Computer Science and Mathematics

Sort by

Article
Computer Science and Mathematics
Computer Networks and Communications

Muhammad Ahsan

,

Muzammil Hussain

,

Abdulazaz Albalawi

,

Waseem Iqbal

Abstract: Wi-Fi 6 has shifted the wireless bottleneck from the access point to the wired uplink, creating a hybrid bottleneck capped first by client-side frame aggregation and then by the wired last hop’s fixed capacity. TCP Small Queues (TSQ) and TCP Pacing (TP) mitigate sender-side bufferbloat, but their default settings limit the frame aggregation Wi-Fi 6 needs to operate optimally, hampering congestion control algorithms (CCAs) such as Bottleneck Bandwidth and Round-Trip Time (BBR) in maintaining optimal congestion windows (CWND). We propose BBR-TAS (TSQ-Adaptive Pacing Shift), a BBR-v3-derived algorithm that adapts the TSQ pacing shift across the STARTUP and steady-state phases to align sender-side queue occupancy with Wi-Fi 6’s frame aggregation needs. BBR-TAS was evaluated against BBR-v3 and TCP CUBIC on a physical Wi-Fi 6 testbed running a stable Linux kernel on both client and server, using Flent to measure throughput, induced latency, and TCP RTT across a combinatorial sweep of pacing shift configurations under single-flow upload, Real-Time Response Under Load (RRUL), and RTT-fairness conditions. In single-flow upload tests, BBR-TAS achieved 11% and 9% lower latency than CUBIC and BBR-v3, respectively. Under RRUL, it achieved a 13% throughput gain over BBR-v3 with latency improvements of ~59% over CUBIC and ~15% over BBR-v3. Under the RTT-fairness test, BBR-TAS achieved a 14.6% latency reduction over CUBIC and a 41.2% reduction over BBR-v3. These findings offer guidance on tuning TSQ-related kernel parameters for BBR-family congestion controls over frame-aggregating wireless links and contribute an open evaluation of pacing shift as a tunable parameter for Wi-Fi 6 environments.

Article
Computer Science and Mathematics
Computer Networks and Communications

Nurul I. Sarkar

,

Sonia Gul

Abstract: Wi-Fi 7 (IEEE 802.11be) introduces key physical and MAC layer advancements including wider channel bandwidths up to 320 MHz, 4096-QAM modulation, preamble puncturing, and tri-band operation across 2.4 GHz, 5 GHz, and 6 GHz to support high bandwidth and low latency wireless applications. Despite these advances, the application-level streaming behavior of Wi-Fi 7 networks under realistic multi-factor conditions remains insufficiently characterized in the literature. This paper presents an empirical and simulation-based evaluation of Wi-Fi 7 streaming stability, assessing the combined effect of received signal strength (RSS), codec bitrate, frequency band, network layer protocol, media type, and network contention on playback delay for MP3 audio and MP4 video streams. A physical testbed comprising a Wi-Fi 7 access point and client devices is used to conduct controlled experiments across varying signal and network conditions, complemented by OMNeT++ simulation to assess MAC layer scalability under higher client densities. Results show that RSS degradation non-linearly increases playback delay and reduces link stability, particularly in the 5 GHz and 6 GHz bands. The 6 GHz band achieves the lowest average playback delay under strong signal conditions, while the 2.4 GHz band offers greater reliability at extended range. Higher codec bitrates are found to reduce playback delay due to improved protocol efficiency and more effective buffer utilization. Network layer protocol (IPv4 vs. IPv6) has negligible impact on streaming performance. Network contention, modelled through increasing concurrent client counts, introduces substantial AP side airtime partitioning effects that degrade per-client streaming quality. These findings establish a reproducible, multi-parameter performance baseline for Wi-Fi 7 audio and video streaming, providing practical guidance for network deployment and serving as a reference for future benchmarking of next-generation Wi-Fi 8 (IEEE 802.11bn) networks.

