With the rapid development of digital banking, the issue of financial fraud detection has grown even more pressing. Real-world fraud systems have two major challenges: extreme class imbalance and behavioral variability of fraudulent activities, which are frequently not captured by monolithic global models. We propose a cluster-aware multi-model framework that simultaneously tackles both challenges. To handle the class imbalance efficiently, we first employ a Conditional Tabular Generative Adversarial Network (CTGAN) to generate high-fidelity synthetic fraud examples. Second, we cluster fraudulent transactions into behaviorally consistent subgroups using non-linear dimensionality reduction (UMAP) and density-based clustering (DBSCAN). This breakdown enables a Mixture-of-Experts (MoE) architecture in which specialized classifiers are trained for different fraud behaviors. We evaluate our approach on a popular benchmark for credit card fraud and show that it outperforms classical resampling methods and strong global baselines. Ultimately, the suggested technique detects infrequent and confined fraud patterns more effectively, resulting in a much higher F1-score and operational viability.
Enterprise security demands actionable threat prioritization across heterogeneous environments. To address the limitations of siloed log analysis, we propose a multi-source, graph-based anomaly detection framework. First, our architecture seamlessly fuses network telemetry from Vectra, Security Information and Event Management (SIEM) logs from QRadar, and endpoint data from CrowdStrike into a unified graph. Second, we utilize the Louvain algorithm to segment the network, identifying functional communities and critical bridge nodes indicative of lateral movement. Third, we extract over 50 structural, behavioral, and temporal features to train an XGBoost-based ensemble classifier. Evaluated on a real-world banking dataset with 31 anomaly types, the proposed system achieves 98% precision. Crucially, empirical analysis reveals that local neighborhood connectivity and traffic dynamics significantly outperform traditional global centrality metrics in detecting complex attacks. Finally, to support operational incident response, we implement a dynamic risk-scoring mechanism that translates model predictions into actionable, IP-level severity assessments across sliding time windows. Ultimately, this framework substantially enhances comprehensive threat visibility and analyst efficiency.
This paper presents a multi–phase classification framework for identifying applications from encrypted network traffic. The proposed model employs deep learning-–based classifiers organized in a phased ensemble structure guided by majority voting. Each classifier operates on a distinct number of packets within a flow, contributing progressively refined predictions as more packet data become available. The ensemble prediction is iteratively updated by integrating outputs from classifiers trained on fewer packets, enabling accurate early classification with limited input. The model is evaluated on a recent dataset comprising real network flows from diverse applications, with comprehensive comparisons across different classification architectures and voting strategies. Experimental results demonstrate the effectiveness and adaptability of the proposed approach for encrypted traffic classification.
In this paper, we explore the optimal use of network coding in multi-source multi-hop Internet of things (IoT) networks, focusing on minimizing the average age of information (AoI) under various system parameters. Specifically, we determine the optimal number of packets for performing network coding at intermediate nodes (servers) to optimize the average AoI performance. Through extensive simulations, we demonstrate how frequency of network coding impacts data freshness across a range of scenarios, including different numbers of sources, transmission success probabilities, and computational capacities. Simulation results provide practical insights into the deployment of network coding in real-world IoT applications, shedding light on the design process of how to implement network coding and highlighting its potential to significantly improve timeliness in data delivery.
In this work, a novel method based on matrix profile and machine learning is proposed for anomaly and attack detection in network traffic. Traditional network security systems are often based on signature-based methods, which are inadequate in detecting unknown attacks. The proposed approach utilizes matrix profile, a powerful tool for time series analysis, to identify anomalies in network traffic and classify these anomalies using machine learning models. In the proposed method, the matrix profile is applied to the selected feature set to highlight anomalies. The proposed information-theoretic features play a crucial role in distinguishing attacks. The results obtained on a publicly available dataset demonstrate that the proposed method achieves high accuracy.
