Wireless Sensor Networks (WSNs) deployed in disaster-monitoring scenarios require energy-efficient, low-latency multi-hop routing under strict resource constraints. Existing multi-agent reinforcement learning (MARL) approaches such as QMIX and QTRAN treat the routing problem independently, ignoring the network topology and suffering from memory explosion at scale. We propose Graph-Attentive Policy Fusion (GAPF), a lightweight meta-learning framework that fuses frozen MARL expert policies through a Graph Convolutional Network (GCN) encoder and a Contextual Algorithm Selection (CAS) controller. GAPF encodes the sensor topology into a compact graph embedding at episode onset and selects the best-performing expert with only 1,473 trainable parameters. We evaluate GAPF across 7 scenarios spanning 20-100 sensors, 3 seeds each, totalling 21,000 test episodes. GAPF achieves near-perfect packet delivery (>= 98 %) across all scales, with +43% to +111% relative improvement over standalone MARL baselines. It consumes 2- 3.5 & times; less energy, maintains 3- 9 & times; better energy balance, and requires 13 & times; less memory (951 MB vs 13.2 GB), passing all feasibility constraints. The scalability analysis reveals that GAPF's advantage grows superlinearly in sparse networks, where topology-aware relay coordination is most critical. Our results demonstrate that lightweight policy fusion with graph-structural awareness can replace heavyweight monolithic MARL for resource-constrained, safety-critical WSN routing.
In this paper, we propose an HSM-based architecture to detect insider attacks on server-side data. Our proposed architecture combines four cryptography-based defense mechanisms: Nonce-Based Process Authentication (NBPA), Hash-Based Field Integrity (HBFI), Hash-Based Field Availability (HBFA), and Hash-Based Row Availability (HBRA). This novel architecture is designed to detect a predefined comprehensive attack model on server-side data tailored for an HSM-based architecture. The implementation results show that the throughput decrease is mostly manageable (14% for NBPA, 30-50% for HBFI, 25% for HBFA, and 43.74% for the combination of all mechanisms), with the indication that some mechanisms are more or less appropriate depending on the situation. Moreover, the HBRA mechanism performed well regarding the attack detection time (5 minutes for a database of 1000 entries).
The Internet of Medical Things (IoMT) connects medical devices to enable real-time monitoring and personalized care, significantly enhancing patient health and well-being. However, this connectivity also introduces substantial cybersecurity risks, including various attack types that compromise data integrity and availability, jeopardizing patient safety and healthcare service reliability. This study addresses these challenges by proposing a real-time anomaly detection model based on machine learning (ML) techniques, designed to detect and mitigate diverse cyber threats effectively. This paper proposes a new medical dataset for anomaly detection, inspired by the UNSW-NB15 dataset, and enriched with healthcare-relevant attack types, including falsification and DoS attacks, to reflect real-world IoMT scenarios. The dataset comprises 253,680 records, with 60% anomalous data distributed across multiple attack types, offering a more challenging and realistic environment for evaluating ML models. Seven machine learning algorithms, including Random Forest, XGBoost, and Artificial Neural Networks (ANN), were rigorously tested, leading to the development of a novel stacking ensemble model. This model integrates XGBoost as the meta-learner with Random Forest and ANN as base models, leveraging their strengths to optimize anomaly detection. The proposed model was evaluated on both the UNSW-NB15 and the new medical dataset, achieving significant improvements across key metrics such as accuracy, precision, recall, and F1-score. A real-time prediction analysis further demonstrated its ability to detect anomalies efficiently during live data transmission, validating its suitability for detecting anomalies in real-time scenarios.