Article
Computer Science and Mathematics
Computer Networks and Communications

Gözde Özsert Yiğit

,

Ilkay Sibel Kervanci

Abstract: A TabNet-based network intrusion detection system can achieve 97% global accuracy while simultaneously exhibiting near-total adversarial collapse in the URLLC slice (PSRI = 0.023)—a critical vulnerability that conventional metrics entirely conceal. This paper introduces the Per-Slice Robustness Index (PSRI) and Slice-Weighted F1 (SW-F1) to expose such hidden vulnerabilities in 5G network slicing environments, and proposes Attention-Guided Evasion (AGE), a transfer-based adversarial attack that exploits TabNet’s native attention mask to concentrate perturbations on the most influential features. Using the CICIoT2023 dataset with 34 attack categories mapped to eMBB, URLLC, and mMTC service slices, we demonstrate that AGE achieves a 50.2% accuracy drop at ε=0.10 while using 17× less L2 perturbation than FGSM and modifying only 8.5% of features. The proposed metrics expose a 0.121-point gap between global weighted F1 (0.928) and slice-balanced SW-F1 (0.807), demonstrating that conventional evaluation systematically overestimates protection for minority slices in heterogeneous 5G environments. These findings highlight the necessity of slice-aware adversarial evaluation frameworks for 5G network security.

Review
Computer Science and Mathematics
Computer Networks and Communications

Ugochukwu Damian Umeakubuike

Abstract: Blockchain and distributed ledger technology (DLT) have been proposed for humanitarian operations because their shared-ledger characteristics may support transparency, traceability, accountability and coordination across organisations. (Hunt et al., 2022; Saad et al., 2022) This systematic evidence review synthesises research on operational benefits, adoption barriers, implementation conditions and evidence gaps in humanitarian supply chains. (Hunt et al., 2022; Saad et al., 2022) The evidence includes systematic reviews, empirical pilot research, expert-based barrier analysis, case-based design research and implementation-framework studies. (Hunt et al., 2022; Baharmand et al., 2021; Sahebi et al., 2020; Baharmand et al., 2021; Maina et al., 2025) Across the literature, the most consistently reported potential benefits are visibility, traceability, transparency, auditability, trust and inter-organisational information sharing. (Hunt et al., 2022; Baharmand et al., 2021; Saad et al., 2022) The empirical base is smaller than the conceptual literature, and barriers include regulatory uncertainty, skills and training, sustainability costs, privacy, infrastructure, scalability, interoperability and governance. (Hunt et al., 2022; Sahebi et al., 2020; Baharmand et al., 2021) The review proposes an eight-stage implementation pathway centred on problem diagnosis, technology justification, governance, privacy-aware architecture, piloting, capacity building, evaluation and controlled scaling. The framework is a synthesis proposed by the author from the reviewed evidence, rather than a tested causal model. The review concludes that blockchain should be selected conditionally, where multiple independent actors need a shared auditable record and where the expected coordination value justifies the additional technological and governance complexity. (Baharmand et al., 2019; Baharmand et al., 2021; Baharmand et al., 2021; Maina et al., 2025).

Article
Computer Science and Mathematics
Computer Networks and Communications

Thawatchai Chomsiri

,

Suwichai Phunsa

Abstract: Smart-city platforms connect Internet of Things (IoT) devices across transport, energy, water, healthcare and e-government services, so every gateway is an entry point and every log shared evidence. This paper evaluates a four-layer architecture: edge intrusion detection trained across districts by federated learning, digests anchored on a permissioned ledger, and a cloud orchestrator that correlates and audits. Its contribution, LPRA, is an aggregation rule whose accept and quarantine decisions are recorded on that ledger. On 211,043 public IoT testbed flows with identifier-free metadata, a depth-8 tree reached F1 = 0.997 at 17.7 KB and a CPU-time-scaled estimate of 0.19 J per million flows. Federated learning across five heterogeneous districts reached 0.971 ± 0.001, against 0.952 ± 0.002 alone. Under four poisoning attacks and an adaptive attacker that knows the screen, LPRA matched the best robust baselines and, unlike them, did not reduce F1 against FedAvg without an attack; the sweep also located and repaired a failure at 40% collusion. Anchoring ran at 146 tx/s on a two-organisation Fabric network. Generalisation fails twice: F1 falls from 0.96 within a dataset to 0.12 across datasets, and from 0.9824 under a random split to 0.0005 on a later capture day. Training must stay local and continuous.

