Securely transmitting a large amount of data in a short time is a serious challenge in today's digital age. Cryptographic primitives can significantly alleviate this problem. The invention of digital signatures represents a major advance in this area. The Certificateless Aggregate Signature (CLAS) scheme is a cryptographic primitive that greatly reduces the computation cost by aggregating several signatures into a single short signature. However, the costs of aggregate signatures have not been reduced to the desired extent. In this paper, we propose a certificateless aggregate signature scheme that requires only two bilinear pairing operations to verify both a single signature and an aggregate signature, regardless of the number of signers. This makes the scheme highly suitable for low-cost IoT applications. In this scheme, we also present a Type I attack on Horng et al.'s scheme and provide an improved version.
Low-altitude intelligent transportation systems (LITS) increasingly require personalized federated learning (FL) to adapt perception models across heterogeneous aerial and edge participants without centralizing sensitive local data. Existing personalized FL methods mainly address statistical heterogeneity across clients, but often treat the federation process as a stable source of global guidance. This assumption is fragile in LITS, where intermittent participation, delayed uploads, and client rejoining can make adaptation statistics stale, unstable, or discontinuous.This work presents Reliable Personalized Federated Adaptation (RPFA), a lightweight reliability-aware framework for statistics-based personalized FL under unreliable LITS federation. RPFA is built on a pFedFDA-style feature-distribution adaptation pipeline and keeps the feature extractor, classifier construction, class-wise statistics, and local–global adaptation form unchanged. It introduces three reliability controls along the adaptation pathway: freshness-aware aggregation down-weights stale statistics during global reference construction, reliability-guided local adaptation attenuates unreliable global guidance during client-side interpolation, and reconnection smoothing dampens prototype transitions for clients that return after missed rounds. Experiments on standard personalized FL benchmarks show that RPFA provides consistent accuracy gains while preserving stable convergence behavior. Additional analyses under delayed communication quantify the behavior of reliability and freshness controls, evaluate recovery after delayed participation, and examine rejoining-client prototype transitions. These results indicate that reliability-aware control is a practical complement to statistics-based personalized FL in dynamic LITS environments.
Transportation Networks (TNs) play a critical role in economic and social systems, yet the dynamic nature and inherent heterogeneity of TN data pose challenges for Dynamic Knowledge Integration (DKI). Traditional approaches for matching entities from different knowledge bases often struggle with the complexity and diversity of TN data, which varies across systems and sources such as traffic sensors and GPS devices. To address this issue, this paper proposes a novel Multi-Objective Genetic Programming assisted Stochastic Deep Reinforcement Learning (MOGP-SDRL) for DKI in TNs. Unlike existing methods, the proposed framework combines SDRL and MOGP to achieve superior efficiency, accuracy and adaptability in handling heterogeneous TN data. First, a novel SDRL framework is designed to automate and optimize the selection of Similarity Features (SFs) for entity matching. This framework incorporates a probabilistic action selection mechanism, which enhances exploration during the SF selection process. Second, a novel MOGP is presented to construct high-quality, diverse SFs by exploring non-dominated feature ensembles, enhancing both accuracy and adaptability in matching results, leading to more accurate and adaptable matching results compared to conventional methods. Lastly, new approximate evaluation metrics are developed to assess alignment quality without relying on predefined entity alignments, guiding the optimization process. Experimental evaluations on OAEI’s knowledge graph (KG) dataset and five pairs of real-world TN dataset demonstrate the effectiveness of the MOGP-SDRL framework, which consistently produces high-quality matching results and achieves significant improvements in both accuracy and robustness over existing approaches.
Masquerade and replay attacks on avatars pose critical threats to user privacy and trust in the emerging metaverse. Existing blockchain or decentralized identity (DID) approaches provide auditability but still struggle with unlinkability and lightweight implementation. This article introduces a privacy-preserving avatar authentication scheme that anchors each user's identity to a first-image commitment, derived from visual features and a random nonce through a fuzzy extractor (FE). Under the real-or-random (ROR) model, we formally prove that the protocol mitigates a range of common threats and simultaneously provides mutual authentication, forward secrecy, and user anonymity. The practicality of the proposed scheme is demonstrated through a head-mounted device-to-server prototype. The average session cost is approximately 21.08 ms, representing a 79.38%-89.58% improvement in computational efficiency over several state-of-the-art blockchain-assisted metaverse authentication schemes. Meanwhile, the corrected communication overhead is around 1.3 Kbits, yielding an 8.89%-43.83% reduction compared with existing counterparts. These results indicate that first-image commitments, combined with blockchain auditability, offer an efficient and privacy-preserving foundation for trustworthy avatar interactions in immersive environments, paving the way toward secure and user-centric metaverse ecosystems.