In this paper, we propose an IoT device cyber physical resiliency approach using a cross-domain device replication that can replicate and securely transfer the profile of the Internet of Things (IoT) user device to another. Our approach aims to offer a cybersecurity abstraction layer to offer continuation of the security engine service when the IoT user device is facing interruption of services in case of IoT-centric solutions, including IoT Mobile payment, Smart city networks communication services, safety communications with integrated location-based services. In a world of cybersecurity where any IoT user devices are vulnerable to hackers, existing IoT devices require them to remain efficiently powered, connected to carry end-to-end secure transaction in an IoT environment without failure. To achieve our goal of resilience and recoverability, we upgraded the IoT modular security engine features with digital replication functions and secure profile transfer capabilities to effectively complete started transactions in situations where lacking sufficient power to transmit or in case of an abrupt connection loss due to network handovers. This leads to integration of IoT cross-environment optimal security enhancements into the existing Simple Public Key Infrastructure following the Pretty Good Privacy Web of Trust approach with Secure Device Profile and Data Processing. Moreover, our implementation succeeded in providing a service continuation on the replicated IoT device, preserving and offering a resilient secure capable environment for carrying secure transactions. The results show a communication success rate of 90 percent between all Security Engine components (DSM, CNSM, SFB) called modules on replicated IoT devices while improving the simulation running time to run two times longer (30 seconds) in each round of tests with 10 per cent faster response and recovery time of 7 seconds.
One of the greatest challenges of Emergency medical services providers is to handle the large number of Emergency Medical Service (EMS) calls coming from the population. An accurate forecast of EMS calls is involved in ambulance fleet dispatching and routing to minimize response times to emergency calls and enhance the efficacy of assistance. Yet, the demand for emergency services exhibits significant variability, posing a challenge in accurately predicting the future occurrence of emergency calls and their spatial-temporal distribution. Here, we propose a stacking ensemble machine learning model to forecast EMS calls, combining different base learners to enhance the overall performance of generalization. Additionally, we conducted experiments using Boruta, Lasso, RFFI and SHAP feature selection methods to identify the most informative attributes from the EMS dataset. The proposed ensemble model integrates a base layer and a meta layer. In the base layer, we applied four base learners: Decision Tree, Gradient Boosting Regression Tree, Light Gradient Boosting Machine and Random Forest. In the meta layer, we used an optimized Random Forest model to integrate the outputs of base learners. We evaluate the performance of our proposed model using the R 2 -score and four different error metrics. Based on a real data set including spatial, temporal and weather features, the findings of this study demonstrated that the proposed stacking-based ensemble model showed a better score and the minimum errors compared to the traditional single algorithms, online machine learning methods and voting ensemble methods. We achieved a higher score of 0.9954, mse of 0.8938, rmse of 0.9454, mae of 0.2923 and mape of 0.0724 compared to state-of-the-art models. This work is an aid for emergency managers in making well-informed decisions, improving outcomes for ambulance dispatch and routing, and enhancing ambulance response time.
In the recent context of the emergence of smart cities, the massive amount of data generated by connected objects has led to unprecedented demands in terms of data transfer. The various constraints linked to their number, their characteristics, and their transmission are even greater and dim the effectiveness, in their regard, of traditional data planning schemes. As a result, the need to minimize the delivery time of urgent packets while reducing the average data delay, the difficulty in choosing and combining the appropriate criteria for classifying and prioritizing data, and the loss of packets are of continuing concern. In this paper, we propose an adaptive scheduling model based on multilevel priority packet classification, preemptive packet queuing with dynamic and adaptive reordering, contingency migration of packets in critical situations, and adaptive criticality-based selection of packet next-hop. We introduce two new parameters for scheduling decisions: the ratio of per-level deadlines reflecting the evolution of a packet in the network and the migration coefficient based on the experience of same-characteristic packets. Performance evaluation shows that the proposed model effectively prevents data loss and prioritizes the transfer of emergency data over a hierarchical wireless sensor network. Moreover, it guarantees the shortest delays for urgent data with an improvement of 31% and promotes fairness toward less urgent ones. The lowest delivery rate observed with the proposed method is 99.9%.