Article
Computer Science and Mathematics
Computer Networks and Communications

Robert Campbell

Abstract: Cryptographic inventories and runtime detection can identify declared or observed cryptographic use, but they do not by themselves establish whether the exact implementation exhibited externally specified behavior or whether an evidence-backed use satisfies explicit policy. We present a deterministic cryptographic assurance composition that connects admitted runtime behavior to provenance-closed evidence, exact implementation identity, separately bound conformance against Contract-registered NIST test vectors, content-addressed policy appraisal, and explainable ACCEPT, REJECT, or REVIEW verdicts. Controlled SHA-256 and AES-256-GCM workloads produced 12 authentic runtime executions and six provenance-distinct occurrences. The frozen implementation subjects produced expected outputs for all 505 registered inventory entries—130/130 SHA-256 and 375/375 AES-256-GCM ENCRYPT—yielding two authentic conformance results. Under a policy frozen before authentic appraisal, all six occurrences followed the positive path to ACCEPT; controls independently demonstrated REJECT for supported policy violations and REVIEW for missing or out-of-coverage evidence. Conformance and appraisal/verdict evidence reconstructed byte-identically in 10/10 replays; 12/12 conformance controls and 25/25 appraisal, REVIEW, and anti-fabrication controls passed. No raw AES key or registered direct encoding was detected within the scanned retained-artifact boundary. These results demonstrate a reproducible bounded assurance chain across two cryptographic classes, without claiming exhaustive correctness, CAVP/CMVP validation, FIPS certification, generalized discovery, regulatory compliance, or production authorization.

Article
Computer Science and Mathematics
Computer Networks and Communications

Mutasim Elsadig Adam

,

Yasir Abdelgadir Mohamed

,

Aghabi Nabil Abosaif

,

Akbar Khanan

Abstract: Recent years have witnessed a significant increase in the number of Internet of Things (IoT) connected devices, producing many functionally similar services that differ in non-functional attributes such as Quality of Service (QoS). Evaluating QoS reliably is complicated by IoTʹs multilayer architecture and inherent uncertainty in consumer preferences, and selecting services on preference alone risks overqualification and inefficient resource use. This study proposes an integrated assessment and selection model. First, a two-stage fuzzy logic method evaluates the QoS of registered IoT services across all architectural layers. Second, candidate services are filtered according to both user preference and task purpose, then ranked using the Analytical Hierarchy Process (AHP). Experiments on a 200-service dataset showed that the assessment model successfully estimated QoS for every service. In a critical-purpose scenario, the model automatically selected 67 high-quality candidate services; in a normal-purpose, low-QoS scenario, it identified 21 low-quality services. The two-stage approach also reduced service-ranking execution time relative to an AHP-TOPSIS (Technique for Order of Preference by Similarity to Ideal Solution) baseline. By incorporating task purpose alongside user preference, the proposed model mitigates service overqualification, improves ranking efficiency, and gives IoT service providers a practical tool for matching services to end-user requirements.

