
The rapid advancement of the Internet of Vehicles (IoV) has significantly enhanced vehicular communication, improving transportation safety and efficiency. However, increased connectivity introduces complex cybersecurity challenges due to diverse cyberattacks. This paper proposes a hybrid ensemble learning-based Intrusion Detection System (IDS) tailored for IoV networks, integrating multiple machine learning classifiers with advanced feature selection and data preprocessing methods to improve attack detection accuracy. The model effectively addresses dataset imbalance using the Synthetic Minority Over-sampling Technique (SMOTE) and is evaluated on the CICIDS2017 dataset, which encompasses a range of known attack types. Experimental results demonstrate that the proposed approach achieves superior classification performance with a detection accuracy of 99.74%, validating the effectiveness and robustness of the hybrid ensemble model for reliable intrusion detection in complex IoV environments, offering a scalable and practical solution for enhancing vehicular cybersecurity.
The wireless Internet of Things (WIoT) networks are becoming more distributed and less resourceful, employing lighter protocols, but they are also becoming more susceptible to cyber threats. In this study, we investigate the security assessment methodology of the WIoT networks based on vulnerability taxonomy. In the present study, the diverse sources, network layer effects, and possible outcomes of vulnerabilities are intended to be classified in a unique way. The risk analysis has been covered using vulnerability analysis, threat modeling-based risk assessment, and penetration testing. Practical application scenarios can be enacted by means of systematic security assessments to make the IoT -based infrastructure secure. The importance of the proposed study is that it helps in developing security frameworks in the WIoT environment, as it addresses the specific issues of other literature on the topic.
The digital economy centralizes data control within platform corporations, creating stark asymmetries between technology giants and individuals. Data cooperatives offer a democratic alternative, yet translating cooperative principles into operational governance remains challenging. This paper introduces a three-dimensional framework aligning the ICA's seven principles with Mechanisms, Enforcement, and Tracking dimensions across six governance categories: blockchain governance, AI monitoring, federated infrastructure, transparency, democratic participation, and automated compliance. Validated through healthcare, agricultural, and mobility cooperative cases, the framework identifies reusable governance patterns that bridge cooperative theory and digital practice, advancing practical pathways toward democratic and interoperable data governance.
The quality of olive oil is a key determinant of its value, yet conventional evaluation techniques are not suited for continuous, real-time monitoring. This paper introduces the design and validation of an Internet of Things (IoT)-based electronic nose (e-nose) system for ongoing assessment of olive oil quality. The proposed system features a custom-printed circuit board (PCB) equipped with an array of metal-oxide semiconductor (MOS) sensors, controlled by an ESP32 micro-controller. An end-to-end IoT architecture was implemented to manage data acquisition, storage, and visualization. The e-nose was validated through a multi-phase experiment in which olive oil samples were subjected to accelerated degradation. Results from the most stable experimental phase confirm the system's ability to monitor changes in the oil's volatile profile over time, highlighting its potential as a proactive and non-destructive quality control tool that addresses the limitations of traditional point-in-time analysis.
Background: In the context of Industry 4.0, the integration of IoT-based monitoring systems has become crucial for managing environmental conditions in industrial environments. However, the utility of collected data depends on its interpretation and the system's ability to handle faults, noise, and incomplete readings. Aims: We aim to demonstrate the application of trend analysis techniques to IoT sensor data, focusing on interpretability and robustness in a real-world industrial environment. Method: We developed an IoT architecture and deployed in a real factory setting to monitor variables such as temperature, humidity, noise, and illuminance using sensors integrated via MQTT. We treated each sensor's time series independently, identifying local trends and generating visual forecasts up to seven hours ahead. Results: Upon using trend analysis, it allowed identification of environmental patterns and atypical behaviors even in the presence of missing data or unstable transmission. The projected trends provided interpretable insights that may support decision-making in operational contexts, contributing to safety and environmental control in industry settings. Conclusions: The usage of trend analysis proved to be a viable strategy for enhancing the interpretation of IoT-based environmental monitoring through physical sensors.
The increasing scale and complexity of Industrial Internet of Things (IIoT) systems demand communication architectures that balance performance, scalability, and maintainability. Although publish-subscribe communication is widely regarded as the de facto standard for decoupled IoT-cloud integration, a comprehensive empirical comparison with direct request-reply architectures remains limited, particularly under realistic IIoT conditions. In this work, we evaluate three IoT-cloud architectures: a direct HTTP-based model, a single-protocol MQTT-based model, and a hybrid model combining MQTT and Apache Kafka. Using a custom testbed with up to 40 virtual IoT devices and four network profiles, we assess latency, throughput, and CPU usage. The evaluation results show that MQTT outperforms HTTP in latency and throughput, while the hybrid model provides extensibility at the cost of higher latency.
