Research Context: The rise of Cloud, 5G, and IoT demands the continuous control of millions of networked devices. While Software-Defined Networking (SDN) simplifies network management, it struggles with security and the fine-grained analysis necessary for reliable operational problem detection. Scientific Problem: A critical architectural gap exists as there is no standardized, flexible framework to catalog diverse network scenarios and automatically associate them with the most effective Computational Intelligence (CI) techniques. This lack of a self-learning structure severely hinders the intelligence of the SDN control layer. Proposed Solution: We present a novel, technology-agnostic Reference Architecture for anomaly detection, applicable to both SDN and traditional networks. This highly resilient design leverages hexagonal microservices and rigorously adopts the TM Forum’s Open Digital Architecture (ODA) model (TAM and eTOM) to achieve crucial industry standardization and interoperability. Related IS Theory: Work Systems Theory (proposing a systemic framework for an organizational process) and Institutional Theory, highlighted by the strategic adoption of ODA/TM Forum standards to ensure industry legitimacy. Research Method: An experimental methodology utilizing a Proof-of-Concept (PoC) prototype validated the architecture. We trained and assessed seven distinct Machine Learning (ML) algorithms against two different public datasets, proving the architecture’s inherent versatility. Summary of Results: Results confirm the absolute need for a flexible architecture, as the solution model varies significantly across scenarios. The analysis showed that the choice of the most effective algorithm is strictly contingent upon the specific anomaly type and the chosen evaluation metric. Contributions and Impact to IS Area: The main contribution is a standardized Reference Architecture that standardizes the evaluation, promotion, and application of diverse computational intelligence techniques according to the network context. This provides a blueprint for next-generation, self-learning, and standards-compliant network operations, marking a significant step towards truly autonomous networks.
This paper introduces a fast-converging learning framework for residential energy consumption forecasting, named Federated Decision Tree (FEDT). FEDT integrates Federated Learning (FL) with Internet of Things (IoT) infrastructure and employs decision tree models for decentralized training across heterogeneous edge devices. The framework incorporates one client-side training strategy and four server-side aggregation mechanisms to collaboratively construct a global decision tree model. FEDT was fully implemented and evaluated on diverse platforms, including Raspberry Pi, Android smartphones, and personal computers (PCs). Experimental results show that FEDT stabilizes by the 17^th round with approximately 80 trees per client, outperforming FedAVG, which requires 38 rounds to reach comparable performance. The fast-converging global training achieves forecasting errors below 2
Research Context: Brain-computer interfaces (BCI) are systems that capture brain signals through techniques such as electroencephalography (EEG), processing these signals for various applications, especially in the control of devices for people with motor limitations. Despite the benefits, there are security concerns, including adversarial and cybersecurity attacks. Due to the emergence of brain-computer interaction devices on the market, it is necessary to analyze the security of these devices. Scientific and/or Practical Problem: Machine learning classifiers used in BCIs are vulnerable to adversarial attacks, which can compromise accuracy, safety, and user privacy. The lack of systematic evaluation of these vulnerabilities represents a gap in current research. Proposed Solution and/or Analysis: This work aims to emulate and analyze adversarial attacks in classifiers of BCI devices. Our experiments used the Foolbox tool to evaluate different adversarial techniques, such as DeepFool, FGSM, PGD, and Carlini-Wagner. Our evaluation identifies the negative effects of adversarial attacks on data classification. Related IS Theory: Technology acceptance model; Information processing theory. Research Method: Experiments were conducted on the BCI Competition 2008 Graz dataset, with attacks emulated during inference. Detection mechanisms based on Random Forest, SVM, and KNN were trained and evaluated to assess the feasibility of automatic defense. Summary of Results: Classifier accuracy decreased sharply under attack, with success rates ranging from 75.2% to 100%. Detection models achieved 83% accuracy with Random Forest and SVM for FGSM attacks, but only 5% with KNN for DeepFool, highlighting the challenge of detecting subtle perturbations. Contributions and Impact to IS area: The work demonstrates the vulnerabilities of BCI classifiers, proposes an evaluation pipeline for adversarial robustness, and emphasizes the importance of integrating security assessment into BCI development. Results have direct implications for information systems dealing with sensitive biomedical data.