Article
Computer Science and Mathematics
Computer Networks and Communications

Yasir Abdelgadir Mohamed

,

Diaeldin Izeldin Mohamed Ibrahim

,

Sally D. Abualgasim

,

Akbar Khanan

Abstract: The Internet of Things (IoT) promises transformative services through pervasive smart objects but raises security and privacy challenges for trusted access in open, dynamic environments. Existing access-control models, reliant on static, manually managed policies, prove inadequate for dynamic IoT systems. This paper presents a context-aware, policy-driven access-control framework (ACF) that automates delegation, revocation, and verification of access rights in distributed IoT settings, implemented on a defense-in-depth testbed integrating a domain controller, certificate authority, Identity Services Engine (ISE), and third-party posture-validation vendor configured to revoke access when a Common Vulnerability Scoring System (CVSS) score exceeds 7. The virtualized testbed comprised approximately ten simulated access initiators and an integrated Cisco AMP environment with 42 managed endpoint records, demonstrating secure site-to-site and remote-access communication, automated policy enforcement, and CVSS-triggered Change of Authorization (CoA). Benchmarked against nine existing IoT access-control frameworks across ten security requirements, the proposed ACF achieved the top rating in seven, matching the best-performing comparators in real-time robustness and meeting the Identity Management standard. Limitations include the absence of controlled large-scale load testing, dependence on Cisco infrastructure, formal security proofs, and physical-device testing. Future work should integrate AI/ML for predictive threat analytics and adopt open-source components.

Article
Computer Science and Mathematics
Computer Networks and Communications

Lijuan Wang

,

Krassie Petrova

,

Mee Loong Yang

Abstract: Software-defined wireless sensor networks (SDWSNs) are deployed in mission-critical applications such as environmental monitoring, smart cities, and healthcare. However, existing protocol architectures such as SDN-WISE lack built-in mechanisms for the detection or mitigate of Denial-of-Service (DoS). Existing trust-based security solutions are rarely fully integrated into the protocol stack; nearly all of them rely on manually configured thresholds which severely undermine their effectiveness. This study integrates the Adaptive, Threshold-Free, and Automatically Weighted Trust Model (ATAW-TM) into the SDN-WISE protocol stack; the ATAW-TM model was adjusted to the resource-constraint sensor node environment by embedding three lightweight adaptations: an inverse-quadratic approximation of Gaussian-like cooperation probability that eliminates exponential function calls and mathematical libraries dependences, a quadratic approximation of second-order Rényi (replacing Shannon entropy) for entropy weight calculation that avoids logarithmic operations, and a lightweight sigmoid approximation for the aging factor that preserves monotonicity and smoothness without the use of exponential functions. To evaluate the integrated model, we developed a comprehensive evaluation framework encompassing 14 distinct DoS attack types and one data tampering attack against SDWSNs. The integrated model was evaluated through extensive Cooja-based simulations. The experimental results indicated that compared to the standard SDN-WISE, the proposed security solution successfully detects a comprehensive range of DoS attacks and one type of data tampering attack, with a negligible performance overhead (less than 5.3% additional hop delay, and 8.1% additional forwarding delay). Furthermore, simulation results show that the proposed method can adapt to variations in network traffic conditions without requiring manual threshold tuning. Overall, the proposed lightweight trust-based attack recognition model offers a practically achievable security solution for resource-constrained SDWSNs, without sacrificing protocol efficiency.

Article
Computer Science and Mathematics
Computer Networks and Communications

Aiman Ahmad Shivani

,

Marzia Zaman

,

Pirathayini Srikantha

,

Darshana Upadhyay

,

Kshirasagar Naik

Abstract: Homomorphic encryption (HE) enables computation on encrypted data and has emerged as a promising technology for privacy-preserving distributed analytics. However, the practical deployment of HE in large-scale hierarchical systems requires a thorough understanding of its computational overhead, scalability, and accuracy. This paper presents a generic hierarchical benchmarking framework for systematically evaluating homomorphic encryption schemes in multi-level aggregation environments. The framework supports configurable aggregation topologies, detailed operation-level profiling, and multiple encryption backends, enabling consistent and reproducible performance analysis across node-, cluster-, and global-level aggregation stages. Using the proposed framework, we conduct a comparative evaluation of the Brakerski/Fan-Vercauteren (BFV) and Cheon-Kim-Kim-Song (CKKS) schemes under identical workloads. Experimental results show that CKKS consistently outperforms BFV, achieving a 44.3% reduction in aggregation latency and a 24.6% reduction in decryption latency. {For the tested encoding and parameter settings,} CKKS delivers significantly lower numerical error, reducing the mean absolute error from 3.21 × 10−3 to 5.91 × 10−10. The proposed framework offers a reusable and extensible platform for evaluating emerging HE schemes and privacy-preserving analytics applications, thereby supporting future research and deployment of secure distributed data processing systems.

