
In this paper, we model the carrier shutdown in multi-carrier mobile networks as a deep reinforcement learning (DRL) problem. The proposed modelling framework performs energy-saving actions by selectively turning off carriers and intelligently reallocating their users consistently with temporal variations of users' density. In addition to maintaining service continuity, our policy further guarantees a novel user experience metric. Leveraging real and recent datasets, we train and evaluate our model over realistic network scenarios. Our results show more than 15% energy saving with the fulfillment of the user experience constraints, outperforming currently deployed solutions and researched approaches in the literature by almost 50%. More interestingly our approach exhibits generalization properties, a very promising characteristic for its adoption in real mobile networks deployment.
The integration of federated learning (FL) and multi-access edge computing (MEC) is a promising direction for next-generation wireless network. However, their joint deployment faces challenges from the limited bandwidth of edge devices (EDs), possible exposure of training information through transmitted updates, and Byzantine vulnerabilities in both EDs and edge servers (ESs). To address these challenges, this article proposes CEBTFL, a communication-efficient and Byzantinetolerant FL for MEC. Specifically, CEBTFL integrates four collaborative mechanisms: i) a sign-optimized momentum update (SOMU) to reduce communication overhead while maintaining model accuracy and data privacy; ii) a lightweight directional screening at ESs that employs cosine similarity-based trust evaluation to suppress unreliable local updates; iii) a hybrid projection consensus at the cloud server (CS) that combines real and dummy data projections for robust global aggregation; and iv) an error-compensated mechanism to stabilize convergence under gradient compression. Theoretical analysis demonstrates that CEBTFL maintains stable convergence, while dummy data can enhance Byzantine robustness. Comprehensive experiments show that CEBTFL sustains high model accuracy and communication efficiency, even with up to 60% Byzantine EDs and 40% Byzantine ESs.
Unmanned aerial vehicle (UAV) swarm provides effectively and diversely applications in low-altitude networks. However, due to the non-stationary open nature wireless environments, and the untrusted UAVs can participate in wireless communication tasks, which cause severe security threats. In this paper, we consider an integrated communication, sensing, computation and security framework, where the swarm UAV carried reconfigurable intelligent surfaces (ARIS) cooperative for communication task offloading with the existence of untrustworthy ARISes. Specifically, we propose a secure collaborative communication task offloading framework, which is federated multiagent deep deterministic policy gradient with the score-trust based aggregation refinement (FedMADDPG-STAR) strategy. In this framework, each ARIS agent learns local trajectories under limited observations and periodically uploads model parameters rather than the raw data to a global server for aggregation via FedMADDPG. On the other hand, the proposed STAR algorithm enhances robustness by comprehensively considering the consistency of training directions, training progress, and multivariate anomaly indicators, thereby enabling adaptive trust scoring and isolation of untrustworthy ARISes. In addition, to increase the training stability and the efficiency of the proposed FedMADDPG-STAR, we design the refined reward function and employ the fast optimal phase-shift configuration. The system complexity is then analyzed. Simulations comparing different robust aggregation methods under various Byzantine attacks demonstrate that our proposed STAR scheme outperforms the typical aggregation approaches. We find that the proposed FedMADDPG-STAR framework can achieve secure and efficient communication task offloading under the non-stationary open nature wireless environments and the Byzantine attacks.
Wireless Power Transfer (WPT) is widely used to replenish energy for the devices in Wireless Rechargeable Sensor Networks (WRSNs). The existing studies typically assume that chargers provide free charging service strictly follow the assigned scheduling results. However, the chargers may be owned by individuals, who expect to profit from energy trading, and may take strategic behaviors to increase their own profits. Moreover, the adversaries could infer the charging costs of chargers from the scheduling results. This exposes energy trading in WRSNs to persistent threats from both incentive attack and inference attack. To address these challenges, we propose a budget-constrained auction-based model for directional charging service in WRSNs, and formulate the Charger Deployment problem for Utility Maximization (CDUM) under the budget constraint. We adopt the auction theory and differential privacy technique to design a novel directional Charger Deployment Mechanism based on budget-feasible auction with Personalized Privacy Preserving (P $^{3}$ CDM). P $^{3}$ CDM determines the charger deployment strategy and payment for each charger based on probability distributions. The theoretical analysis demonstrates that P $^{3}$ CDM achieves computational efficiency, truthfulness, individual rationality, differential privacy, and utility maximization. The experimental results show that P $^{3}$ CDM reduces privacy leakage by an average of 71.4% compared with other privacy-preserving algorithms. Compared with other benchmarks, P $^{3}$ CDM only incurs an increase of 5.64% in payment, and 24.1% reduction in utility. The field experiments further demonstrate that P $^{3}$ CDM achieves the same utility as the non-privacy-preserving algorithm, with the cost of 4.32% increase in average payment per charger, while preserving charging cost privacy.