Pattern recognition is widely used in artificial intelligence applications, but privacy leakage arising from data-level pattern analysis may undermine its secure and trustworthy use. In particular, frequent pattern mining on shared or published datasets can unintentionally reveal sensitive information before model training and deployment, creating a serious concern in privacy-sensitive pattern recognition scenarios. To address this issue, this paper studies privacy leakage as a data-level security problem and proposes an optimization-driven framework for sensitive pattern hiding. The proposed framework formulates sensitive pattern sanitization as a constrained optimization problem that suppresses sensitive frequent patterns while preserving non-sensitive structures related to data utility and subsequent analysis. An artificial intelligence inspired metaheuristic optimization strategy is used to identify data modifications that balance privacy protection and utility preservation. The proposed method is evaluated using three complementary metrics: hiding failure, missing cost, and artificial cost. Experiments on benchmark datasets and healthcare-related data show that the proposed framework consistently reduces privacy leakage while preserving high mining-level utility, outperforming existing sanitization approaches. The results suggest that optimization-driven sensitive pattern hiding can serve as an effective and scalable data-level defense against privacy leakage, and can support privacy-preserving pattern analysis in privacy-sensitive application domains.
The large-scale deployment of Internet of Things (IoT) technology across various aspects of daily life has significantly propelled the intelligent development of society. Among them, the integration of IoT and named data networks (NDNs) reduces network complexity and provides practical directions for content-oriented network design. However, ensuring data integrity in NDN-IoT applications remains a challenging issue. Very recently, Wang et al. (Entropy, 27(5), 471(2025)) designed a certificateless aggregate signature (CLAS) scheme for NDN-IoT environments. Wang et al. stated that their construction was provably secure under various types of security attacks. Using theoretical analysis methods, in this work, we reveal that their CLAS design fails to meet unforgeability, a core security requirement for CLAS schemes. In particular, we demonstrate that their scheme is vulnerable to a malicious public-key replacement attack, enabling an adversary to produce authentic signatures for arbitrary fraudulent messages. Therefore, Wang et al.’s design cannot achieve its goal. To address the issue, we systematically examine the root causes behind the vulnerability and propose a security-enhanced CLAS construction for NDN-IoT environments. We prove the security of our improved design under the standard security assumption and also analyze its practical performance by comparing the computational and communication costs with several related works. The comparison results show the practicality of our design.
The advancement of airborne wireless sensor networks (AWSNs) in modern aircraft monitoring has introduced heightened risks to security isolation, particularly from insider threats. Namely, the bidirectional real-time data flows enable attackers to hijack vulnerable nodes as gateways to breach both aircraft control systems and airline operational domains, potentially leading to data exfiltration or system sabotage. To address the issue, more recently, a decentralized zero trust framework for AWSNs has been designed, which is centered on a certificateless aggregation signcryption (CLASC) scheme. Unfortunately, through a concrete security attack, we find that the underlying CLASC scheme is insecure against a public-key replacement attacker. In particular, an attacker can successfully forge a valid signature on any false message, thus destroying unforgeability, one of the most important security features a CLASC scheme must provide. Therefore, the existing design cannot achieve its goal. To tackle this problem, we design a security-enhanced CLASC scheme and prove its security under standard security assumptions. We also analyze its practical performance by comparing the computational and communication costs with several related works. By replacing the insecure CLASC scheme, we obtain a security-enhanced distributed zero trust framework for AWSNs.
Next-generation communication networks are revolutionizing digital publishing through intelligent content distribution and collaborative optimization capabilities. However, existing federated learning approaches face fundamental limitations, including trusted third-party dependencies, excessive communication overhead, and vulnerability to collusion attacks between servers and participants. This paper introduces VHFL-DP, a verifiable homomorphic federated learning framework for digital publishing environments operating within 6G network infrastructures. The framework addresses critical privacy and scalability challenges through four key innovations: a distributed cryptographic key generation protocol that eliminates trusted third-party requirements, Chinese remainder theorem-based dimensionality reduction, auxiliary validation nodes that enable independent verification with constant-time complexity, and an intelligent incentive mechanism that rewards digital publishing platforms based on objective contribution quality metrics. Experimental evaluation on MNIST and Amazon reviews datasets across six baseline methods demonstrates that VHFL-DP achieves superior performance with accuracy improvements of 4.2% over the best baseline method. The framework maintains constant verification time ranging from 2.73 to 2.91 seconds regardless of platform count, increasing from ten to fifty, or dropout rates reaching thirty percent. Security evaluation reveals strong resilience with only 2.4 percentage point accuracy degradation under poisoning attacks compared to 6.7-7.0 points for baseline method, inference attack success near random guessing at 51.3%, and 92.4% successful aggregation under Byzantine adversaries.
Wireless Edge Networks (WENs) are becoming essential for latency-sensitive AI applications like autonomous driving and industrial IoT, where complex AI tasks are executed as AI Service Chains (AISCs). However, existing approaches face two main challenges: the “single-function” limitation of eXpress Data Path (XDP), which restricts the flexibility and parallel deployment of AISCs, and the lack of global optimization in traditional AISC orchestration strategies, leading to resource inefficiencies and increased latency. This paper proposes an efficient AI service orchestration framework for WENs. The framework introduces a container-based high-performance data plane to decouple XDP from physical interfaces, enabling parallel service deployment and optimizing intra-node communication with ipvlan. Additionally, we present a Batch-based Service Chain Orchestration (BSCO) algorithm that uses a GRU network for prediction and a two-layer Deep Reinforcement Learning model for global optimization. Experimental results show that the proposed framework reduces AI service chain latency and outperforms state-of-the-art algorithms in service acceptance, latency control, and load balancing, validating its efficacy in resource-constrained WENs.