The exponential growth of the Industrial Internet of Things (IIoT) network has increased the risk of malware attacks, which can be a great threat to data integrity and system reliability. Conventional malware detection methods are not always robust, scalable, and interpretable and thus are not effective in very dynamic environments. Accordingly, this paper proposes a meta-ensemble deep learning model that combines VGG16, ResNet50, ResNet101, and DenseNet121 via a meta-learner to classify malware using image-based representations of executable files. The proposed model was evaluated experimentally to have an accuracy of 95%, which was higher in comparison to all of the baseline models, such as VGG 16 (92%), ResNet50 (90%), ResNet101 (89%), and DenseNet121 (88%). The meta-model achieved 97 percent benign precision and 98 percent malware recall in class-wise performance that significantly lowered the false positive rate and increased the detection sensitivity compared to standalone models. The Grad-CAM explainable AI (XAI) method was used to generate visualization of the class-distinctive regions, allowing interpretability and increasing the trust level of the analyst. These findings point to the conclusion that the proposed meta-ensemble framework provides a more scalable, interpretable, and robust solution to malware detection and therefore exhibits promising prospects in the security of IIoT networks.
Fog computing brings processing and storage closer to data sources, aiming to reduce latency and communication overhead in distributed systems. Although reference models such as IEEE 1934 (OpenFog) provide high-level guidelines, practical architectures that address interoperability, scalability, and co-ordination across fog domains remain limited. Previous studies have examined container placement, hierarchical scalability, and multi-layer orchestration, but direct inter-fog communication and modular abstractions are less explored. This work presents a modular architecture that organizes fog nodes into protocol, processing, and service layers, supporting configurable services and request redirection between domains. A prototype was implemented using Docker containers representing smart city devices operating with HTTP and CoAP protocols. An experimental evaluation illustrates how the architecture manages request distribution, protocol handling, and data consolidation across environments. These results show the adequate performance of the proposed fog computing modular architecture for smart cities.
This work presents an experimental vulnerability evaluation in a WPA3-Enterprise scenario to evaluate the performance of the current WPA3 security methods over different devices and operating systems, including iOS, macOS, Ubuntu, and Windows. We constructed a testing infrastructure with Kali Linux and employed the ALFA AWUS036AXML adapter, in combination with Hostapd and FreeRADIUS software, to setup RADIUS servers and a rogue access point. We evaluated multiple client connection situations to a rogue access point utilizing three device configurations: Safe (compulsory CA certificate verification), Weak (server certificate verification disabled or CA not installed), and Mixed (device trusts the non-valid CA certificate). The experimental results indicated that Evil Twin attacks were effective against clients operating on Ubuntu 24.04.2 and Windows 10, attributable to inadequate certificate verification configurations. We provided guidelines to mitigate risks.
IoT technology has rapidly grown in recent years, both in terms of research and product development. The usage of IoT technology is growing in a variety of Smart Home applications, such as Smart Home Security, as a result of the development of technologies like 5G network and BLE as well as the appearance of faster and more compact embedded systems. In this project, we implemented a Smart Door Lock capable of being controlled by the user's smartphone in a user-friendly and secure way, using BLE and IoT technology. This system focuses on capabilities that let the user remotely grant access to his Smart Door Lock, which makes it a great resource for rental housing environments. The final developed system could be given a level 4 classification on the Technology Readiness Level scale, which is equivalent to a technology validated in a lab, and it could easily be improved to a level 5 classification, which corresponds to a technology validated in a relevant environment.
The rapidly expanding telecommunication industry offers consumers a wide range of services in response to the swift technological growth and convergence. The presence of multiple operators within the same geographic regions has intensified market competition. Although, customer acquisition strategies remain vital, customer retention has emerged as an equally critical component of business sustainability. In particular, retention strategies are often more cost-effective than acquisition efforts, Customer retention can be ensured with the help of Customer Churn Prediction (CCP). This churn prediction can be performed using forecast analysis and machine learning approaches to determine which customers are expected to cancel their subscriptions in future. Timely measures can save a telecom industry from losing churned customers. In the existing literature, machine learning classification has been used to analyze the churn however, the problem of highly imbalanced nature of dataset needs further investigation. In this paper, the contribution is twofold: Firstly, we investigate how different over-sampling techniques mitigate the effects of class imbalance and how better accuracy can be achieved in CCP. To achieve this, numerous experiments have been conducted on a publicly available dataset. The experimentation included five oversampling techniques which are Random Oversampling, SMOTE, SVM SMOTE, Borderline SMOTE, and ADASYN. We have applied twelve different machine learning classifiers as our base classifiers. The purpose of using multiple classifiers as base classifiers is to investigate the heterogeneous nature of classifiers for churn prediction. Secondly, the predictions from these base classifiers are sent to a multi-layer perceptron-based meta-classifier using the stacking ensemble learning method. Furthermore, we have analyzed all these classifiers and meta-classifiers with the original dataset with and without doing oversampling. The results indicate that the proposed approach has a comparatively better accuracy and F1 scores.