6G, as a platform for the internet of everything, supports high data rates and low latency and satisfies the requirements for services, massive data traffic, storage, and processing, thus providing new opportunities for accessing consumer goods and digital services. Due to its enhanced autonomy, accuracy, and predictive capabilities, artificial intelligence (AI) is anticipated to play a significant role in the evolution of 6G by enabling large-scale deployments of self-optimized and automated systems, and enhancing applications and services, including augmented/virtual/mixed reality, Industry 5.0, banking, and financial services. 6G and AI can potentially revolutionize the banking and financial industry despite cost, scalability, security, privacy, and adoption constraints. This chapter discusses security and privacy concerns in 6G and potential solutions, the relevance and impact of 6G technology to the banking and financial industry, solutions and recommendations for developing secure 6G banking and financial systems, and future research directions.
We consider the timeliness in delivering an update consisting of multiple message packets to multiple users via multicast transmissions with or without employing network coding where Age of Information (AoI) is adopted to quantify the timeliness of packets. The expressions for peak and average expected AoIs are analytically derived for both uncoded and network coded transmissions for both 2-user and generalized k-users scenarios where the computational burden stemming from network coding is taken into account. The behavioral analyses of a number of network parameters are investigated, and the effect of data rate and computational capacity of nodes is analyzed. Simulations are performed for various Internet of Things (IoT) deployments, and the analyses suggest that the use of network coding for multicast transmissions can result in substantial AoI improvements, with the exception of scenarios in which sensors have extremely limited computational capabilities.
With the advent of emerging mobile network technologies such as 5G and Beyond 5G, the proliferation of Internet of Things (IoT) or, more broadly, Internet of Everything (IoE) integration has become ubiquitous across various industries and daily routines. Nevertheless, the pervasive vulnerabilities inherent in IoT networks-stemming from their widespread distribution, coupled with the limited security measures and processing capabilities of IoT devices-render them susceptible to a myriad of threats, notably Distributed Denial of Service (DDoS) attacks, which pose a grave risk to network availability. In response to the imperative for lightweight DDoS detection in IoT environments with resource constraints, this study is centered on Matrix Profile (MP)-based anomaly detection. Renowned for its effectiveness in analyzing time series data and distinguished by its expedited processing and minimal computational burden, this research undertakes a comparative analysis of six MP-based algorithms. Four unsupervised and two supervised algorithms are analyzed. These algorithms are specifically tailored to operate efficiently on IoT devices. The overarching objective is to assess the efficacy of these algorithms in identifying DDoS attacks through the utilization of system data derived from IoT devices. The study also endeavors to propose a novel approach aimed at fortifying the security posture of IoT networks against the pervasive threat of DDoS attacks.
In recent years, the increasing demand to see the status of objects over the internet leads to an increase in the number of Internet of things (IoT) applications. The unique nature of IoT, which involves potentially millions of interconnected devices with different data rate, power, bandwidth and range specifications, require different performance metrics than those conventionally employed in other communication applications. In conventional wireless communication systems such as cellular networks, performance indicators including data rate and spectral efficiency have become decisive, whereas in energy-constrained real-time IoT applications which require low data rate, the freshness of information has become a more prominent characteristic. Age of information (AoI), which is the elapsed time after the last received packet update was created at the source, has emerged as a fundamental metric for determining the freshness of information and has attracted substantial research interest. In this regard, this paper is dedicated to provide an overview of the current state-of-the-art on the use of AoI for the design and optimization of a large variety IoT applications. After a brief introduction of the IoT and AoI fundamentals, this paper presents a survey of the research works on common design issues such as AoI based optimization, scheduling for IoT networks, application of learning methods in large scale IoT systems, real life applications and experimental results together with a synopsis of potential future applications and research challenges.
This work explores the age of information (AoI) impact of block coding with maximum-likelihood decoding (MLD), along with the consideration of polar coding with successive-cancellation (SC) decoding as a realizable subcase by employing an Internet of things (IoT) network, where sensors transmit data over discrete memoryless binary symmetric or erasure channels. A general lower bound for block coding is derived along with the upper bounds depending on the coding schemes. Simulation results indicate that block coding can theoretically outperform no coding up to 20 - 25% in terms of AoI depending on the block-length of the code. Suitable conditions in polar coding to converge to theoretical MLD performance are discussed.