Article
Computer Science and Mathematics
Computer Networks and Communications

Thawatchai Chomsiri

Abstract: Listed-Rule Firewalls (LRF), deployed in iptables, nftables, Cisco ACL, and pfSense, suffer from linear matching complexity and structural anomalies affecting a large share of production rules. This paper presents an automated, formally proven framework converting LRF policies into Tree-Rule Firewall (TRF) structures. It combines a unified four-dimensional range decomposition, a projection normalization algorithm generalized to all twelve valid attribute orderings, and protocol-dependent destination-port semantics for ICMP. A tree is fixed by a permutation of the four packet attributes, so the admissible orderings form the half of the symmetric group S₄ placing protocol before dst_port. Three theorems and four propositions establish that this admissible set is exactly half the group and that the tree returns the same action as the original policy for every packet under every admissible ordering: semantics is invariant, structural cost is not. Evaluation on 10,000 synthetic policies (73 million packet comparisons) records no semantic discrepancy; on industry-calibrated synthetic ClassBench-ng rulesets, tree depth stays at its by-construction maximum of four with no early collapse. A 10,000-policy benchmark quantifies the broken cost symmetry: protocol-first orderings dominate at small sizes but reach statistical equivalence in matching time by 200 rules, while their structural advantage persists. All evaluated policies contain at most 400 rules.

Article
Computer Science and Mathematics
Computer Networks and Communications

Ahmad Abumihsan

,

Amani Yousef Owda

,

Majdi Owda

,

Ana Fernández-Vilas

,

Mobarak Abumohsen

Abstract: Software-defined networking (SDN) is an advanced network architecture to transform the conventional network to meet evolving requirements. Unlike traditional networks, SDN breaks down the control and data plane, making it efficient to monitor, configure, and optimize the network resources. However, due to its centralized nature, SDN is prone to several attack vectors. Among them, distributed denial of service (DDoS) attacks are the most potent threats to the SDN controller. This paper presents a novel approach to detect DDoS attacks on SDN controllers using a novel detection model based on a parallel one-dimensional convolutional neural network-gated recurrent unit (1D CNN-GRU) architecture equipped with a novel hybrid feature selection approach. The suggested hybrid feature selection combines the filter feature methods (mutual information, chi-squared, and ANOVA) with a self-attention mechanism to effectively detect the most vital features for DDoS attack detection in SDN environments. The proposed detection model 1D CNN-GRU leverages the strengths of both a convolutional neural network (CNN) and a gated recurrent unit (GRU). The CNN captures spatial and local patterns, while the GRU focuses on temporal dependencies within the data. The proposed approach showcased high levels of accuracy (97.882%), precision of (98.078%), and F1-measure of (97.276%). Additionally, it exhibited a low false positive rate (FPR) of 1.208% and a short detection time of 1.206 seconds.

Article
Computer Science and Mathematics
Computer Networks and Communications

Laha Ale

,

Letian Lin

,

Na Cao

,

Zheng Ma

,

Peng Yu

Abstract: Accurate traffic forecasting is essential for proactive resource management in edge computing, where service demand evolves dynamically across both space and time. In practical cellular edge systems, traffic exhibits strong spatial correlations among neighboring service regions and long-range temporal dependencies driven by user mobility and application behavior. Existing recurrent forecasting approaches can capture short-term dynamics but often struggle to model long-horizon traffic evolution under non-stationary conditions. To address this challenge, we propose a spatiotemporal graph Transformer framework that jointly models spatial interactions and temporal dependencies for traffic forecasting in edge computing. The framework employs graph neural networks to capture spatial correlations among service regions and leverages Transformer-based self-attention to learn long-range temporal patterns from historical traffic observations. By decoupling spatial representation learning from temporal reasoning, the proposed approach provides an effective mechanism for large-scale spatiotemporal traffic modeling. Extensive experiments on a real-world cellular network dataset demonstrate that the proposed graph Transformer consistently outperforms recurrent graph-based baselines, including GCN-RNN, GCN-LSTM, and GCN-GRU models, across multiple forecasting horizons. The resulting forecasts enable more effective proactive resource provisioning and reduce overload risk compared with reactive management strategies. These results highlight the potential of graph-enhanced attention mechanisms for building intelligent and adaptive edge computing systems.