A crescente complexidade das infraestruturas de Tecnologia da Informação, especialmente em data centers, tem ampliado a necessidade de monitoramento contínuo que considere não apenas aspectos computacionais, mas também fatores ambientais que impactam sua operação. Nesse contexto, ruídos e sons gerados pelos equipamentos emergem como uma fonte relevante de informação sobre o estado funcional da infraestrutura. Este mapeamento sistemático tem como objetivo identificar, organizar e analisar estudos que exploram o uso de sinais acústicos em ambientes de data centers, com foco em aplicações voltadas ao monitoramento e à detecção de anomalias. O trabalho também investiga a evolução das pesquisas, as principais técnicas e metodologias adotadas, bem como identifica lacunas e oportunidades na literatura. Ao sistematizar essas evidências, o mapeamento contribui para delinear o estado atual do conhecimento e para situar a análise acústica como uma fonte complementar de informação no monitoramento de infraestruturas críticas de TI.
Emerging technologies such as Cloud Computing, 5G, the Internet of Things (IoT), and Edge Computing demand the management of large-scale and highly dynamic network infrastructures. Traditional network configuration does not scale efficiently, whereas Software-Defined Networking (SDN) enables centralized control and simplified management. Despite these benefits, SDN environments still face significant challenges related to security and fine-grained anomaly detection. Several studies have demonstrated the effectiveness of computational intelligence (CI) techniques for anomaly detection in SDN. However, the diversity of network anomalies and CI-based solutions introduces substantial heterogeneity, making model selection and integration challenging. This paper proposes a reference architecture designed to validate, promote, and explain the suitability of different CI techniques for distinct network anomaly scenarios. The proposed architecture adopts a hexagonal microservices design and a unified information model aligned with the application, information, and process layers of the TM Forum Open Digital Architecture (ODA). Validation was performed through a proofof-concept prototype using two datasets and seven machine learning algorithms. The results demonstrate the importance of architectural flexibility, enabling the dynamic integration and replacement of CI models to support adaptive and scalable SDN anomaly detection.
IoT networks are transitioning towards greener underlying technologies. In smart cities environments, while some devices are already sustainable with rechargeable batteries and energy harvesting hardware, many still rely on traditional non-sustainable components. This partial sustainable Internet of Things (IoT) network poses a research challenge, since the profile of sustainable nodes aims for neutral or self-powered operation, which may conflict with the energy-saving goals of traditional non-sustainable nodes. In this challenging scenario, it is essential to share Energy Information (EI), i.e. battery state-of-charge, among the nodes to efficiently manage energy resources. However, EI sharing is valuable data for attackers to perform energy-based attacks, exploiting the most vulnerable nodes in smart cities. To tackle these problems, this article presents the Dual Energy PROfile for interNet-of-thiNgs with Enhanced Security (DEPRONN-ES), which is a solution designed to support partially sustainable networks, i.e. traditional and sustainable nodes, and applies differential privacy to enhance data privacy levels of the EI sharing. The performed evaluation shows the proposed solution is able to reduce the success rate of attacks in 87% and its effectiveness in terms of consumed resources of the attacked node. Besides, DEPRONN-ES is able to support conflicting profiles to operate in distinct energy consumption levels. This framework utilized emulation of IoT devices and real data traces of indoor light intensity measurements provided by Columbia University as a harvesting source of the rechargeable batteries of sustainable nodes.
