Centralised architecture models are often adopted in the development of smart cities to take advantage of the technologies provided by dominant companies such as Google, Meta, and Amazon. This approach often comes with significant drawbacks, such as (i) application developers becoming dependent on the policies and rules imposed by large companies, which are subject to change, and (ii) users having their data collected and used haphazardly, and often without authorisation, which can undermine the trust that users place in the solution. Infrastructure for smart cities should, therefore, incorporate decentralised technologies that satisfy or reinforce important quality attributes such as trustworthiness, privacy, and security. The main objective of this article is to survey and discuss how the services of a smart city can be implemented using decentralised architectures; we explain the advantages and disadvantages of decentralised architectures and emerging technologies. We review the specialised literature and compile a set of emerging technologies that are essential to conceive a decentralised architectural solution for smart cities. The current state-of-the-art in decentralisation shows that this model can be implemented with current technologies and help to satisfy the quality attributes mentioned above, and potentially reinforce the degree of trustworthiness of the solution. We also propose a four-dimension guideline that functions as a conceptual driver for structuring actions for researchers, system architects, policymakers, and city authorities in the design, evaluation, and long-term maintenance of decentralised smart cities, thereby enhancing their capacity to address escalating urban challenges. We conclude that the set of technologies discussed in this article has the potential to be reused and replicated across smart cities.
In this paper, we propose a modularized framework for communication processes applicable to crash and Byzantine fault-tolerant consensus protocols. We abstract basic communication components and show that the communication process of the classic consensus protocols such as RAFT, single-decree Paxos, PBFT, and Hotstuff, can be represented by the combination of communication components. Based on the proposed framework, we develop an approach to analyze the consensus reliability of different protocols, where link loss and node failure are measured as a probability. We propose two latency optimization methods and implement a RAFT system to verify our theoretical analysis and the effectiveness of the proposed latency optimization methods. We also discuss decreasing consensus failure rate by adjusting protocol designs. This paper provides theoretical guidance for the design of future consensus systems with a low consensus failure rate and latency under the possible communication loss.
Edge computing enables distributed machine learning models to be deployed and trained near the user space. However, the intricate nature of edge computing raises several challenges to distributed machine learning frameworks: 1) inferior convergence arising from non-independent and identically distributed (non-IID) edge data; 2) inefficient structural adaptation, where device dynamism complicates the adjustment of aggregation structure; and 3) reduced training efficiency, as resource heterogeneity and fluctuations create systemic stragglers. To address these issues, a distributed hierarchical model training framework has been proposed by considering the dynamic aggregation structure and frequency in this paper. This framework designs an Edge Aggregation Structure and Frequency method, namely EASF, for distributed model training in heterogeneous edge computing environments. First, a dynamic distributed aggregation structure method is formulated to consider various data distribution patterns. This method constructs and modifies the aggregation structure in a distributed manner to adapt to variations in working edge devices. Second, a self-adapted aggregation frequency method and a timeout abandonment mechanism are proposed to allow each node to update its aggregation frequency adaptively. Lastly, a theoretical analysis demonstrates the convergence property of the EASF method in dynamic environments. Extensive experiments have been conducted on a set of open testbeds. Results show that the EASF significantly improves the efficiency and accuracy of hierarchical model training in heterogeneous edge computing.
Optimization, which lies at the core of network operations, is usually associated with extensive expert knowledge and manual overhead, which impedes its efficient implementation. To address this issue, this study illustrates the potential of a paradigm shift from algorithmic solvers to semantic agents for network optimization. Specifically, we envision a generalized Large Language Model (LLM)-based framework, called ComLLM, for addressing fundamental problems in mobile communication networks. Without explicit mathematical problem formulation, ComLLM can understand the semantic context (i.e., high-level, human-interpretable goals and constraints) and autonomously call incorporated prediction modules to generate adaptive optimization decisions. A case study on mobile edge computing demonstrates that ComLLM effectively performs joint data transmission rate prediction and autonomous vehicle task scheduling. ComLLM can be used for minimizing end-to-end latency or maximizing revenue. Furthermore, the paper provides insights into ComLLM and discusses open challenges.