In this paper, we propose a modular security approach using a positioning security engine featuring Global Positioning System (GPS) location features that can uniquely identify the Internet of Things (IoT) user device. Our approach aims to reinforce the security and viability of IoT-centric solutions for various innovative applications, including IoT Mobile payment, Smart city heterogeneous networks, communication services, safety, and location-based services integration. To achieve our goal of securitization and viability, we target consumer IoT devices equipped with built-in location-based GPS chips, which are vulnerable to hackers where the existing cryptographic authentication-based protocols demand power and computation resources required for authentication protocols is not sufficient to carry end to end secure transaction in an IoT environment. Therefore, to compensate this lack of environment capability to carry the end-to-end secure transaction on IoT devices when emitting various radio signals, we implement a modular security approach to compensate the lack of capabilities. This leads to an optimal security facilitated by Simple Public Key Infrastructure following the Pretty Good Privacy Web of Trust approach. Moreover, our implementation on the development board Arduino succeeded in providing and extended secure capable environment for carrying secure transactions. The results show a communication success rate of 70, 80 and 90 percent between Security Engine component called modules, with 70 percent of successful Secure Sockets Layer (SSL) key exchange by every identified user in average 15 seconds simulation running time for every two by third round of simulation.
Mobile banking applications make users' daily lives easier by allowing them to access banking services, such as balance inquiries and bill payments, anytime and anywhere. Since these applications manage very sensitive financial data, special attention must be paid to data security. Several works in the literature assess the security of mobile banking applications. However, we observe the lack of a widely adopted framework among researchers for assessing the security of mobile banking applications. In this paper, we propose a framework consisting of twenty-six criteria for assessing the security of Android mobile banking applications. These criteria are divided into five categories: mobile device security, data in transit, data storage, cryptographic misuse, and others. Subsequently, we evaluate the proposed framework based on predefined requirements. These requirements are no redundancy, no ambiguity, and comprehensiveness. As a case study, we assess the security of the Android mobile banking applications of seven major Canadian banks. The results show that data in transit is adequately protected by these applications.
Internet of Things (IoT) a paradigm that brought several new communication technologies, allowing more ubiquity and real-time applications. This innovation sped up the implementation of intelligent transportation systems in smart cities. However, the use of these technologies needs the original routing protocols. The latters must meet real-time application requirements, such as reduced transmission delay, minimal packet loss, and less power consumption. This paper comes up with a novel solution LoRaWAN-based Geographic Routing Protocol (LGRP) using a multi-criteria metric taking into account delay, packet loss, distance, and relative velocity. The hybridization of LoRaWAN with 802.11p technologies is introduced to overcome challenges of urban scenarios in our protocol achievement. We carry out the routing protocol using the Network Simulator 3 (NS-3). Then, we assess its effectiveness in comparison with the greedy perimeter stateless routing (GPSR), the Ad hoc On-Demand Distance Vector (AODV), the Cross-Layer Weighted Position-based Routing (CLWPR), and the blended OpenFlow-Optimized Link State Routing (Centralized). The simulation results show that the proposed routing protocol outmatches the comparative ones in packet delivery and end-to-end delay.
Data security is an increasingly important issue in 2023. Whether about user privacy, data availability, or integrity, consumer information is getting targeted by cyber-pirates for various motives. Many strategies and tools have been developed to keep outsider attackers from accessing server-side data, but there needs to be more solutions that target insider attacks. In this paper, we propose a combinatory attack model to identify the risks of insider attacks against HSM-based security architectures. Our proposed model is based on the study of attack vectors in the security architecture and the conduction of all possible attacks on those vectors. It shows that these typical architectures are vulnerable to private key theft and replacement and data theft, alteration, swapping, nullification, and deletion. Results show that we successfully conducted each attack on an HSM-based security architecture relatively easily. They prove the essential need for a security architecture considering insider threats.
Vehicular Ad-hoc Networks (VANETs), as the most significant element of the Intelligent Transportation Systems (ITS), have the potential to enhance traffic efficiency and road safety by making the transportation system smarter and are still at the initial point of development. In this paper, we propose an ensemble-based machine learning model for network traffic prediction in VANET. We take advantage of Ensemble Learning (EL), which combines different Machine Learning (ML) models to achieve better performance and improve accuracy. We consider the most informative attributes of the VANET dataset using Boruta and LightGBM as ensemble feature selection methods. Our proposed model is based on Stacking Ensemble Learning with Booster Model (STK–EBM) designed with a stacking ensemble of heterogeneous ML models. The framework of the proposed model consists of two layers, including a base layer and a meta layer. The first layer integrates Random Forest (RF), K-Nearest Neighbor (KNN) and XGBoost as a booster of the base learners. An optimized Logistic Regression (LR) employs as our meta learner in the second layer. We evaluate the performance of our model considering classification metrics and then compare it with the most popular traffic predictive models. Simulation results show that the STK–EBM model gives a more stable prediction than the single algorithm, as well as better overall performance in terms of prediction accuracy and execution time.
