) focus on the presence of Security Operation Centers (SOCs), which include different security technologies for the detection and response to cyber-attacks. Nevertheless, such baseline SOCs do not provide the ability to perform a coordinated and orchestrated detection and response cycle for existing cyber threats, but also do not provide proactive measures for zero-day threats. To this end, this paper presents a new approach for automating the orchestration of the incident lifecycle through next-generation SOC services able to detect/mitigate sophisticated attacks against CNIs, but also implement proactive detection and mitigation measures against zero-day threats. The approach is presented through a reference model for intelligent SOC components that additionally allow tackling the challenges in traditional SOC environments, such as fatigue for the multiple alerts for the SOC analysts and the time required for investigating triaging and investigating incidents. Full article
(This article belongs to the Special Issue Feature Papers in Networks: 2025–2026 Edition)
Show Figures

Figure 1

52 pages, 5807 KB  
Article
AI-Enabled Digital Trust, Ethics, and Safety-Risk Signal Analysis in Contact-Based Sport Communities: ESG-Oriented Text Mining and Sentiment Classification of Judo and Brazilian Jiu-Jitsu Platform Discourse
by Kyong Jun Park, Jong Kyun Choi and Hyung Jong Na
Electronics 2026, 15(14), 3207; https://doi.org/10.3390/electronics15143207 - 21 Jul 2026
Viewed by 465
Abstract
Existing platform-monitoring methods for sport communities commonly rely on isolated descriptive text-mining outputs or general sentiment scores; they rarely integrate interpretable ESG issue coding with class-sensitive risk detection and provide limited support for auditable, privacy-conscious analysis of safety, ethics, and institutional trust. These [...] Read more.
Existing platform-monitoring methods for sport communities commonly rely on isolated descriptive text-mining outputs or general sentiment scores; they rarely integrate interpretable ESG issue coding with class-sensitive risk detection and provide limited support for auditable, privacy-conscious analysis of safety, ethics, and institutional trust. These limitations motivate a multi-stage framework that converts heterogeneous platform discourse into complementary structural and evaluative signals. Conceptually, digital trust is treated as the focal governance outcome; ethics and safety are substantive domains of concern; ESG provides the bounded classification and response ontology; and early warning denotes a prototype, human-reviewed weak-signal triage concept rather than incident prediction or a deployed security-monitoring system. Using 377,700 cleaned Korean-language comments on judo and Brazilian Jiu-Jitsu (BJJ) collected from Naver News and YouTube between 2010 and 2025, the framework combines n-gram analysis, LDA topic modeling, CONCOR network analysis, bounded ESG discourse classification, and three-class sentiment prediction. The individual analytical algorithms are established; the methodological contribution lies in their governance-oriented orchestration through a bounded ESG/non-ESG coding gate, a study-specific index layer, and a human-reviewed pathway from aggregate discourse signals to proportionate review. The analytical workflow identifies issue salience, relational topic structures, ESG dimensions, sentiment risk, legitimacy balance, and platform-specific risk concentration while excluding personally identifiable information. Empirically, social and governance concerns dominate the corpus, and governance-related negative sentiment consistently exceeds social-risk sentiment, highlighting rule transparency, coach ethics, misinformation, platform reputation, and institutional response as central trust-risk domains. Cell-weighted sensitivity checks preserved the governance-over-social and YouTube-over-Naver risk ordering, although the pooled salience estimate remained sensitive to the rapid expansion of BJJ discourse on YouTube. The fine-tuned KLUE-BERT model achieved a Macro-F1 of 0.838 and a negative-class F1 of 0.862, outperforming the strongest baseline, Text-CNN (Macro-F1 = 0.791), by 0.047 absolute Macro-F1 points (approximately 6.0% relative improvement). These findings support the feasibility of a batch-oriented, human-reviewed prototype for prioritizing aggregate discourse patterns. They do not establish the effectiveness of a real-time security-monitoring, incident-detection, or operational early-warning system. Full article
Show Figures