Recent attacks on federated learning (FL) can introduce malicious model updates that can circumvent widely adopted Euclidean distance-based detection methods. This article proposes a novel defense strategy, referred to as LayerCAM-AE, designed to counteract model poisoning in FL. The LayerCAM-AE puts forth a new Layer Class Activation Mapping (LayerCAM) integrated with an autoencoder (AE), significantly enhancing detection capabilities. Specifically, LayerCAM-AE generates a heat map for each local model update, which is then transformed into a more compact visual explanation. The autoencoder processes the LayerCAM heat maps from the local model updates, improving their distinctiveness and increasing the accuracy in spotting anomalous maps and malicious local models. To mitigate the risk of misclassifications in LayerCAM-AE, a voting algorithm is developed, where a local model update is flagged as malicious if its heat maps are consistently suspicious over several communication rounds. Extensive tests on the SVHN and CIFAR-100 datasets are performed under both Independent and Identically Distributed (IID) and non-IID settings in comparison with the state-of-the-art ResNet-50 and REGNETY-800MF defense models. The experimental results show that LayerCAM-AE increases detection rates (Recall: 1.0, Precision: 1.0, FPR: 0.0, Accuracy: 1.0, F1 score: 1.0, AUC: 1.0) and the test accuracy of FL, surpassing both the ResNet-50 and REGNETY-800MF. Our code is available at: https://github.com/jjzgeeks/LayerCAM-AE .
As large language models (LLMs) increasingly shape decision-making, public discourse, education, healthcare, and governance, a critical question emerges: Whose values are these systems truly reflecting? While today's generative Al systems demonstrate extraordinary capabilities, they also inherit hidden biases, ethical blind spots, and implicit assumptions embedded within their training data. Existing alignment approaches often remain opaque, resource-intensive or insufficiently adaptive to diverse societal expectations. This paper introduces a novel value-driven LLM framework designed to systematically uncover, quantify, and realign the implicit valles embedded within LLMs toward socially desirable outcomes. Built upon the Al for Social Good (ASG) framework, our proposed methodology operationalizes ethical alignment across six critical domains: reasoning and interpretibility, bias removal, transparency and accountability, security and privacy, moral and ethical observations, and public understanding. Using advanced embedding techniques, cosine-based value-difference metrics, and topic-weighted iterative fine-tuning, the framework transforms ethical alignment from an abstract aspiration into a measurable and actionable computational process. To demonstrate adaptability across moral and regulatory paradigms, the framework evaluates two distinct referencq value systems: the Ten Commandments and the General Data Protection Regulation (GDPR). Experimental results using open-source LLMs, including Llama 3.2 and Gemma 2, reveal substantial reductions in value misalignment, ranging from approximately 25% to 70% across ethical domains, while preserving model flexibility and scalability. Visualizations in value-embedding space further confirm significant convergence between original model outputs and socially aligned reference values after iterative realignment. Beyoral technical innovation, this work positions value alignment as a foundational challenge for the future governance of generative AI. The proposed framework functions both as a diagnostic instrument for identifying ethical gaps and as an intervention mechanism for adaptive value realignment, offering policymakers, developers, and institutions a scalable pathway toward transparent, accountable, and socially responsible Al systems. By bridging computational methods with moral, legal, and societal principles, this research advances a new paradigm for embedding human-centered values directly into the next generation of intelligent systems.
Low-latency data sensing and transmission is critical for many city-level applications like traffic incident management to mitigate congestion and enhance road safety. Vehicular crowdsensing (VCS) emerges as a powerful paradigm to provide real-time traffic sensing services from points-of-interest (PoIs) by leveraging the collaboration of unmanned ground vehicles (UGVs) and unmanned aerial vehicles (UAVs). In this paper, we first introduce two novel metrics: sensing capability-aware age-of-information ($s$AoI) and latency-weighted data collection ratio, to measure the data freshness and amount under the condition of non-uniform status packet size, respectively. We propose an auto-regressive sequential multi-agent deep reinforcement learning framework called “A2G-MADRL”, which consists of an interaction-aware heterogeneous vehicular graph convolution network (HVGCN) for feature extractions, and a dynamically ordered masked policy generator (DOMPG) for coordinating UAVs and UGVs. Extensive experiments on two real-world datasets in KAIST and Roma demonstrate that A2G-MADRL significantly reduces the attained $s$AoI and improves latency-weighted data collection ratio, outperforming seven baselines when varying the number of UAV-UGV pairs, data generation speed in a timeslot, and the number of communication channels.