Bio-cryptosystems often save the biometric template for authentication and generally employ randomly generated keys to encrypt and sign data. This method raises privacy protection concerns. Furthermore, for a system secured by the usage of a cryptographic key, losing the key often has disastrous consequences. To overcome the privacy issues, and allow the secure recovery of lost keys, we design a Key Derivation Function to extract a key from biometric data: a new method – based on clustering algorithms – detects consistent and discriminative features from biometric characteristics to create a code. Then, HMAC-SHA256 (as specified by the National Institute of Standards and Technology) generates a standard key from the code. To reproduce the code at future times (that also serves for authentication), the Key Derivation Function stores helper data with the guarantee of privacy. Indeed, with a private face dataset, the probability of generating the code with only the helper data is less than 2−300, and less than 2−246 for a subset of the YouTube Face database. Moreover, on the private database and the tested users from the YouTube Face database, our system has a false acceptance rate of 0%. It corrects up to 40.3% of noise levels on the private database and has good management of the inter-user variability.
Vehicular network services in the smart cities generate enormous data by vehicular road users, which is a critical challenge. Network traffic leads to a negative impact on safety applications. AI techniques are a promising solution to address network traffic in VANETs with V2X data. In this paper, we propose a soft voting classification model, which consists of hybrid supervised machine learning algorithms to predict traffic in the network. We evaluate the prediction performance of five well-known machine learning models and the proposed model based on various classification evaluation metrics. The simulation results show that the proposed network traffic prediction model performs better than other considered machine learning models in terms of accuracy (0.94%), time consumption (12.25 seconds) and AUROC (0.907) that proves its stability.
Conventional authentication systems, that are used to protect most modern mobile applications, are faced with usability and security problems related to their static and one-shot nature. Indeed, one-shot authentication mechanisms challenge the user at the beginning of a session leaving them vulnerable to attacks on lost/stolen devices or session hijacking. In addition, static authentication mechanisms always use the same challenges to authenticate the user without considering the dynamic nature of the risk related to the authentication context. To mitigate these challenges, we propose RLAuth, a risk-based authentication system that can automatically adapt the level of challenge presented to the user on each authentication request based on the current context. RLAuth is based on binary anomaly detection, which is solved using a deep reinforcement learning agent that acts as the classifier. To cope with the high class imbalance in the anomaly detection problem, we propose to use a balanced sampling technique during experience replay and an imbalanced correction factor during reward computation. We evaluate RLAuth on a public dataset using the G-mean metric which is the square root of the product of sensitivity with specificity. This metric is efficient to measure the classification performance of a model under class imbalance since it does not overfit to the majority class. Finally, RLAuth obtained a G-Mean of 92.62%. In addition, the reinforcement learning agent can be trained offline for acceptable results in about 130 s and can then be periodically retrained to improve its performance over time.
Active Authentication (AA) systems continuously authenticate users on smartphones. With high quality front-facing cameras available on recent smartphones, face-based active authentication emerges as a good candidate for AA systems. On the other hand, secure authentication of mobile users is a big concern in biometric systems. Mobile match-on-card (MMOC) technique takes advantage of SIM/eSIM card as a secure element (SE) to protect biometric templates and verify users isolated from the smartphone's environment. However, resource limitations of smart cards make MMOC authentication hard to implement. In this paper, we propose two system architectures for MMOC face-based AA systems. In Cloud-assisted MMOC architecture (CA-MMOC), we use cloud resources for model selection and training. Full MMOC architecture (F-MMOC) relies only on SIM/eSIM card's resources for enrollment and verification. A quantization scheme is proposed to make the authentication system implementable on SIM cards, plus a speed-up technique to reduce on-card execution time. Using a public mobile video dataset, we evaluate the proposed system. Our evaluation results show that the proposed MMOC authentication achieves high accuracy in real-time with a small memory footprint on SIM, and is suitable for cross-platform authentication. We also implement the CA-MMOC system on a real smartphone and evaluate the system's performance overhead in terms of power consumption, CPU and memory usage.
