
The rapid progression of automotive technology through In-Vehicle Networks (IVNs) such as Controller Area Networks (CAN), Local Interconnect Network (LIN), FlexRay, Media Oriented Systems Transport (MOST), and Automotive Ethernet has significantly reshaped internal vehicle communication. This expansion in connectivity has led to new cybersecurity risks that directly affect passenger safety and the reliability of transportation infrastructure. These challenges highlight the need for resilient infrastructure for sustainable industrialisation. Many existing reviews in the IVN cybersecurity domain focus individually on specific protocols or attack categories and corresponding defense strategies rather than considering the entire framework. Thus, we conduct a Systematic Literature Review (SLR) on existing literature from 2010 to 2025 and examine cybersecurity developments related to IVNs. A structured taxonomy that integrates IVN protocols, major attack techniques, and datasets, along with cryptographic, conventional and Artificial Intelligence (AI)-based cybersecurity mechanisms, is presented. Our study adheres to PRISMA guidelines and provides a comprehensive and systematic analysis of the IVN cybersecurity domain. This provides a consolidated data synthesis of existing literature, offering deeper insights into current trends, research gaps, and emerging research directions in IVN cybersecurity. The SLR also emphasizes the transition from static, rule-based methods to adaptive and hardware-based solutions and identifies that the key trend is the shift toward adaptive cybersecurity mechanisms in heterogeneous IVN environments. Finally, the limitations in current solutions are also identified as research gaps, and the future research directions are outlined to strengthen the cybersecurity resilience of autonomous vehicles.
The Domain Name System (DNS) is responsible for translating human-readable names into computer-friendly identifiers and employs a reverse tree architecture to facilitate this translation. The forward DNS (fDNS) translates human-readable domain names into computer values, while the reverse DNS (rDNS) usually maps an IP address to a hostname. The DNS has evolved into a more intricate system, driven by economic incentives, with data stewardship being delegated to numerous autonomous stakeholders. Due to its role in Internet infrastructure, studying DNS is fundamental for both practical and security reasons. In this work, we characterize commonly used DNS datasets and the challenges linked to their usage. We thoroughly survey DNS focused research studies published over the course of more than a decade, within more than 15 proceedings, and observe a prominent reliance (62%) on short-term datasets. Our investigation into the challenges that limit the adoption of long-term datasets reveals that some of these challenges are associated with the distributed design of the DNS, while others are associated with the evolution of the DNS deployment. That is, we found that, the diversity of stakeholders has the potential to impede data collection and access by various stakeholders, as well as the sharing of data between operators and researchers. Specifically, the distributed design of the DNS leads to challenges regarding namespace coverage, privacy, confidentiality, format, size, and time granularity. Furthermore, certain DNS data is considered commercially sensitive, which further increases the penumbra over the global DNS exchanges, leading to a lack of publicly available DNS data. In earlier works, we observe a distinction in research topics between studies using actively and passively collected DNS data, followed by a recent convergence in topics investigated across both data collection approaches. Lastly, we noted that rDNS data is studied much less than fDNS, i.e., only 2.7% of the studied papers.
Agent-based modeling and simulation (ABMS) serves as a pivotal bottom up paradigm for revealing macro level emergent behaviors through micro level interactions. Classic ABMS remains foundational to the field, while they typically necessitate manual development and labor intensive construction of agent logics. Based on a synthesis of recent advancements, this article synthesizes the literature through a lifecycle-oriented organizing framework that supports the ABMS lifecycle, including (1) a generative workflow leveraging prior knowledge for conceptual abstraction; (2) a simulation modeling framework comprising an agent decision-making architecture integrating multimodal perception, retrieval augmented generation enhanced memory, and chain of thought reasoning alongside communication design and LLM-based code generation; and (3) a simulation data analysis framework that synthesizes micro level quantitative analysis with macro level qualitative analysis. This study aims to provide a methodological perspective for the integration of LLMs into ABMS.