Article
Computer Science and Mathematics
Computer Networks and Communications

Iacovos Ioannou

,

Vasos Vassiliou

Abstract: Circuit power consumed by radio frequency chains in massive multiple input multiple output arrays is reduced through antenna selection. Conventional gains are commonly established under perfect channel knowledge and isolated cell assumptions, whereas deployed links are affected jointly by estimation error, pilot contamination, spatial correlation and inter cell interference. Two complementary primary contributions are proposed. APCS Boost R provides interference calibrated algebraic selection through an interference whitened D optimal seed and projected exchanges implemented with rank one updates. Candidate subsets are evaluated by a calibrated surrogate that combines a user measurement report with a closed form estimation error correction while preserving the algebraic update structure. APCS Boost RG provides certified network informed learning through a physics derived heterogeneous graph neural network trained by imitation of a network level partial response oracle. Learned exchange potentials are combined with exact surrogate increments and every accepted subset is verified against the robust stage utility floor. In a three cell urban macro system with 64 antennas, 16 active chains and eight users per cell, APCS Boost R attains 19.364 bit/s/Hz over 200 paired realizations. Improvements of 2.58 percent over APCS Boost, 6.76 percent over norm initialized greedy search and 10.16 percent over a genetic algorithm are obtained with a selection time of 20.4 ms. Energy efficiency is increased from 0.497 to 0.510 bit/J/Hz without a statistically significant change in minimum user rate. APCS Boost RG provides an additional 0.019 bit/s/Hz, with a positive mean in every replication and a confidence interval excluding zero. The learned key produces a tighter paired interval than exact surrogate ranking within the same single exchange neighbourhood while preserving the certified floor. The results demonstrate that objective calibration and certified graph learning provide complementary gains under jointly modelled multi cell impairments with distributed inference and no runtime cross cell signalling.

Article
Computer Science and Mathematics
Computer Networks and Communications

Chinedu Ositadimma Chukwu

,

Ejike Utulor

,

Adaeze Naomi Umunna

,

Jenny Chukwu

Abstract: This study investigated the influence of teachers’ perception and digital readiness on their preparedness for the implementation of computer-based WAEC examinations in Nigerian secondary schools by 2030. A multi-phase quantitative research design combining ex post facto and correlational approaches was adopted. The ex post facto phase allowed examination of existing conditions, such as teachers’ prior exposure to technology and ICT experience, without manipulation of variables, while the correlational phase determined the strength and direction of relationships between teachers’ perception, digital readiness, and preparedness for CBT. The population comprised all 12,483 registered secondary school teachers across public and private institutions in Ebonyi State, responsible for teaching and assessment for national examinations. A stratified random sampling technique was employed, based on school location and subject discipline, yielding a sample of 1,248 teachers, approximately 10 per cent of the population. Data were collected using the Teachers’ Perception and Digital Readiness Inventory (TPDRI), a structured questionnaire divided into three sections: demographic information (6 items), perception of CBT (15 items), and digital readiness (25 items), rated on a four-point Likert scale. Reliability was established through a pilot study with 30 teachers, yielding Cronbach alpha coefficients of 0.74 for perception and 0.78 for digital readiness. Descriptive statistics summarized teachers’ responses, while one-sample t-tests and simple regression analysis examined predictive relationships. Findings indicated that teachers’ perception of CBT was largely neutral, with an observed mean marginally above the baseline (Mean = 37.65, SD = 9.45, t = 0.57, p = 0.567), revealing uncertainty regarding feasibility and benefits. Digital readiness was significantly higher than baseline (Mean = 66.85, SD = 14.52, t = 10.25, p < 0.001), though gaps in infrastructure and training persisted. Regression analysis showed perception significantly predicted digital readiness (B = 1.82, Beta = 0.41, t = 7.58, p < 0.001, R² = 0.17), indicating that positive attitudes contribute to higher readiness, while other factors such as access to ICT resources also play a role. The study concludes that successful CBT implementation requires both enhancement of teachers’ perception through sensitisation and professional development, and investment in digital infrastructure, training, and support to ensure equitable preparedness across Nigerian secondary schools.