QUIC is an emerging transport-layer protocol that provides reliability and security. QUIC was designed to overcome issues from other protocol stacks used in the Internet, such as TCP/TLS, especially focusing on web traffic performance improvement. Therefore, QUIC was not conceived for Internet of Things (IoT) scenarios, which are characterized by significant resource constraints. However, as QUIC prominance increases, and the IoT continues to expand, QUIC may offer connectivity opportunities for IoT devices. In this paper, we explore the suitability of QUIC for IoT environments. Leveraging optional functionality, we propose, discuss, and evaluate a QUIC profile for IoT scenarios that is currently being considered for IETF standardization.
Vehicular Crowdsensing (VCS) has emerged as a promising paradigm that leverages the complementary strengths of unmanned aerial vehicles (UAVs) and unmanned ground vehicles (UGVs) for large-scale urban sensing and data collection. In this paper, we consider a UAV-carrier-enabled VCS campaign in which UGVs dynamically dispatch and recall UAVs within the workzone, where UAVs sense points of interest (PoIs) and UGVs facilitate data collection, with the goal of maximizing the total collected data volume and geographic fairness, while minimizing overall energy consumption. We propose a heterogeneous multi-agent deep reinforcement learning (MADRL) framework, called “HADRL-VCS”, consisting of an attentive memory-integrated information exchange mechanism that enables UAVs and UGVs to fuse newly received information with historical memory, thereby expanding the collective sensing range and enhancing cooperative decision-making. We also propose a mutual policy divergence-driven exploration strategy designed to explicitly promote diverse exploration and complementary role differentiation among heterogeneous UAVs and UGVs. Extensive experimental results based on realistic simulations using real-world urban maps from Guangzhou, China, and Madrid, Spain, show that HADRL-VCS achieves better performance over five baselines in terms of data collection ratio, geographic fairness, sensing range expansion ratio, overlap ratio, and efficiency.
Traditionally, Internet of Things (IoT) communication technologies have been designed to offer low bit rates (from similar to 10(2) to similar to 10(6) bit/s). However, recent IoT-intended technologies like 5G Reduced Capability (RedCap) support significantly greater bit rates (up to similar to 10(8) bit/s), enabling emerging IoT use cases that demand greater capacity. Thus, the spectrum of IoT scenarios and corresponding requirements is expanding, a trend which is expected to continue with 6G networks. In this context, support, configuration and performance of a crucial upper-layer protocol like TCP become challenging. In this paper, based on our IETF standardization work, we describe how TCP can run suitably on a wide variety of IoT environments (from highly constrained scenarios to resource-rich ones). Furthermore, we present and study the novel TCP option called TCP Acknowledgment Rate Request (TARR), designed for further TCP adaptability, which is particularly useful for current and future IoT networks.
Public administrations and private companies have announced plans to deploy networking infrastructure to support future robotic and human presence on or near space targets, such as the Moon and Mars. While using an IP protocol stack for deepspace communication had been neglected, recent events have motivated the reconsideration of IP to enable the Interplanetary Internet. This new paradigm facilitates the integration of IP-based Internet of Things (IoT) protocols for deep-space environments. This paper illustrates the similarities between deep-space and IoT scenarios, presents related IETF standardization work, and discusses opportunities and future directions for IP-based IoT protocols in the Interplanetary Internet.