In Northern Haiti, a unique experience has been developed and an innovation hub has been realised; the core of this is a City of Knowledge that is articulated around an entrepreneurial university, the Institute of Science, Technology and Graduate Studies of Haiti (ISTEAH). Spread over seven departments in the country, as its name suggests, ISTEAH is a technological university that seeks to put science and technology at the service of development by training citizens, leaders and innovators who can promote the advancement of the country. Resolutely turning towards entrepreneurship, this university is in the process of setting up an entire entrepreneurial ecosystem centred around an incubator-accelerator to create-with students, graduates and young people from around the country-technological and social enterprises to generate value, create wealth and jobs and support sustainable development. In this article, this experiment and its perspectives are analysed in light of the sustainable development goals.
With the rapid development of the Internet and computer technology, mobile applications are becoming more popular to automatically perform everyday tasks at any time and place. Moreover, data is stored on a distant server and accessed remotely. This leads to stealing or damaging information. In this paper, we propose a security architecture based on the Hardware Security Module (HSM) to protect server-side data against outsider attacks. This architecture relies on three cryptographic modules to ensure the protection of the private key and the sensitive data against theft and corruption. The implementation of this architecture showed that the gain in data security is very noticeable in the three modules. The first module increased the safety of the private key storage to prevent an attacker from using it. The second module allows performing regular queries on encrypted fields where all attack vectors related to data sniffing were eliminated. Finally, the third module works in the background to achieve a secure hybrid backup and a complete restoration of the entire database in case of destruction of data. Moreover, the results prove the effectiveness and the performance of our proposed architecture in terms of response times at the level of security of the private key (6% to 92% faster) and the backup of the data (0.7 to 32µs per entry).
Billions of purchase receipts, tickets, invoices, and bills are printed every year worldwide for various commercial transactions. Purchase receipts are necessary proofs for warranty, accounting, refunds, and product repairs in case of product malfunction. However, the production and use of paper receipt involves the use of significant amounts of natural resources, such as trees, water, and energy while also generating large amounts of chemical pollutants and greenhouse gas emissions in the atmosphere. To address these issues and reduce their environmental effects, we propose a digital solution called “Screen-to-Screen” (STS) to transfer purchasing receipts directly from sellers’ screens to customers’ screens through visual smartphone-scannable codes (VSCs) and a dedicated smartphone app. Upon purchase, customers of supermarkets, stores, restaurants, pharmacies, etc., will only need to scan on-screen visual codes with their smartphones to retrieve their purchasing receipts in digital formats, without the need to print or use physical paper receipts anymore. By implementing an eco-friendly STS digital solution, significant amounts of energy, trees, and water can be saved, and considerable amounts of pollutants and greenhouse gas emissions can be avoided.
Blockchain is a new paradigm to realize payment without a single Trusted-Third-Party. The technology exploits cryptography to secure all the transactions that are available to participating nodes for validation via distributed consensus algorithms. Blockchain-based architectures for mobile payment face challenges like transaction privacy and performance issues. We analyze these architectures and assess the privacy issues and the performance in the real world. Then, we propose a payment scheme to guarantee the privacy of the transactions with discussions on tricks to improve the performance. We study the feasibility of implementation of the proposed scheme, both on public and consortium Blockchains. The payment scheme ensures that a participating node has access to only a part of the meaningful data of a transaction. The expected performance with Hyperledger Blockchain (with less than 16 participating nodes) is more than 1000 TPS. We indicate updates to decrease the duration of a transaction from 15 S to less than 1 S with public Ethereum Blockchain.
Steven Chamberland合作论文数Department of Computer Engineering26
H. Boucheneb合作论文数Ecole Polytechnique de Montreal4