Self-Sovereign Identity (SSI) is widely positioned as the decentralized future of digital identity. However, although traditional SSI literature emphasizes architecture and privacy, it largely overlooks a systematic analysis of how trust is formed, propagated, and managed. Trust is fundamental because, without it, the actions performed by key actors, including credential issuers, lose much of their practical value. In this landscape, trust is the ground on which SSI systems stand; when that ground is absent or unstable, any structure built on it crumbles. Against this backdrop, we chart the landscape of trust through a comprehensive survey of Trust Models (TMs) and Trust Management Systems (TMSs) in SSI. At the abstract level, we analyze TMs by examining the types of trust relationships among SSI actors and how trust is defined and represented. At the implementation level, we discuss TMSs in terms of how trust is represented, stored, and protected in the systems proposed in the literature. We analyzed 26 sources (24 peer-reviewed papers plus the Sovrin whitepaper and governance framework document), consolidated into 24 approaches, benchmarking 16 features across these dimensions. Based on this analysis, we identify five open challenges: enabling cross-chain trust portability; designing a hybrid TM that blends Web of Trust and hierarchies; supporting heterogeneous actors such as IoT devices and humans; implementing privacy-preserving feedback mechanisms; and TM and TMS interoperability in emerging settings, including delegated AI agents. Our analysis offers a compass to guide researchers and developers in selecting trust models and advancing SSI systems.
The continuous progress and distinct capabilities have led the Internet of Drones (IoD) to be a persuasive paradigm that offers promising advantages across various applications, spanning from defense to civilian uses. Despite its manifold benefits, it is essential to highlight that it also faces several challenges, and security remains a critical concern that can hold back its widespread adoption. Stringent authentication mechanism design has appeared as one of the favorable techniques for tackling distinct security attacks in IoD networks. This survey presents a detailed review of existing literature, focusing on authentication protocols explicitly designed for securing communication in IoD networks. Recognising the growing complexity and diversity of communication, we present a novel multi-layered taxonomy that offers a comprehensive roadmap for classifying authentication mechanisms across the IoD stack. The presented taxonomy interactively maps each authentication technique to its system roles, cryptographic foundations, and operational context within the IoD network to demonstrate a more holistic understanding of prevalent authentication mechanisms. Drawing from our presented taxonomy, we highlight the compelling contributions and acknowledge the potential limitations of the recent literature. We compare the security and resistance to common attacks of prevalent protocols while highlighting their advantages and limitations. Based on the security analysis, we shortlist protocols for full-scale implementation that exhibit the highest security coverage. We then present a detailed experimental analysis of these selected protocols against various metrics (i.e., CPU execution time, memory consumption, etc.) using a Holybro QAV250 quadcopter drone-based testbed setup. Finally, we discuss future challenges that require joint efforts from academia and industry.
The confluence of Machine Learning (ML), Edge, and containerization has resulted in the emergence of Edge AI, which enhances reliability, fault tolerance, data security and privacy, inference time and accuracy. On one hand, accelerated hardware and advanced interconnects have reduced training times and improved accuracy. Leveraging this, the orchestration engines automate workload management but often struggle with limited features and sub-optimal policies. Edge offers a myriad of interconnected devices employing hardware and orchestration engines, but these devices are inherently distributed and resource-constrained, which adversely impacts Edge AI adoption. Moreover, leveraging Artificial Intelligence (AI) for Edge orchestration to optimize resource provisioning, scheduling, and management without compromising the quality of service has been the driving motivation. However, integrating these components to enable Edge AI poses substantial challenges encompassing the hardware, interconnects, orchestration engines, computational, application, and workload heterogeneities. Additionally, training data scarcity, constrained and heterogeneous resources, control plane management overhead, delayed data traversal, and other factors exacerbate Edge AI orchestration challenges. Considering these challenges and opportunities, this paper establishes a top-to-bottom architectural view to investigate cross-layer Edge AI orchestration progress across three layers. At the bottom layer, NVLink, Compute Express Link, and other heterogeneous interconnects that manage the underlying hardware are discussed and compared in terms of offered bandwidth, latency, topology, and other features. In the middle layer, heterogeneous container orchestration engines and their high/low-level runtimes are contrasted for Edge AI. For the top layer, a systematic review of research works empowering heterogeneous Edge AI orchestration which proposed heuristic, meta-heuristic, optimization, and AI/ML solutions for container migration, autoscaling, ML/DL model-switching, resource forecasting, and scheduling is conducted. Furthermore, this article investigates the employment and position of Generative AI in Edge computing. Subsequently, taxonomies of optimization models, ML/DL models, orchestration engines, runtimes, and orchestration objectives are provided. Finally, the identified research gaps and possible future directions conclude this article.