Reliable inertial navigation in global positioning system (GPS)-denied indoor environments is critical for cyberphysical systems such as smart manufacturing floors, emergency-response platforms, and healthcare facilities, where continuous and privacy-respecting location awareness supports human-machine coordination and situational decision-making. Data-driven inertial navigation improves pedestrian tracking from commodity inertial measurement units (IMUs); however, training on trajectory data raises privacy concerns because motion traces can reveal sensitive mobility patterns. Existing differentially private training methods often inject isotropic noise without accounting for the structure of inertial representations, which can degrade fine-grained motion cues required for drift compensation. To address these challenges, we propose ConvXformer, a hierarchical hybrid architecture that combines ConvNeXt-style temporal convolutions with Transformer encoders to capture short-term motion dynamics and long-range temporal dependencies for drift-aware inertial navigation. For privacy-preserving training, we introduce a utility-aware mechanism that combines per-sample gradient clipping and isotropic Gaussian privatization with gradient-aligned subspace denoising (GASD), implemented as truncated-singular value decomposition (SVD) denoising of the privatized aggregate. Because GASD is applied only after the Gaussian mechanism, it acts as postprocessing and incurs no additional privacy loss. We evaluate ConvXformer on OxIOD, RIDI, and RoNIN, where it achieves strong performance relative to representative prior methods, while ConvXformer-DP maintains competitive utility under moderate privacy budgets. We further introduce Mech-IO, a real-world dataset collected in a machinery-rich indoor environment with substantial magnetic disturbances, to examine robustness under challenging sensing conditions. The results show that ConvXformer supports privacy-aware inertial navigation for learning-enabled cyberphysical systems in which localization accuracy, data protection, and system robustness must be jointly considered.
Large language models are increasingly being used to support network operations (NetOps) and artificial intelligence for IT operations (AIOps), including incident investigation, root-cause analysis, configuration synthesis, and limited self-healing. In both NetOps and AIOps, this shift is changing how tasks are managed. Agent-based operations work as workflows, from gathering evidence to taking action, following permissions, policies, and checks, and providing rollback options when necessary. This is crucial because operational decisions can have instant impacts. To make the argument concrete, we organise the relevant literature around the hierarchy of autonomy, tool scope, evidence traces, and assurance contracts. These contracts define what an agent may observe, propose, and execute. They also define the checks that must pass before any action is allowed. A consistent pattern appears across work on telemetry query recommendation, diagnosis, root-cause analysis, configuration synthesis, change planning, and limited self-healing. Operational reliability does not come chiefly from the model itself. It depends on the machinery around the model. We also argue that evaluation should go beyond static question answering. Agentic NetOps and AIOps systems require workflow-centred evaluation, including trace quality, bounded tool use, safe proposal generation, replay in sandboxed environments, and canary trials with rollback-aware scoring. Without these measures, a system may appear robust yet remain too fragile. Finally, we examine security, privacy, and governance risks that become acute when agents sit close to operational control surfaces. Taken together, the survey concludes that progress in intelligent NetOps and AIOps will depend on treating autonomy as a constrained operational control problem, whose outputs must be reliable, auditable, and securely deployable.
This article proposes a new cyberattack on decentralized federated learning (DFL), named user isolation poisoning (UIP). While following the standard DFL protocol of receiving and aggregating benign local models, a malicious user strategically generates and distributes compromised updates to undermine the learning process. The objective of the new UIP attack is to diminish the impact of benign users by isolating their model updates, thereby manipulating the shared model to reduce the learning accuracy. To realize this attack, we design a novel threat model that leverages an adversarial message-passing graph (MPG) neural network. Through iterative message passing, the adversarial MPG progressively refines the representations (also known as embeddings or hidden states) of each benign local model update. By orchestrating feature exchanges among connected nodes in a targeted manner, the malicious users effectively curtail the genuine data features of benign local models, thereby diminishing their overall influence within the DFL process. The MPG-based UIP attack is implemented in PyTorch, demonstrating that it effectively reduces the test accuracy of DFL by 49.5% and successfully evades existing cosine similarity- and Euclidean distance-based defense strategies.