Article
Computer Science and Mathematics
Computer Networks and Communications

Basker Palaniswamy

,

Paolo Palmieri

Abstract: Modern e-commerce platforms must handle sudden and unpredictable traffic surges caused by flash sales, festive shopping events, and viral online activity. Traditional web architectures typically adopt one of two extremes: a tightly coupled monolithic design that provides low latency but becomes fragile under heavy load, or a loosely coupled microservices architecture that improves scalability and resilience but introduces communication overhead during normal operation. This trade-off forces system designers to choose between performance efficiency and scalability robustness. This paper introduces ATLAS (Adaptive Traffic-aware Loose–tight Architecture System), a next-generation adaptive web architecture that dynamically adjusts its coupling strategy based on real-time system conditions. ATLAS employs machine learning models to analyse operational telemetry, predict traffic surges, detect anomalies, and forecast potential system failures. Using these predictions, the architecture can automatically transform its runtime structure, switching between tightly coupled monolithic execution and loosely coupled microservices deployment as traffic conditions evolve. To improve reliability, ATLAS incorporates a self-healing recovery pipeline that autonomously detects service failures, isolates faulty components, and restores normal operation without human intervention. Through case studies of large-scale platforms such as Google Search, Amazon, and Flipkart, we illustrate how existing systems can evolve toward the ATLAS paradigm, enabling self-adaptive and resilient web infrastructures for the next generation of large-scale online services.

Article
Computer Science and Mathematics
Computer Networks and Communications

Shuxuan Ma

,

Zhuoran Cai

,

Yue Yin

Abstract: The electromagnetic spectrum grows increasingly crowded with the rapid expansion of mobile, satellite and Internet of Things communications, making intelligent spectrum sensing and efficient management an urgent priority. Automatic modulation classification (AMC) serves as the core of cognitive radio and intelligent communication. Existing deep models often suffer from a large number of parameters and high computational complexity. To overcome these limitations, we propose MDSCNet, a Multi-Scale Depthwise Separable Complex Network. Built upon complex depthwise separable convolution, the network makes full use of the phase information in IQ signals while naturally preserving the symmetric relationship between the in-phase and quadrature components. An asymmetric multi-scale structure with embedded channel attention further helps the model capture diverse distortion patterns under non-ideal channels at negligible extra cost. The overall parameter count is kept extremely low, at only 47.739k. Experiments on the RML2016.10a and RML2016.10b datasets show that MDSCNet delivers excellent recognition performance under low signal-to-noise ratios, reaching 63.37% and 67.07%respectively. More importantly, it significantly outperforms mainstream methods in both parameter count and computational load.