Os Sistemas de Detecção de Intrusão (IDS) são elementos importantes para redes de acesso via rádio abertas (Open RAN), pois fornecem serviços essenciais de defesa contra ameaças cibernéticas. Tipicamente, os IDS em ambientes Open RAN dependem de modelos de aprendizado de máquina, o que os torna vulneráveis a adversários que buscam escapar da detecção. Em especial, um ataque DDoS capaz de contornar o IDS de uma infraestrutura Open RAN representa um risco significativo para o provedor de serviços de telecomunicações. No entanto, poucos estudos têm se dedicado a ataques adversariais direcionados a IDS em redes Open RAN. Nesse contexto, este trabalho apresenta um ataque adversarial denominado Distributed DoS Adversarial Detection Evasion (DDoS-ADE), projetado para evadir a detecção de ataques DDoS por um IDS implantado no Controlador Inteligente de RAN (RIC) de uma infraestrutura Open RAN. Além de apresentar esse ataque de evasão, o artigo investiga a eficácia de duas estratégias de defesa: (i) redução das características do modelo e (ii) treinamento adversarial. Tanto o ataque DDoS-ADE quanto os métodos de defesa foram implementados e avaliados no testbed OpenRAN@Brasil. Os resultados demonstram que o DDoS-ADE é capaz de evadir 94,66% das detecções de um IDS não protegido. Em comparação, os métodos de defesa implementados conseguem reduzir a evasão em até 98,45%.
Data privacy and eXplainable Artificial Intelligence (XAI) are two important aspects for modern Machine Learning models. To enhance data privacy, recent machine learning models have adopted Federated Learning (FL). On top of that, additional privacy layers can be added, notably Differential Privacy (DP). On the other hand, to improve explainability, ML must consider more interpretable approaches with reduced number of features and less complex internal architecture. In this context, this paper aims to achieve a Machine Learning (ML) model that combines enhanced data privacy with explainability. So, we propose a FL solution, called Federated EXplainable Trees with Differential Privacy (FEXT-DP), that: (i) is based on Decision Trees, since they are lightweight and have superior explainability to neural networks-based FL models; (ii) provides additional layer of data privacy protection applying Differential Privacy (DP) to the Tree-Based model. However, there is a side effect adding DP: it harms the explainability of the system. So, this paper also presents the impact of DP protection on the explainability of the ML model. The carried out performance assessment shows the results of FEXT-DP in terms of numbers of rounds, Mean Squared Error and explainability.
The Internet of Things (IoT) increasingly relies on edge computing nodes to decentralize computation and enhance processing power near IoT devices. However, IoT edge computing nodes are generally not designed for highly intensive machine learning (ML) training. In current IoT architectures, multiple edge computing nodes are strategically positioned near IoT devices, each accessing only a portion of the data generated by the entire IoT network. In this paper, we bring the concept of Federated Learning (FL) to this scenario, by enabling each IoT edge computing node to run lightweight ML models on local datasets cooperatively. Our primary goal is to design a decision tree-based solution for cooperative IoT edge computing, termed Federated Decision Trees (FeDT). To achieve this, we propose four FL strategies based on decision trees, which aggregate the learning contributions of multiple FL clients while adhering to FL principles. Our results demonstrate that the proposed strategies can achieve approximately $80 \%$ of the performance of a centralized ML model in terms of Pearson correlation. Furthermore, compared to FedAVG, a classical FL solution, FeDT requires approximately four times fewer training rounds to converge.
As redes móveis 5G viabilizaram novas aplicações com diferentes características de tráfego. Nesse cenário, a alocação adaptativa de um Equipamento do Usuário (UE) em um slice de rede pode ser complexa, devido aos diferentes tipos de tráfego gerado pelas aplicações do usuário. Para abordar este desafio, este trabalho propõe uma solução denominada USAP-5G (UE Smart Allocation Platform in 5G Mobile Networks). A solução foi desenvolvida levando em conta a utilização de um modelo de aprendizado de máquina LSTM (Long Short-Term Memory) integrado a uma arquitetura Open RAN e 5G. Em testes realizados no testbed OpenRAN@Brasil, a solução demonstrou eficácia na redução da latência na tomada de decisão e no desempenho do esquema de alocação de UEs em slices 5G. Com isso, a alocação de usuários em slices 5G foi automatizada, ajudando a reduzir o OPEX (Custo Operacional) no gerenciamento de serviços da rede.