The digital substrate - data, algorithms, infrastructure, platforms, applications - is being governed without adequate conceptual foundations. The ability and legitimacy required to govern this substrate, and to govern with it, are simultaneously misaligned, contested, and structurally absent. We introduce digital statecraft as the organising concept for this emerging field, arguing that 'digital' reconstitutes the statecraft question rather than merely extending its domain. The concept operates on two dimensions - statecraft over digital systems, concerning the authority and capacity of the state in relation to the digital substrate itself, and statecraft with digital systems, concerning the deployment of algorithmic tools as instruments of governing authority. And it rests on two foundational requirements, technical coherence and legitimate authority, that are genuinely in tension. We derive ten principles of digital statecraft from these foundations, each naming a condition whose absence produces an identifiable and structural governance failure: public interest first, human-machine complementarity, governability by design, systemic coherence, hybrid institutions, adaptive governance, human centricity and civic agency, accountable and traceable authority, judgment across time, and the non-delegable core. This article takes the state as the starting point, the institutional form that developed historically in response to the problem of effective and legitimate public governance, and the only current candidate for which the full set of legitimacy conditions is institutionally available. But the digital statecraft programme holds open a deeper question than just whether states can reform themselves: governing well in the algorithmic age may require rethinking the boundaries, scale, and affiliative basis of statehood itself.
Packet networks are controlled dynamical systems with discontinuities, delayed observations, and partial state information. Adaptive or learning-driven proposers can improve performance, but an unsafe proposal may still cause starvation, tail-delay spikes, or unstable queue behaviour. This paper treats packet-network control as an executed-action certification problem. A certified operator sits between any proposer and the dataplane. At each control tick, the proposer emits an arbitrary candidate action $\tilde u(t)$. The operator either projects it to an executable action $u(t)$ that satisfies a configuration-compiled certificate, or reports INFEASIBLE and executes an always-defined fallback with quantified slack. The certificate also exports an auditable envelope $\bar z(t)$ for downstream composition. The guarantees are conditional and explicit. They apply on ticks where the operator reports CERTIFIED, the declared arrival envelope and backlog bound are valid, and the platform realises the assumed service lower bound. Under these conditions, one mechanism covers backlog caps, service floors, mitigation caps, Foster--Lyapunov drift constraints, and compositional envelope contracts. We prove operator-level safety, feed-forward compositional safety and stability using exported envelopes, and a cyclic closure result under a small-gain condition. We also define breach and infeasibility semantics, discuss calibration of the service-tracking factor that links certified targets to realised scheduler behaviour, and evaluate the design under delayed telemetry, delayed actuation, weak proposers, envelope mismatch, overload, and millisecond-scale certification. The present evaluation validates the certified execution boundary in a byte-level closed-loop backend; deployment-level scheduler tracking is left to future Linux or hardware experiments.
We argue that the absence of central authorities and trust decentralisation in decentralised ID systems enable them to achieve openness, transparency, scalability, privacy and reliability. These are highly desirable properties in several application domains including smart city services. Decentralised ID systems are only emerging. Several candidates exist at an experimental stage of development, awaiting deployment and evaluation in realistic applications. In this paper, we discuss Trustchain. We explain the features that have motivated us to use it in the implementation of smart city services. Also, we share our experience gained from its local deployment.
The metaverse is a shared virtual 3D space that combines immersive experiences with applications in gaming, social interactions, commerce, and more. It is rapidly becoming a reality, driven by advances in virtual reality, augmented reality, artificial intelligence, blockchain, and other emerging technologies. Among these, blockchain technology enables secure and decentralized ownership as well as seamless interoperability of virtual assets. Non-fungible tokens ensure verifiable ownership and fraud prevention, while smart contracts facilitate automated peer-to-peer transactions. Blockchain’s security and transparency promote trust and innovation, laying the foundation for a connected and user-driven metaverse ecosystem. In this paper, we explore the role of blockchain technology as a key enabler for the metaverse, providing solutions for decentralization, governance through decentralized autonomous organizations, interoperable mechanisms, digital asset ownership, traceability, auditing, and identity management. We present the key difference between traditional virtual worlds and the metaverse, and why blockchain is preferred over other decentralized technologies for the metaverse. We comprehensively review recent advances in metaverse system architectures, focusing on state-of-the-art solutions and lessons learned. We compare the existing literature based on key parameters; namely, contributions, advantages, limitations, and applications. We present key challenges, including deepfake threats, identity theft and brand infringement risks, mental health risks, digital safety and gambling risks, virtual world laws and regulations, and privacy and data security concerns. We outline future recommendations for enabling a sustainable and user-friendly metaverse ecosystem.
Carlos Molina合作论文数Newcastle University8