Many real-time mobile applications, such as video conferencing, virtual reality, and industrial internet of things (IIoT) control, impose strict deadlines on packet arrivals. Multipath transmission, supported by most modern mobile devices through both Wi-Fi and cellular interfaces, can enhance the performance of these real-time applications. However, most existing multipath schedulers fail to jointly consider deadline requirements and the monetary costs of using multiple paths, where cellular data plans are generally more expensive than Wi-Fi plans. To address this issue, we propose a Deadline-aware Multipath Packet Scheduler, DaMPS, designed to prioritize packet delivery within packets' deadlines in wireless mobile networks. DaMPS performs intelligent scheduling via optimization and adapts its decisions to varying network dynamics based on a Multi-Armed Bandit (MAB) technique. To further reduce the monetary costs associated with transmission, we introduce a Cost-aware extension for DaMPS, named CaDaMPS, to select cost-effective paths while ensuring deadline satisfaction. We implement DaMPS and CaDaMPS in MPQUIC and evaluate their effectiveness under various network conditions using Mininet. Our extensive experimental results show that DaMPS and CaDaMPS improve deadline adherence by 6.37%$\sim$63.05% and 5.32%$\sim$61.44%, respectively, while maintaining high throughput and low latency comparable to those of other schedulers. Moreover, CaDaMPS reduces the average cost per packet by 20%$\sim$59% without compromising deadline requirements.
Low-power wide area networks (LPWANs) have gained significant traction in recent years, with LoRaWAN (long-range WAN) emerging as a prominent representative. Recently, LoRaWAN has expanded into the 2.4 GHz unlicensed band to support global deployments and higher data rates. However, this shift introduces severe cross-technology interference (CTI) from coexisting Wi-Fi networks that share the same spectrum, leading to substantial communication failures. As a physical-layer solution to this problem, this paper presents CoWiL to combat CTI from Wi-Fi to LoRa (the physical layer of LoRaWAN) in the 2.4 GHz band for better coexistence between LoRaWAN and Wi-Fi networks. Existing approaches address this problem by compromising Wi-Fi performance or assuming that Wi-Fi interferes with only a small portion of LoRa signals. Unlike them, CoWiL does not affect normal Wi-Fi communications and remains effective across varying levels of CTI. This is achieved by implementing CoWiL at the LoRa receiver side to directly extract LoRa data out of the CTI from Wi-Fi. Specifically, CoWiL leverages the temporal correlation between the preamble and payload of a LoRa signal, using the demodulated preamble to construct a frequency bin mask that aids in robust payload decoding. Experimental evaluations in diverse real-world settings demonstrate that CoWiL reduces the LoRa packet error rate by up to 90% compared to state-of-the-art methods under Wi-Fi-induced CTI, significantly enhancing coexistence performance.
WiFi fingerprint-based localization technology utilizing Received Signal Strength Indicator (RSSI) has gained significant attention due to its deployment convenience and cost efficiency. While existing methods rely extensively on offline-trained models, deep learning-based localization systems remain highly vulnerable to adversarial attacks that severely degrade localization performance. To address these challenges, this paper proposes a new diffusion-inspired localization defense method named as SRLoc to reconstruct clean RSSI signals from adversarially perturbed inputs. Instead of relying on the multi-step stochastic iterations which are typical of standard diffusion models, SRLoc employs a highly efficient single-step conditional denoising network and utilizes the attack intensity directly as a conditioning vector rather than traditional time steps. Furthermore, the model replaces the conventional U-Net upsampling module with a 1D transposed convolutional architecture tailored for sparse RSSI data, and is optimized with a customized triple-loss function. This function strategically imposes physical space limits and geographical consistency constraints on the basis of standard robust Huber loss, ensuring that the reconstructed signals remain physically plausible. Experimental results demonstrate that the SRLoc effectively defends against adversarial attacks on both the CJU dataset and Tampere dataset in comparison with four state-of-the-art methods and five baseline methods, while maintaining excellent localization performance. On the CJU dataset, the SRLoc can resist 86.5%, 80.8%, and 76.9% of the attacks from FGSM, PGD, and MIM respectively, outperforming the best comparative method by 9.2%, 12.6%, and 15.8% under attack intensity of 0.2. On the Tampere dataset, the SRLoc achieves attack resistance rates of 95.7%, 92.6%, and 94.6% against FGSM, PGD, and MIM respectively, surpassing the best comparative method by 10.6%, 6.8%, and 6.8%. Furthermore, SRLoc maintains excellent defensive capability even when facing unknown and black-box attack types. These results indicate that the SRLoc method effectively mitigates localization errors induced by adversarial attacks, thereby significantly enhancing the robustness of the localization model.