Collision avoidance is a critical requirement in multi-UAV networks to ensure safety, prevent damage, and enable successful mission completion, especially in dynamic and crowded environments and real-time navigation scenarios in UAV swarms. This survey aims to provide a clear and structured review of deep learning-based collision avoidance techniques in multi-UAV networks. The survey covers key categories of deep learning techniques for collision avoidance, including deep reinforcement learning, perception-based models, sequential models, cooperative learning methods, imitation learning, and transformer-based approaches. The paper analyzes how these methods are designed, their working principles, and their strengths and limitations in real-world applications. The main contribution of this survey is a detailed comparison of these techniques in terms of performance, scalability, coordination, and practical usability. It also discusses key design issues, including communication constraints, energy efficiency, safety, and multi-agent learning. The findings show that deep learning methods offer better adaptability and decision-making than traditional approaches, but they still face challenges such as high computational cost and complex training. Finally, this survey highlights open issues and future research directions to support the development of more efficient and reliable collision avoidance systems for multi-UAV networks.
RESTful APIs have become a fundamental component of modern cloud-native and microservice-based applications, enabling seamless integration between distributed services. Since these APIs often expose sensitive data and business logic through publicly accessible endpoints, they have become attractive targets for cyberattacks. Recent security incidents and the growing number of API-related vulnerabilities demonstrate that traditional web application security mechanisms are insufficient for protecting RESTful APIs. Although numerous testing approaches have been proposed, existing research remains fragmented and often focuses primarily on functional validation rather than systematically addressing security vulnerabilities and adversarial exploitation patterns.This survey provides a comprehensive review of RESTful API testing approaches with a particular focus on those identifying security vulnerabilities. Based on a systematic analysis of 69 primary studies, we examine common RESTful API vulnerabilities and present a structured taxonomy that distinguishes between application-level weaknesses and configuration or deployment-level issues. We further analyze the attack patterns that exploit these vulnerabilities and review state-of-the-art testing approaches, including specification-based, model-based, property-based, and AI/ML-driven techniques. In addition, we analyze existing tools, datasets, and evaluation metrics used to assess the effectiveness of RESTful API testing methods.Finally, the survey identifies several critical research gaps that limit the effectiveness of current approaches, particularly around authenticated, context-aware testing and the detection and validation of logic-based security violations. We discuss emerging trends and outline potential research directions, including dependency-aware testing frameworks and AI-driven techniques for automated vulnerability discovery. This work aims to guide researchers and practitioners toward developing more systematic and robust frameworks for RESTful API security testing.
Multiparty quantum key agreement (MQKA) enables n ≥ 3 mutually distrustful users to establish a shared secret key through collaborative quantum protocols. In this paper, we provide a comprehensive review where we argue that MQKA is best understood as a design space organized along three orthogonal but tightly coupled axes: (1) network architecture, which determines how quantum states flow between participants; (2) quantum resources, which encode the physical degrees of freedom used for implementation; and (3) security model, which defines trust assumptions about devices and infrastructure. Rather than treating MQKA as a linear sequence of isolated protocols, we develop this three-axis perspective to reveal recurrent patterns, sharp trade-offs, and unexplored design spaces. We classify MQKA protocols into structural families, map them to underlying quantum resources, and analyze how different security models shape fairness and collusion resistance. We further identify open challenges in composable security frameworks, network native integration, device-independent implementations, and propose a research roadmap toward hybrid-resource, bosonic-code-encoded, and fairness-aware MQKA suitable for the future quantum internet deployments in the post-NISQ era.
Large Language Models (LLMs) and Evolutionary Computation (EC) are increasingly being combined to support automated optimization, algorithm design, and adaptive decision-making. This survey reviews the bidirectional interaction between these two paradigms and examines how their complementary strengths can be leveraged in hybrid intelligent systems. First, we analyze how EC can enhance LLM-based systems through prompt optimization, hyperparameter tuning, and architecture search. Second, we review how LLMs can improve EC by supporting metaheuristic design, surrogate reasoning, adaptive operator control, and heuristic generation. We further discuss emerging co-adaptive frameworks in which LLMs and EC interact through iterative feedback loops. Beyond summarizing recent developments, the survey provides a structured perspective on interaction mechanisms, application patterns, and methodological challenges, including computational cost, reproducibility, interpretability, benchmarking, and generalization. The paper concludes by outlining open research questions and future directions for developing more robust, transparent, and scalable LLM-EC systems.