Figure 1

14 pages, 242 KB  
Proceeding Paper
A Survey on Federated Learning and Edge Computing: Applications, Advantages, and Challenges
by Theodora Nevrataki, Panagiotis Radoglou-Grammatikis, Antonios Sarigiannidis, Panagiotis Sarigiannidis and George F. Fragulis
Eng. Proc. 2026, 143(1), 39; https://doi.org/10.3390/engproc2026143039 - 20 Jul 2026
Viewed by 533
Abstract
Federated learning (FL) and edge computing are transformative technologies that enhance privacy, efficiency, and real-time intelligence for distributed machine learning across diverse edge device networks. FL enables devices to collaboratively train models locally, so sensitive data remains on each device, ensuring privacy and [...] Read more.
Federated learning (FL) and edge computing are transformative technologies that enhance privacy, efficiency, and real-time intelligence for distributed machine learning across diverse edge device networks. FL enables devices to collaboratively train models locally, so sensitive data remains on each device, ensuring privacy and regulatory compliance (like GDPR and HIPAA). Edge computing complements FL by bringing data processing closer to sources such as IoT sensors and smartphones, which reduces latency, bandwidth use, and dependence on cloud servers. This architecture is vital for smart cities, healthcare, industry, and autonomous systems, supporting real-time decision-making. The review details challenges such as resource heterogeneity, communication constraints, security risks, and management complexity, while highlighting opportunities for scalable orchestration, decentralized architectures, and blockchain integration. Together, FL and edge computing create a robust paradigm for scalable, privacy-aware distributed intelligence across multiple domains. Full article
27 pages, 2050 KB  
Article
Intelligent Attack Detection in Blockchain-Enabled Multi-Cloud Systems: A Systematic Review and SOC-LLM-Augmented Architecture Proposal
by Adam Koty Abbass Ahmat and Habiba Chaoui
Computers 2026, 15(7), 456; https://doi.org/10.3390/computers15070456 - 17 Jul 2026
Viewed by 467
Abstract
This paper presents a systematic literature review examining how blockchain technologies can enhance the security and performance of multi-cloud systems. Multi-cloud architectures offer resilience, scalability, and flexibility; however, they also pose complex security challenges related to APIs, service-level agreements (SLAs), orchestration, and authentication. [...] Read more.
This paper presents a systematic literature review examining how blockchain technologies can enhance the security and performance of multi-cloud systems. Multi-cloud architectures offer resilience, scalability, and flexibility; however, they also pose complex security challenges related to APIs, service-level agreements (SLAs), orchestration, and authentication. The promise of blockchain technology to improve the security and transparency of numerous applications, including cloud storage systems, has attracted considerable attention in recent years. Much research has focused on decentralized storage in cloud environments, spanning supply chains, FinTech, healthcare, and education. Still, the integration of blockchain with the cloud and its potential to enhance security and performance warrant an in-depth study. Using the PRISMA methodology, a structured search was conducted across six major scientific databases, including IEEE, ACM Digital Library, ScienceDirect, Scopus, Web of Science, and IJIMAI. Twenty-four primary papers published between 2019 and 2025 were selected for analysis after clear inclusion and exclusion criteria were applied. This review examines the security dimensions in multi-cloud environments—architectural vulnerabilities, API security, authentication, orchestration and automation vulnerabilities, SLAs, and cybersecurity compliance issues—in relation to blockchain technology. Based on the identified gaps, we propose a SOC-LLM-augmented security architecture that integrates blockchain-based evidence integrity, statistical anomaly detection, machine learning, large language models, and autonomous AI agents to enable intelligent attack detection and response. The proposed framework introduces specialized agents for detection, correlation, threat intelligence retrieval, blockchain evidence validation, explanation generation, and response planning. The analysis shows that integrating SOC-LLM capabilities with blockchain can move multi-cloud security from passive auditability toward proactive, explainable, and human-in-the-loop cyber defense. Finally, this paper discusses open challenges, including LLM hallucination, data scarcity, real-time scalability, evaluation standardization, and trustworthy deployment in critical multi-cloud infrastructures. The study’s conclusion highlights research gaps and suggests future lines of inquiry concerning scalable blockchain architectures and the incorporation of AI for proactive cloud security monitoring. Full article
(This article belongs to the Section Blockchain Infrastructures and Enabled Applications)
Show Figures

Figure 1

Back to TopTop