Visible light positioning (VLP) is a promising indoor localization technology with strong interference immunity and easy integration with existing infrastructure. However, most existing VLP systems rely on multi-anchor deployments and Received Signal Strength (RSS), which are costly to deploy and remain sensitive to receiver pose and ambient light. To address these limitations, we propose a single-anchor LED-array localization framework based on Phase-Difference (PD) fingerprints and Graph Neural Networks (GNNs). First, to mitigate the sensitivity of RSS and the complexity of multi-anchor geometry, we introduce the first single-anchor PD LED-array localization scheme. By encoding positional information in inter-LED PDs, this design eliminates the need for multi-anchor surveying and synchronization, suppresses slow illumination drifts. Second, to handle the instability of raw measurements, we develop a robust fingerprint construction pipeline that begins with photodiode samples and performs inter-LED phase estimation, temporal unwrapping with outlier rejection, wrap-safe sine–cosine embedding, and normalized storage in a compact database. Third, to address the limitations of heuristic K-nearest-neighbor matching, we propose a query-centric GNN-based localization framework that encodes physics-aware similarity cues in node features and learns geometry-aware neighbor weights. We evaluated the proposed method in four representative indoor scenes against ten baselines. Results show that PD fingerprints consistently outperform RSS fingerprints, and the proposed GNN further improves accuracy. It achieves mean errors of 0.26 m and 0.43 m in the corridor and office–corridor scenes, respectively, and reduces the mean error by up to 56% compared with the strongest baseline. These results demonstrate a scalable and robust pathway to high-accuracy VLP with lightweight infrastructure.
Federated learning (FL) is susceptible to poisoning attacks, where malicious clients manipulate local data or models to disrupt training. The system and data heterogeneity inherent in practical FL systems exacerbates these vulnerabilities, rendering existing defense mechanisms ineffective or infeasible. Specifically, distinguishing benign local models, trained on heterogeneous client data, from poisoned ones presents a significant challenge. Moreover, semi-asynchronous FL (SAFL) paradigms, commonly employed to address system heterogeneity, further complicate this issue by preventing fair evaluation of local models originating from different global models (i.e., with varying staleness). In this work, we propose a novel defensive framework (namely Fed-Beta) for robust and accurate FL model training under system and data heterogeneity. First, we introduce a staleness-aware SAFL paradigm, where the server accepts only a fixed number of local models per round and groups them based on their staleness. Then, we implement a two-stage aggregation mechanism. Specifically, we develop a robust intra-group aggregation method using model inversion to evaluate data-domain discrepancies among clients. This method accurately identifies and excludes malicious local models from aggregation, producing a reliable representative model for each group. Moreover, we design a model-consistency-aware inter-group aggregation method, which selectively aggregates group representative models with consistent update directions to update the global model. Theoretically, we conduct rigorous convergence analysis of Fed-Beta, offering insights into how system and data heterogeneity affect the defensive performance. Empirically, extensive experiments corroborate its superiority over existing schemes.