NLP has evolved from rule-based systems to Transformer-based LLMs, revolutionizing human-machine interac tion. However, modern NLP systems face key bottlenecks: data privacy concerns in centralized training, limited adaptability to dynamic environments, and weak grounding in real-world intelligent systems. Recent advances combining FL, NLP, and RL have enabled privacy-preserving, communication-efficient, and aligned intelligence. This review contextualizes these developments through benchmark settings, datasets, models, and communica tion metrics. In NLP, LoRA-based federated fine-tuning reduces trainable parameters and transmitted data by 30-75%, achieving competitive accuracy on GLUE, ATIS, SNIPS, and clinical NER tasks (i2b2 and MIMIC-III) while maintaining privacy across distributed clients. Compared to full-model updates, parameter-efficient meth ods yield 100-1000 & times; communication reduction, further improved by quantization (4-8 & times;), gradient sparsification (10-100 & times;), and layer skipping (similar to 70%). Under heterogeneous device conditions (up to 1000 & times; compute variation), FedAvg and FedProx reach within 1-3% and 5-10% of centralized accuracy, while ILoRA improves convergence stability by 4-8%. In parallel, NLRL enhances sample efficiency by 15-25% through language-guided policy opti mization, and RLHF-based alignment boosts human preference metrics by 10-30%. These techniques collectively enable scalable, secure, and adaptive learning across distributed and embodied environments. Finally, this survey highlights the synergy among FL, RL, and NLP, showing their integration within intelligent edge and robotic sys tems, achieving over 95% accuracy under constrained resources, and outlines open challenges in bias mitigation, communication bottlenecks, and safety in autonomous decision-making.
As Internet censorship continues to be deployed across a number of nation-states, understanding its scope and underlying mechanisms is more important than ever. Consequently, research on censorship measurement and circumvention has attracted growing academic interest, particularly in recent years. This article provides an overview of the current state of the art in the field of Internet censorship measurement and circumvention research. First, a brief overview of the fundamentals is provided, followed by an in-depth analysis of 146 con temporary Internet censorship measurement and circumvention studies, predominantly those published within the last ten years, by applying a semi-systematic literature review methodology. Subsequently, the review briefly summarizes the ethical considerations in the field, it visualizes the geographical focus of censorship measurement studies, and it provides an overview of Internet protocols used to measure censorship. In addition, it presents a tax onomy of censorship circumvention tools, analyzes their key characteristics, and examines the prevalence of the underlying network protocols used in circumvention tools. The findings suggest that, while there are numerous solutions for circumventing censorship, many are niche or theoretical, and their practicality remains unknown. Although there is an observable trend toward large-scale longitudinal censorship measurement studies, the real-world effectiveness of (academic) censorship circumvention methods is rarely evaluated. Since both censorship measurement and circumvention research go hand-in-hand, there is an increasing number of measurement studies which directly translate their findings into practical circumvention strategies.
Service Function Chains (SFCs) support computer networks in keeping pace with increasing user numbers and changing usage patterns by enabling network programmability. SFCs virtualise network functions, such as firewalls, enabling them to be programmatically embedded on servers and linked, creating a chain of virtual network functions. Optimally composing and embedding SFCs on physical networks is an NP-hard optimisation problem. Since 2016, there has not been a comprehensive literature survey of approaches to optimally compose and embed SFCs across all application domains. In this work, we survey the literature, identify, and analyse 209 papers based on their title, abstract and content. We then develop an analytical framework to extract data from the curated papers. Based on the data, we propose an update to the existing three-stage definition of the optimal SFC composition and embedding problem, factoring in recent technological advancements and approaches. We analyse the extracted data in terms of use cases, including optimisation objectives, application domains, physical network topologies, algorithms used, their scalability, their adaptability to a dynamic network environment, and the evaluation mechanisms used. Based on this analysis, we finally present emerging trends and identify research gaps in the literature.