This paper presents the design and evaluation of an integrated mobile system to support product localization and indoor navigation within supermarkets. Using augmented reality for real-time visual guidance, computer vision for shelf-level recognition, and QR-code-based markers for accurate spatial initialization, the system bridges the gap between virtual and real store environments. The solution utilizes a React Native frontend and a backend built with FastAPI, PostgreSQL, and PyTorch. Experimental results validate its technical viability, demonstrating world alignment and shelf detection, while addressing BLE signal instability and image processing latency. The proposed architecture proposes a foundation for retail navigation systems, aimed at delivering scalable, accurate, and user-friendly in-store experiences.
Computers are shifting from being general-purpose devices to becoming more specialised ones. This trend can especially be recognised when looking at the Internet of things (IoT) field. In the particular case of IoT, power consumption is a critical issue that is addressed by relying on minimalistic devices, such as microcontrollers. Concretely, minimalistic first means that the computing performance and the memory capacity are reduced to a minimum. In this situation, it is challenging to operate a display from the device to report information to the user. Existing solutions circumvent this problem for instance by providing character-only displays. However, most of them only support Latin characters, leaving, for example, Far Eastern cultures aside. In this paper, we propose an output solution that not only supports the Roman letters but also major character sets of the Chinese Japanese Korean (CJK) notoriously difficult group. Furthermore, we show that the cost efficiency and performance overall of our proposal are better than those of previous works.
The rapid growth of IoT devices has raised global demands for enhanced security. In Japan, the Information-technology Promotion Agency (IPA) launched the JC-STAR program to evaluate and certify the security compliance of IoT devices. Manual assessment, however, requires extensive expertise and effort due to the diversity of devices and the vast amount of product documentation, highlighting the need for automation. In this paper, we propose an automated security compliance evaluation method using hierarchy-aware RAG (Retrieval-Augmented Generation) and LLMs (Large Language Models). The proposed method effectively extracts relevant information from device documents and evaluate security compliance using the retrieved document chunks. Unlike conventional retrieval, our approach exploits document hierarchies to identify the section most relevant to the query and coherently retrieve its associated content, thereby providing richer context and reducing hallucinations. Experiments on three devices showed that our method outperformed or matched a baseline across all metrics. In particular, for a device with a large-scale document, it achieved notable gains in TPR and F-measure.
Wireless Body Area Network (WBAN) significantly enhances e-health by improving patient care and monitoring. However, ensuring the privacy of Electronic Health Record (EHR) remains a key challenge due to attacks, such as data disclosure, patient location and identity tracking, and sensor data tampering. These issues lead to misdiagnoses or inappropriate treatment. In this paper, we propose a context-aware, privacy-preserving protocol using Transaction Pseudonyms (TPs) to generate one-time, unlinkable identifiers for each patient-doctor interaction. Our protocol introduces a lightweight, distributed mechanism for pseudonym management, strengthened by a Random Contextual Refresh (RCR) function. The RCR triggers TPs regeneration based on randomized time intervals or minor stochastic variations in the patient's contextual data, reducing pseudonym reuse and correlation while preserving unlinkability with minimal overhead. Performance evaluations show that the proposed protocol outper-forms existing schemes in both efficiency and patient privacy protection.
A planar metamaterial lens-based single-element circularly polarized (CP) antenna for millimeter wave (mm-wave) band applications is presented. The proposed antenna consists of a modified patch excited by a single-point-fed coaxial probe and two displaced layers of a novel meta-lens design. The modified structure allows for the simultaneous excitation of orthogonal components with equal magnitudes. To realize the gain enhancement of the proposed design, a novel meta-lens is designed based on meta-atoms of subwavelength size arranged in a disconnected cross-shape repeated pattern. To effectively focus the outgoing CP wave radiated by the antenna, the focal distance is meticulously optimized. Two layers of the same lens are used to enhance the antenna gain. Following a rigorous numerical analysis and optimization, the proposed design is fabricated and experimentally validated. The comparison of the results with the lens and without the lens illustrates that a 4 dB gain improvement is attained with the compact lens configuration. Furthermore, the antenna features a wide impedance bandwidth (S11) from 24 GHz to 31 GHz and the axial ratio (AR) below 3 dB within the same operating band. The proposed design offers multiple advantages, including a simple geometrical configuration, light in weight, and ease of integration due to the planar lens structure. The proposed antenna is suitable for multiple modern communication systems, including short-range radar systems and other line-of-sight mm-wave applications requiring fixed-beam and high data rates.