Wireless Rechargeable Sensor Networks (WRSNs) have become a key enabler of the Internet of Things. There are directional wireless chargers capable of emitting multiple charging beams to charge the nodes in WRSNs via Wireless Power Transfer technology (WPT); yet most existing research on antenna charging direction selection assumes a single-beam model, leading to the selection of a suboptimal antenna direction set. In addition, prior research mostly focuses on two-dimensional networks and lacks effective solutions for three-dimensional (3D) scenarios. In this paper, we investigate the Charging Scheduling problem using a Unmanned Aerial Vehicle (UAV) with Dual-Conical Charging Beams in 3D-WRSNs (CSUDB-3D) for charging the nodes in the network and prove it to be NP-hard. To address this challenge, we first tackle the problem of antenna direction set selection from the infinite-size entire 3D spherical direction set by elegantly designing an algorithm via exploiting the geometric properties among the nodes. We prove that this algorithm guarantees to return an antenna direction set with the minimum size that is functionally equivalent (FuncEqv)-meaning it ensures the same optimal scheduling performance-to the original infinite 3D spherical direction set, and hence name it the Minimum FuncEqv Direction Set Algorithm (MFEDS). Then, the Lin-Kernighan Heuristic (LKH) algorithm is adopted to determine a quasi-optimal charging tour for the UAV to charge the nodes. By integrating MFEDS and LKH, we build a three-step framework termed Scheduling of a UAV Charger with Dual-Conical Charging Beams in 3D-WRSNs (UAVDCB-3D) to effectively solve the CSUDB-3D problem. Simulation results demonstrate that UAVDCB-3D outperforms the best existing benchmark in terms of both total energy loss and time span. Specifically, it reduces total energy loss by up to 51.10% and the time span by up to 46.15%.
Multi-access edge computing provides an effective computation offloading paradigm for resource-constrained vehicles by deploying resources at network edges. However, high vehicular mobility and heterogeneous task demands lead to spatio-temporal load imbalances across static roadside units (RSUs). Prior works either lack responsiveness to sudden workload surges or exhibit poor robustness under sustained fluctuations. To fill this gap, we explore an aerial-terrestrial cooperative design, leveraging UAV assistance and cross-RSU task migration to enable responsive surge absorption and system-wide robustness. Nevertheless, achieving preemptive UAV position scheduling and anticipatory cross-RSU task migration remains challenging. We argue that proactive prediction of future dynamics is crucial for guiding timely and collaborative decision-making. On this basis, we propose a Dynamics-Aware Hierarchical Multi-Agent (DHMA) deep reinforcement learning approach that jointly optimizes UAV position scheduling and vehicular computation offloading. Additionally, we develop a prediction-driven observation augmentation method to enhance the perception capabilities of agents for future dynamics based on predicted workload surges and vehicular movements. Comprehensive evaluation across four simulation scenarios, together with real-world validation, demonstrates the effectiveness, robustness, and practical viability of our approach.
Low Earth orbit (LEO) satellite networks have evolved into a pivotal communication infrastructure due to their global coverage, low propagation delay, and high deployment flexibility, where a domain-partitioned architecture is typically employed for scalability. However, the extreme topological dynamics caused by continuous orbital motion, combined with the pronounced network heterogeneity across different control domains, pose substantial challenges for efficient and reliable routing. Conventional routing methods, which often rely on relatively stable topology structures, struggle to handle frequent link disruptions, rapid path-length variations, and constantly changing neighboring satellite sets. To tackle these challenges, this paper proposes a meta-learning routing framework built upon a discovering reinforcement learning (RL) optimization mechanism for dynamic and heterogeneous LEO satellite networks. The framework employs meta-optimization to automatically generate adaptive RL update rules, enabling agents to rapidly adjust their routing behaviors under heterogeneous and time-varying network conditions. Simulations reveal that the proposed approach effectively decreases energy consumption and delay while maintaining strong adaptability and scalability across diverse LEO sub-networks.
Accurate identification of mobile traffic is fundamental to network management and security. However, the explosive growth and frequent evolution of mobile applications present a formidable open-set challenge, rendering conventional models trained in a closed-world setting prone to performance degradation. While signature-based methods are often perceived as more adaptable to real-world network environments, the design of their matching patterns relies excessively on manual expertise, and they exhibit insufficient accuracy for identifying encrypted traffic. Conversely, machine learning (ML) approaches uncover latent features but are notoriously sensitive to training data and typically fail in open-set scenarios by misclassifying unknown traffic. Current research predominantly refines ML frameworks, largely overlooking how principles of signature-based methods can guide ML toward robust open-set identification. To bridge this gap, we propose DualEvo, a dual-stage evolution-aware framework. First, a signature-gated filter uses automatically generated meta-feature signatures from invariant packet length segments to swiftly discard irrelevant traffic. Surviving flows then undergo contextual verification, which leverages a contextual packet length matrix and ensemble learning to confirm matches with high confidence. Experiments on 1,000 applications show DualEvo achieves a 94.46% F1 score with only 208 false positives among one million unknown traces, proving its superior accuracy and robustness in open-set environments.