Article
Computer Science and Mathematics
Computer Networks and Communications

Vasco Bexiga

,

André Lopes

,

Nelson Pimenta

,

Paulo Chaves

Abstract: Smart water metering deployments require low-power, large-scale communication infrastructures that existing LPWAN solutions do not fully address. Among the most widely used technologies, LoRaWAN's single-hop topology requires dense gateway de-ployments in urban environments, while cellular alternatives incur subscription costs and higher energy consumption. This paper presents a multi-hop LoRa network protocol spe-cifically designed for smart water metering, exploiting the static network topology and uplink-dominated traffic pattern of this application to substantially simplify the protocol design. The protocol constructs a tree rooted at the gateway through distributed relay se-lection. Each node selects its relay using only lightweight message exchanges and a cost function that combines hop count, relay load, and link quality, requiring only local infor-mation and no global routing tables. Explicit acknowledgements are replaced by over-hearing relay retransmissions, further reducing energy consumption. The cost function coefficients were tuned through simulation using Bayesian optimization across network sizes of up to 100 nodes, revealing that the optimal parameter configuration is itself net-work-size dependent. Compared with a shortest-hop (BFS) baseline, the proposed ap-proach limits the maximum relay load to approximately 12 client nodes regardless of network size, achieving a reduction of up to 72% in the 100-node scenario while incurring an average hop-count increase of up to approximately 13%.

Article
Computer Science and Mathematics
Computer Networks and Communications

Gemma B. Vate

,

Jorge E. López de Vergara

,

Iván González

,

Gustavo Sutter

,

Luis de Pedro

Abstract: This paper investigates whether JA4+ fingerprint decomposition improves passive identification of Internet of Things (IoT) devices in encrypted network environments. As TLS encryption and privacy-preserving mechanisms such as Encrypted Client Hello reduce the visibility of application-layer metadata, traditional payload- and domain-based identification techniques become less effective. JA4+ fingerprints provide an alternative approach by extracting observable characteristics from TLS handshakes, certificates, and transport-layer metadata without requiring traffic decryption. The proposed methodology evaluates different JA4+ fingerprint combinations for IoT device identification using traffic traces from the CICIoT2023 dataset. Traffic traces were processed with Zeek to extract the JA4+ fingerprint family, which was evaluated using dictionary-based classification and Random Forest models. Compact fingerprint representations were compared with decomposed protocol-level features to determine whether feature decomposition improves classification performance or enhances interpretability. Experimental results show that JA4+ fingerprints enable accurate IoT device identification using only passive encrypted traffic metadata. The compact JA4+ representation achieved the best classification performance among the evaluated configurations, reaching a Macro F1-score of 0.8333 and a Top-1 accuracy of 0.9091. Decomposed representations achieved comparable results but did not provide consistent classification improvements. These findings indicate that compact JA4+ fingerprints already preserve most of the discriminative information required for IoT device identification, making protocol-level decomposition unnecessary when maximizing classification performance. Nevertheless, decomposed representations remain valuable for interpretability and feature-level analysis. The results highlight the potential of JA4+ fingerprinting for scalable IoT security monitoring under increasingly encrypted network conditions.

Article
Computer Science and Mathematics
Computer Networks and Communications

Francis Kagai

,

Philip Branch

,

Jason But

,

Rebecca Allen

Abstract: Emergency and infrastructure-poor environments require coordination mechanisms that continue operating despite intermittent connectivity, limited bandwidth, and changing node participation. Existing low-bitrate mesh systems commonly rely on fixed timing configurations that either introduce unnecessary waiting under favourable conditions or become fragile as airtime and contention increase. This paper presents an adaptive quorum-based coordination framework for low-bitrate LoRa mesh networks that continuously adjusts execution timing from estimated LoRa airtime and observed participation. Each node executes a lightweight Monitor–Analyse–Plan–Execute–Knowledge (MAPE-K) control loop that derives slot spacing and coordination deadlines online. The framework combines quorum and full-participation finalisation with bounded single-retry recovery to keep local state deterministic. The approach was implemented on a four-node SX1276 LoRa mesh with opportunistic gateway support and evaluated under crash and omission faults with honest firmware. Across 2,514 coordination rounds, median completion time was 2.1 s in three-of-four quorum mode and 5.3 s under full participation, while all first-deadline misses completed through bounded recovery. Results indicate that adaptive timing reduces completion-time penalties associated with conservative static scheduling while preserving bounded execution behaviour on the evaluated testbed. The contribution is a cross-layer execution-timing framework that treats airtime as a runtime control signal for offline-first LoRa mesh coordination rather than a fixed deployment parameter.

of 27