Simulation-based Digital Twins are increasingly used for decision support in manufacturing. This paper examines peer-reviewed studies to evaluate how, and to what extent, decision support is automated in existing Digital Twins implementations. We analyze each implementation across six dimensions: (i) the domain of application, (ii) the main goal, (iii) the methodology used to develop or extract the Digital Twin model, (iv) the decision support methodology, (v) the level of automation, and (vi) the main gaps and limitations of the implementation. Across the reviewed studies, automation remains partial; no implementation achieved fully autonomous end-to-end operation of the Digital Twin. Building on this analysis, we identify key enablers and barriers to automating decision support in Digital Twins, with a primary focus on the manufacturing domain. Based on these findings, we outline research priorities to help close the decision support automation gap in Digital Twins, emphasizing the importance of human oversight, risk-aware control, and data privacy and security. In addition, we emphasize the importance of generalizability and scalability, and the evaluation of decision outcomes and Artificial Intelligence components. Overall, this review clarifies the current state of automation in decision support within Digital Twins and highlights targeted areas for future development toward fully autonomous decision support in Digital Twins.
This work addresses the digital transformation and Industry 4.0 context, emphasizing the growing relevance of Digital Twin (DT) systems. Despite the potential of existing proprietary DT solutions, they often present practical limitations such as cost, lack of interoperability, and limited customization. To overcome these challenges, this paper proposes an open-source methodology for selecting and implementing a simplified DT architecture. The first phase involved a review of existing solutions, the definition of evaluation criteria weighted through the Analytic Hierarchy Process (AHP) method, and the application of the Technique for Order Preference by Similarity to Ideal Solution (TOPSIS) decision-making model. This multi-criteria approach enabled the comparison of different platforms and justified the choice of Eclipse Ditto as the systems core. In the second phase, a practical case study was developed in a smart classroom scenario, integrating virtual sensors and simulated actuators. The implemented architecture enabled data ingestion and transformation into the Ditto Protocol, time-series storage in InfluxDB, monitoring through dashboards in Grafana, automatic actuation via mapping rules, three-dimensional simulation in Unity, and contextualized analysis with a Local Language Model (LLM) (via Ollama). The results validate the technical feasibility of the proposed approach, demonstrating reliable, modular integration, and scalability potential. Limitations were also identified, including reliance on public brokers and maturity challenges in 3D modules. This work contributes both a functional proof of concept and a structured methodology for platform selection, offering a solid foundation for future research and real-world applications.
The expansion of Internet of Things (IoT) devices has been accompanied by escalating malicious activities targeting their vulnerabilities. Fuzzing is an effective technique for discovering unknown vulnerabilities, with methods such as AFL and Snipuzz widely adopted. However, existing approaches often fail to apply to certain IoT devices, particularly those that conceal detailed error messages for security reasons or have closedsource implementations. This paper proposes an LLM-based IoT fuzzing test case generation method that remains effective under such constraints. By leveraging IoT communication logs and the reasoning capabilities of large language models (LLMs), our method preserves input format consistency while also inferring conditions that may trigger specific vulnerabilities. It then generates test cases tailored to efficiently induce such vulnerabilities. Evaluation results demonstrate that our method successfully detected vulnerabilities that both existing and baseline fuzzing techniques failed to uncover.
The increasing convergence of information technology (IT), operational technology (OT), and Internet of Things (loT) devices in manufacturing systems introduces unprecedented cybersecurity challenges. Traditional protection mechanisms, designed for static enterprise environments, lack the adaptability required to counter multi-vector attacks that propagate across industrial and loT domains. This paper presents a modular, adaptive orchestration framework that integrates real-time monitoring, analytics, and automated response within a unified architecture. Implemented and validated in a Manufacturing Cyber-Physical System (CPS) deployed on the Ludus cyber-range platform, the framework leverages Infrastructure-as-Code (IaC) principles to ensure reproducibility, scalability, and interoperability across IT and OT infrastructures. Benchmarking under four adversarial scenarios—credential theft, lateral movement, unauthorized Modbus operations, and data exfiltration—demonstrates measurable improvements, including a 16.7% increase in detection accuracy, 41.5% faster response, and 35% reduction in recovery time, with minimal resource overhead. The results confirm that adaptive, IaC-driven orchestration significantly enhances the responsiveness and resilience of IoT-enabled industrial networks. The proposed architecture provides a replicable foundation for future research on autonomous, self-healing cybersecurity mechanisms in critical manufacturing environments.