As network scale and complexity escalate, fine-grained monitoring has become critical for operation, adminis tration, and maintenance. In-band network telemetry (INT) offers a leading solution for end-to-end visibility by embedding device states directly into packets. However, its widespread deployment faces a fundamental chal lenge, the inherent conflict between comprehensive visibility and limited network resources. To address this, the orchestration of INT is crucial. In this paper, we define in-band network telemetry orchestration (INTO) as a control mechanism that performs the unified modeling, planning, and scheduling of telemetry tasks to determine their triggering modes, coverage, and execution paths under resource constraints. Building on this definition, we provide a comprehensive and structured survey of INTO. With the introduction of a system-level constraint ab straction and a structured taxonomy, we present a thorough analysis of the current INTO research. Specifically, we analyze active INTO from both task-driven and method-based perspectives, and examine passive INTO fo cusing on flow selection and data reduction mechanisms. Furthermore, we conceptualize hybrid INTO as a joint optimization problem that coordinates multi-modal telemetry. Finally, we outline open challenges and future directions to guide the evolution of network telemetry.
Networked Control Systems (NCSs) are an essential component of modern cyber-physical applications, such as industrial automation, smart infrastructure, healthcare, and Industry 5.0 systems. NCSs are still affected by their continuing technological limitations despite rising adoption rates, coupled with new sustainability issues that have not been adequately addressed in the literature. This article is a hybrid systematic and bibliometric review of 240 peer-reviewed journal and conference articles published between 2013 and August 2025, according to the PRISMA 2020 guidelines. This paper identifies and systematically classifies existing challenges, patterns of co-occurrence of issues through bibliometric mapping, and major gaps in designing sustainable NCSs. The findings suggest that the most frequently reported challenges include communication-related impairments, especially network induced delays, packet loss, and quantization. These factors are highly interdependent and have far-reaching impacts on system stability and control performance. Nonetheless, the area of sustainability, including energy efficiency and resource optimization, is discussed in a fairly narrow range of research, which presents a gap between performance-focused and sustainability-aware research. In addition, although recent research investigates the integration of IoT and AI to enhance flexibility and efficiency, their contribution to the overall optimization of control performance and energy use is not well developed. The systematic review combined with bibliometric mapping allows for a systematic synthesis, which helps to connect the challenges of technological use to the aspects of sustainability and identify unexplored research perspectives. These findings establish a rigorous foundation for advancing NCSs toward fully integrated control–communication–sustainability paradigms, wherein latency-aware, energy-efficient, and AI-driven control strategies are not only desirable but essential for next-generation system performance and resilience.
RGB-thermal salient object detection (RGB-T SOD) leverages complementary RGB and thermal modalities to improve robustness under challenging conditions such as low illumination, occlusion, and adverse weather. Despite rapid progress in this area, a comprehensive and up-to-date survey of methodological developments remains unavailable. This survey provides a systematic review of 91 RGB-T SOD studies published up to April, 2026, covering the evolution of the field from early machine learning approaches to recent deep learning-based methods. Particular attention is given to emerging technologies, including vision foundation models and diffusion models. Deep learning-based approaches are analyzed from both architectural and technological perspectives and are organized into three functional components: feature extraction, feature enhancement and fusion, and decoding strategies. To support objective comparison, we present a quantitative evaluation of 37 representative models and an attribute-based analysis of 25 methods, characterizing their behavior across diverse and challenging scenarios. Based on this analysis, we identify key limitations and distill major research trends, concluding that cross-modal knowledge transfer and the integration of large-scale multimodal models constitute promising directions for future RGB-T SOD research. All reviewed methods are systematically categorized and maintained in a publicly available GitHub repository https://github.com/LLiSJ-web/Awesome-Salient-Object-Detection/tree/main to support reproducibility and ongoing development.
Recently, numerous table intelligence (TI) tasks have experienced rapid advancements, driven by the rise of large language models (LLMs). However, these tasks remain highly fragmented and lack a structured and comprehensive synthesis from a global perspective, hindering the identification of overarching trends and challenges. Moreover, this fragmentation prevents the establishment of a systematic evaluation framework in the domain of TI and impedes the accurate assessment of LLMs in TI tasks. To tackle the aforementioned problem, in this survey, we propose a systematic taxonomy encompassing all TI tasks and conduct a comprehensive analysis of existing works. Furthermore, we construct a general benchmark dataset based on TI taxonomy to evaluate the performance of leading LLMs and explore future directions, opportunities, and challenges in TI domain for in-depth research.