A Internet das Coisas (IoT) tem dependido de nós de computação em borda para descentralizar a computação e trazer mais poder de processamento próximo aos dispositivos IoT, como sensores e atuadores. Os nós de computação de borda da IoT têm mais poder de processamento de dados e recursos energéticos do que os dispositivos IoT regulares que visam monitorar e atuar no ambiente. No entanto, em geral, os nós de computação de borda não são projetados para treinamento intensivo de Aprendizado de Máquina (ML) ou para hospedar grandes modelos de ML. Nas arquiteturas de rede IoT atuais, existem múltiplos nós de computação de borda estrategicamente localizados perto de um grande número de dispositivos, onde cada um dos nós de computação de borda tem acesso a parte dos dados produzidos por toda a rede IoT. Neste cenário, cada nó de computação de borda executa modelos de ML leves em seu conjunto de dados local. Neste artigo, propomos uma solução, chamada FEderated Decision Tree (FEDT), Árvore de Decisão Federada, que agrega o aprendizado produzido por múltiplas árvores de decisão de nós de borda cooperativos, seguindo os princípios de aprendizado federado. Apresentamos quatro estratégias de aprendizado federado diferentes e demonstramos que o FEDT pode alcançar cerca de 80% de um modelo de ML centralizado em termos de correlação de Pearson.
The research agenda on programmable data planes has been primarily focused on high-end networking devices, driven by technical requirements derived from operations & management needs of large scale datacenters and cloud providers. In this paper, we argue in favor of a yet incipient but equally paramount and challenging topic in this agenda: research on programmable low-end devices, like Low-power wide-area network (LPWAN). One main motivation is “unlocking” LPWAN, enabling one to freely redefine how they parse and process packets by means of Domain-specific languages such as P4. In addition to reducing capital expenditure by allowing interoperability between devices from multiple vendors, programmability would open LPWAN to an entire novel class of use cases, like providing inclusive internet access to technologically marginalized populations (such as rural communities). To contribute to this emerging research agenda, we propose a conceptual architecture and demonstrate the technical feasibility of a Programmable LPWAN by means of a proof-of-concept prototype, built using off-the-shelf hardware. More importantly, we present and discuss valuable lessons towards the design of such devices, maintaining their popular characteristics (like low power, low cost, long rage) yet freely (re)programmable for a broader class of novel use cases.
A honeypot is a defense technique that complements defense systems, which are generally composed of firewalls and intrusion detection systems. A honeypot consists of a “bait” system that simulates attractive and vulnerable targets for potential attackers. In this article, we address the problem of the lack of dynamism in traditional honeypots, which are based on static scripts, with a special focus on botnet-type threats. To tackle this problem, the proposed solution integrates a large language model into a honeypot, capable of interacting with the attacker by dynamically imitating a target device. The open-source tool Cowrie was used as the traditional reference honeypot to receive functionalities from the large language model, including command response generation, log data analysis, and the emission of alerts and actions. Regarding the evaluation, tests were conducted to measure the accuracy of the command responses produced by the proposed honeypot, the time required for response generation, and the number of tokens. The obtained results reveal the viability of the proposed integration, showing that a large language model is a promising alternative for honeypots to achieve a higher level in deceiving attackers.
Federated Learning (FL) has emerged as a machine learning approach able to preserve the privacy of user’s data. Applying FL, clients train machine learning models on a local dataset and a central server aggregates the learned parameters coming from the clients. The training of the global machine learning model runs without sharing user’s data. However, the state-of-the-art shows several approaches to promote attacks on FL systems. For instance, inverting or leaking gradient attacks can find, with high precision, the local dataset used during the training phase of the FL. This paper presents an approach, called FAST Improved Deep Leakage from Gradients (FAST-iDLG), which is able to improve the inverting gradient attack, considering the spatial correlation that typically exists in a set of images stored in the local FL dataset. Instead of initiating the attack of an image using dummy data, FAST-iDLG blends the previous reconstructed images using a sliding window and an exponential function to weight the blend. The performed evaluation shows an improvement of 66% - 26% in terms of attack success rate and reduces by 55% - 25% the number of iterations per attacked image.