Constant-envelope signals are widely used in mobile edge applications and wireless communication systems for their hardware-friendly design, energy efficiency, and reliability. However, reliable detection with simple, power-efficient receivers remains challenging. Coherent methods offer superior performance but require complex synchronization, increasing complexity and power use. Noncoherent detection is simpler, avoiding synchronization, but traditional approaches rely on in-phase and quadrature-phase (IQ) demodulators for signal magnitudes and assume energy detection without theoretical justification. This paper proposes a framework for asymptotically optimal detection using a bandpass-filter envelope-detector (BFED) under the Bayes criterion and the generalized likelihood ratio test (GLRT) with unknown amplitudes. Using standard small- and large-argument modified-Bessel-function approximations, we show that the resulting closed-form GLRT reductions are regime dependent: in the low signal-to-noise ratio (SNR) regime, the GLRT reduces to the energy detector (ED), whereas in the high-SNR regime, an amplitude detector (AD) compares the estimated amplitude with the noise standard deviation. When the instantaneous SNR regime is unknown, as in many fading or resource-constrained mobile-edge settings, we further propose a reliability-based intelligent detector (RID). RID runs ED and AD in parallel from the same magnitude samples, preserves their consensus decision, and resolves the unique one-sided disagreement branch through a weighted comparison of normalized reliability margins. Its reliability weight is calibrated offline, so the runtime implementation remains SNR-agnostic and low-complexity. The proposed asymptotically optimal detectors provide a likelihood-based theoretical foundation and enable low-complexity implementations for resource-constrained mobile-edge applications, including wireless sensor networks (WSNs) and Internet of Things (IoT) systems.
This paper proposes spiking-aided wifi sensing network (SWS-Net), a novel hybrid neural architecture that seamlessly integrates Spiking Neural Networks (SNNs) with conventional Artificial Neural Networks (ANNs) to achieve robust WiFi-based indoor sensing. WiFi signals provide a cost-effective and device-free approach for detecting human activities, gestures, identities, and other related phenomena. Nevertheless, their performance is often hampered by multipath fading and environmental noise, presenting substantial challenges. Drawing inspiration from the human brain’s remarkable ability to process noisy sensory inputs, SWS-Net combines the inherent noise resilience of spiking neuron dynamics with the powerful feature extraction capabilities of ANNs. We provide a theoretical analysis that contrasts the noise-handling mechanisms of SNNs and ANNs, demonstrating how their synergistic integration enhances both robustness to noise and efficiency during training. Extensive experiments on three representative WiFi sensing tasks show that SWS-Net outperforms baseline models by delivering superior accuracy and faster convergence, thereby confirming its efficacy in complex and dynamic indoor environments.
The user-centric network (UCN) paradigm provides a promising foundation for mobile edge computing (MEC) by mitigating severe cell-edge interference through multi-access point (AP) cooperation. However, most user-centric MEC schemes rely on ground APs, whose rigid deployment makes them vulnerable to post-disaster damage and severe blockage, delaying service recovery and restricting coverage. To address this issue, this paper develops a user-centric MEC architecture based on unmanned aerial vehicle access points (UAV-APs), which leverage rapid deployment and flexible coverage to provide more reliable services in dynamic environments. Specifically, we formulate a multi-level delay-energy coupling optimization problem that jointly accounts for task offloading and resource allocation, thereby enabling more effective optimization of both communication performance and energy consumption. The problem is challenging because shared resource competition may cause policy oscillation in parallel updates, while existing action-modeling methods remain insufficient for capturing the coupling between discrete offloading and continuous power control in the access–fronthaul–edge computing process. To solve this problem, we propose HH-SEQUEL, a novel multi-agent reinforcement learning (MARL) framework with level-wise hybrid discrete-continuous action parameterization and sequential cross-level updates, enabling end-to-end joint optimization of offloading and resource allocation under delay-energy coupling. Simulation results show that our method reduces latency by 21.39%–65.31% compared to state-of-the-art baselines, and lowers energy consumption by up to 93.89% against baseline approaches.