Low-rate Denial of Service (LDoS) attacks can significantly reduce the serving capabilities of networks. These attacks involve sending periodic high-intensity pulse data flows, and their harmful effects are like those of traditional DoS attacks. However, LDoS attacks have different attack modes, which make them particularly challenging to detect. The high level of concealment associated with LDoS attacks makes it extremely difficult for traditional DoS detection methods to identify them. This paper explores the potential of using statistical features for LDoS attack detection. The results demonstrate that statistical features can offer promising performance in detecting these types of attacks. Furthermore, through the application of RFE and SHAP analysis, we find that entropy and L-moment-based features play a crucial role in detection. These findings provide important insights into the use of statistical features for network security, which can help to enhance the overall resilience of networks against various types of attacks.
In this study, we will examine user’s keyboard usage behavior, the features extracted from the user’s timing data during a short-fixed text entries will be converted into images and fed into a Gated Recurrent Unit (GRU) in a new Siamese Network topology will be proposed. The results will be examined within the scope of group leakage, and a new leakage-free method will be proposed and evaluated.
We propose a novel scheduling strategy for prioritization-critical time-sensitive Internet of things (IoT) networks. The goal is to decrease the number of sensors with outdated information and minimize the difference between their age of information (AoI) and the specified limit, within a resource-constrained environment. The proposed approach relies on reformulating the original problem as a knapsack problem. This novel method is shown to outperform benchmarks to satisfy the needs of priority-aware IoT networks.
We investigate the timeliness in delivering updates within a multisource multihop Internet of Things (IoT) network via multicast transmissions with or without employing network coding, using a completely probabilistic model. Age of Information (AoI) is adopted to quantify the timeliness of packets. Extensive simulation results, which corroborate the theoretical findings, demonstrate that in scenarios where the number of sources is high, the number of intermediate nodes relaying to monitors is low, there are multiple monitors, the transmission success probability is low, and computational resources are sufficient, the utilization of network coding has a great potential to improve the data-freshness in multisource multihop IoT networks which closely represent the spine of the real-life scenarios.
The internet of things (IoT) has been used in a wide range of applications since its emergence, including smart cities, intelligent systems, smart homes, smart agriculture, and healthcare. IoT systems rely on information processing and sharing, where data leakages may jeopardize their security and privacy. On the other hand, quantum computers are poised to solve complex problems that traditional computers cannot. However, due to the fact that the majority of cyber algorithms are based on significant computational complexity, quantum computing poses a substantial threat to the cyber security of global digital infrastructure, including IoT networks, smart cities, banking, and intelligent infrastructure. This chapter discusses potential security and privacy measures for a post-quantum world against threats posed by quantum computing, including post-quantum cryptography, quantum software testing, post-quantum blockchain technology, and architectural considerations for creating post-quantum secure IoT systems.
Controlling the events occurring in the network traffic and detecting malicious activities are of great importance for the security and sustainability of the system. For this reason, it is necessary to accurately detect different types of attacks that may occur in network traffic. On the other hand, it is very important from the security aspect to be able to distinguish the types of attacks that have not been seen before. In this paper, a two-step procedure is proposed that can both correctly classify known attack types and distinguish unknown attack types. In the first stage, incoming traffic is classified by supervised learning with an autoencoder. In the second stage, the reliability of this classification is checked with the help of the autoencoder and the Extreme Value Theorem (EVT). According to the reliability value, incoming traffic is classified as unknown class. The simulation results were obtained with the IDS 2017 data set, which is widely used in the literature.
In this paper, we propose a dynamic graph-theoretical solution, aiming to minimize the average Age of Information, to the user pairing problem in cellular networks employing non-orthogonal multiple access with variable user rate demands. The proposed approach is based on first constructing a conflict graph corresponding to all possible user pairings and then reformulating the problem of finding the average Age of Information minimizing user pairs as that of finding the maximum weighted independent set on the conflict graph. We show that the conflict graph corresponding to this user pairing problem is claw-free. This new reformulation combined with the claw-freeness property allow the original NP-hard optimization problem to be transformed into another one that can be solved in polynomial time. We validate the performance of the proposed graph-based user pairing approach via numerical experiments where the results indicate significant gains in average Age of Information compared to the state-of-the-art non-orthogonal multiple access user pairing approaches and the orthogonal multiple access strategy.
Hakan Deliç合作论文数Bogazi??i University3