Este artigo apresenta uma revisão sistemática sobre sistemas de detecção e prevenção de intrusão (IDS/IPS) em redes de Internet das Coisas (IoT), com foco na borda e na nuvem. A análise abrangeu 24 artigos selecionados de quatro bases de dados, avaliados quanto à qualidade e relevância. Os resultados indicam que soluções como detecção baseada em comportamento, assinaturas e anomalias têm sido exploradas para proteger redes IoT, com destaque para o aprendizado de máquina, especialmente o aprendizado federado. No entanto, desafios como a complexidade da rede e a diversidade de dispositivos ainda persistem. O estudo categoriza e compara abordagens, fornecendo parâmetros e métricas para replicação em futuras pesquisas sobre segurança em IoT. Além disso, contribui com diretrizes para experimentação e reprodutibilidade de resultados.
Managing big data traffic plays an important role in contemporary communication and is essential for efficiently handling an unprecedented volume of information. In the globalized context of the internet, the ability to measure and predict this traffic is a strategically valuable resource that requires a deep understanding of historical data. This article proposes a predictor based on a generalization of the Choquet integral, which aggregates data, reducing the complexity and dimensionality of traffic predictions. The approach is assessed using real data, demonstrating that the Choquet integral achieves higher accuracy with the appropriate a parameter. Considering the worst-case scenario in terms of wasted time, and given that the overall algorithm achieved a satisfactory error rate, we can conclude that the least efficient algorithm was the brute force search. In comparison, binary search and random binary search demonstrated a time efficiency improvement of 56.75% and 59.49%, respectively. Among the integrals evaluated, the Choquet (a) integral yielded the smallest errors.
We present a prototype that could open the doors to mitigate digital exclusion in technologically underserved pop-ulations. By converging software-defined networks (SDN) with programmable data planes (PDP), our approach enables one to customize low-cost hardware to fit the network behavior. We integrate low-power wide-area networks (LPWANs), known for their scalability and efficiency, with PDPs to propose a flexible solution for changing requirements, such as distance and terrain configurations, validated through real-world test scenarios.
Federated Learning (FL) has emerged as a machine learning approach able to preserve the privacy of user's data. Applying FL, clients train machine learning models on a local dataset and a central server aggregates the learned parameters coming from the clients, training a global machine learning model without sharing user's data. However, the state-of-the-art shows several approaches to promote attacks on FL systems. For instance, inverting or leaking gradient attacks can find, with high precision, the local dataset used during the training phase of the FL. This paper presents an approach, called Deep Leakage from Gradients with Feedback Blending (DLG-FB), which is able to improve the inverting gradient attack, considering the spatial correlation that typically exists in batches of images. The performed evaluation shows an improvement of 19.18 of iterations per attacked image, respectively.
Rapid technological advancement has revolutionized the acquisition, processing, and storage of personal data, with notable data breaches from significant corporations emphasizing the value of data and the need for enhanced privacy protection. This has led to a global focus on individual privacy by enacting privacy-centric laws. The healthcare sector, known for its data sensitivity, presents distinct challenges necessitating stringent privacy protocols. The healthcare sector, known for its data sensitivity, presents distinct challenges necessitating stringent privacy protocols. Thus, there is a critical need for robust data privacy measures, including (pseudo)anonymization, to address this shift. This paper introduces a tailored multilevel (pseudo)anonymization architecture designed for healthcare data, capable of ensuring secure data handling and precise anonymization across various sources, even in a (pseudo)anonymized state. The proposed architecture was developed as a proof of concept and underwent thorough evaluation through a series of experiments. The outcomes are encouraging by showcasing effectiveness in achieving accurate anonymization, secure data and supporting re-identification when essential for individual security.