Semantic communications have emerged as data-driven intelligent communication paradigms. However, they raise privacy concerns regarding sensitive information within codec models and transmitted semantic contents. To address these issues, this paper designs a Full-LIfecycle Privacy-preserving Semantic Communication (FLIP-SC) system. This system covers the entire system deployment process, which consists of codec installation, codec inference, and wireless transmission. First, a TEE-shielded codec inference scheme is proposed to safeguard sensitive codec-parameter information in untrusted local deployment environments during the deployment and inference phases. Second, a semantic symbol sanitization coding scheme is developed for the transmission phase, reducing symbol entropy via tailored quantization to suppress codec-specific statistical leakage and resist model stealing attacks. Third, based on the preceding codec-level defenses, a symbol-rotary obfuscation scheme is introduced to further mitigate semantic content leakage and model inversion attacks. It achieves obfuscation through random permutation and phase perturbation, while retaining joint source-channel coding properties and avoiding the excessive overhead of conventional bit-level encryption. Extensive experiments illustrate that the proposed system effectively ensures the privacy preservation of sensitive information throughout the entire system deployment process. It provides robust protection against both model stealing and model inversion attacks, and its protection level is comparable to that of a black-box setting.
This paper proposes UW-ISAC, an integrated sensing and communication (ISAC) framework for underwater acoustic sensor networks (UASNs), aiming to manage the inherent trade-off between Age of Information (AoI) minimization and throughput maximization. Leveraging the centralized training with decentralized execution (CTDE) paradigm, UW-ISAC employs deep multi-agent reinforcement learning (MARL) for joint power allocation, transmission mode selection, and sensing-driven coordination strategies. To support low-overhead cooperation under bandwidth-constrained acoustic channels, UW-ISAC incorporates a lightweight QF-Extractor that encodes AoI-related queue states into compact decision-oriented semantic vectors, and a validity-weighted state estimation mechanism that mitigates the impact of delayed neighbor information. These components are trained within a unified MARL framework to reduce potential mismatch among separately optimized modules. Simulations on joint power allocation and link adaptation tasks demonstrate that UW-ISAC achieves strong overall trade-off management, with up to 87.2% reduction in average AoI and 180.5% improvement in throughput compared to baseline methods. UW-ISAC also improves robustness under dynamic traffic loads, reducing peak AoI by 51.9% in high-congestion scenarios. By integrating semantic-aware coordination with delay-aware decision-making, UW-ISAC provides an effective resource management approach for resource-constrained underwater networks.
In the above paper, Shariq et al. proposed PSRSD2D, a drone-to-drone (D2D) authentication scheme claimed to provide multiple security properties. However, our analysis indicates that an adversary can launch drone capture attacks against two drones to recover the root secrets of the trusted authority, leading to a system-wide breakdown. Moreover, PSRSD2D is vulnerable to ephemeral secret leakage attacks and fails to achieve forward secrecy. After analyzing the underlying causes of these flaws, we introduce targeted modifications. The enhanced protocol mitigates the vulnerabilities in PSRS-D2D and provides stronger security guarantees.
Smart homes, enabled by the Internet of Things (IoT), offer substantial convenience but also introduce security challenges. These often stem from anomalous behaviors, including improper user interactions and malicious attacks. Although various behavior-modeling methods have been proposed, userdevice interactions are often unobservable in practice due to encrypted traffic and limited vendor access, while anomaly detection models suffer severe degradation during cold start. These issues greatly limit real-world deployability. Moreover, existing approaches struggle to capture infrequent behaviors, leverage temporal context, and handle noisy user activities, resulting in suboptimal detection performance. To address these challenges, we propose HomeGuardian, a non-intrusive end-to-end anomaly detection system based on mirrored gateway traffic. It first employs a Robust Contrastive Behavior Identification (RCBI) algorithm to infer user-device interactions from encrypted traffic and obtain behavior data. Building on this, we develop an anomaly detection framework with three components: Loss-guided Dynamic Mask Strategy (LDMS), Three-level Time-aware Position Embedding (TTPE), and Noise-aware Weighted Reconstruction Loss (NWRL). LDMS enhances learning of infrequent behaviors, TTPE incorporates temporal context, and NWRL reduces behavioral noise through adaptive reconstruction weighting. To improve cold-start performance, we further introduce the Dynamic Risk Compensation Algorithm (DRCA), which maintains stable detection capability with limited historical data. Extensive experiments show that HomeGuardian consistently outperforms state-of-the-art baselines while providing accurate and interpretable results.