Integrating the Industrial Internet of Things (IIoT) and cloud computing is increasingly prevalent in modern business. However, to safeguard data privacy in the cloud server (CS), sensitive information must be encrypted prior to uploading to a CS. The real challenge is searching encrypted data without compromising speed or security. Public Key Encryption with Keyword Search (PEKS) schemes enable the search of ciphertexts without exposing sensitive information. This article introduces a novel Certificateless Searchable Encryption with Cryptographic Reverse Firewalls (CL-SE-CRF). Meanwhile, the proposed scheme addresses the PEKS limitations by removing the requirement for conventional certificate management and addressing concerns related to key escrow. In addition, the security analysis demonstrates that the CL-SE-CRF scheme can prevent and resist keyword guessing attacks (KGA), algorithm substitution attacks (ASA), and chosen keyword attacks (CKA). Furthermore, experimental results demonstrate that the CL-SE-CRF significantly reduces communication and computation costs in the IIoT compared to similar protocols. Therefore, the proposed scheme is helpful for IIoT applications.
The rapid expansion of the Internet of Things (IoT) has accelerated the widespread adoption of unmanned aerial vehicles (UAVs) in various applications, including traffic monitoring. Nevertheless, storing UAV-collected data on the cloud introduces significant concerns regarding data confidentiality and security. Preserving the privacy of UAV data through encryption is feasible, yet this approach compromises the flexibility and ease of searching and retrieving the encrypted data. This paper introduces a novel heterogeneous searchable signcryption with cryptographic reverse firewalls (HSS-CRF) scheme to enhance the usability of searchable encrypted UAV data and ensure confidentiality. The HSS-CRF protocol establishes a secure communication channel from the sender's UAV site in a certificateless cryptography (CLC) environment to the authorized user utilizing a public key infrastructure (PKI) cryptosystem enhanced by CRF. Furthermore, the HSS-CRF scheme robustly counters threats from internal keyword guessing attacks (IKGAs), algorithm substitution attacks (ASAs), and keyword guessing attacks (KGA). Our analysis demonstrates that the scheme achieves a reduction in computational and communication overhead, making it suitable for resource-constrained UAV environments.
Space-air-ground integrated networks (SAGIN) provide ubiquitous connectivity for large-scale internet of things (IoT) applications by integrating satellite, aerial, and terrestrial networks. However, secure and efficient data authentication in SAGIN remains challenging due to network heterogeneity, dynamic topology, and resource-constrained devices. Traditional public key infrastructure based (PKI-based) schemes incur high certificate management overhead, while identity-based approaches suffer from key escrow, limiting their applicability in SAGIN environments. This paper proposes a hierarchical lightweight certificateless aggregate signature scheme for secure data authentication in SAGIN. In the proposed scheme, IoT devices generate lightweight certificateless signatures, which are hierarchically aggregated at unmanned aerial vehicles and high-altitude platforms without performing pairing operations. The final aggregated signature is verified at powerful satellite or ground control stations, significantly reducing computation and communication overhead. Security analysis shows that the scheme is existentially unforgeable under adaptive chosen-message attacks and resistant to pollution attacks. Performance evaluation through theoretical analysis and simulation demonstrates low overhead, constant-size aggregated signatures, and good scalability, making the proposed scheme suitable for large-scale SAGIN-enabled IoT systems.
The rapid convergence of the Internet of Things (IoT) and the metaverse has intensified cross-domain data exchange and digital asset sharing, raising new challenges in access control, key-abuse prevention, and interoperability across heterogeneous domains. Existing blockchain-based solutions still rely on centralized authorities or isolated single-chain architectures, which limit scalability and flexible cross-domain coordination. To address these issues, this article proposes DCAChain, a decentralized cross-domain access-control architecture for the metaverse. DCAChain integrates a relay-chain (RC)-parachain (PC) model with hashed timelock contract (HTLC) to enable verifiable cross-domain coordination, and builds upon accountable ciphertext-policy attribute-based encryption (CP-ABE)/noninteractive zero-knowledge (NIZK)-based authorization to resist key abuse without trusted intermediaries. The framework further supports dynamic attribute lifecycle management, including expiration, revocation, and key update, and introduces smart-contract-based policy reuse and attribute-set deduplication to reduce repeated encryption redundancy in asynchronous multiuser scenarios. Experimental results on Ethereum and Hyperledger Sawtooth show that DCAChain achieves lower operational cost, reduced latency, and improved scalability compared with representative frameworks. These results indicate that DCAChain is a practical solution for privacy-preserving cross-domain access control in metaverse environments.
With the rapid development of connected autonomous vehicles, intelligent traffic systems are increasingly integrating Roadside Unit (RSU). However, some edge devices in the RSU telecommunication network with limited computing power, due to their simple structures, struggle to implement complex security measures, making them vulnerable nodes in RSU networks and prime targets for cyberattacks. Hence, technologies such as intrusion detection are essential for providing security. However, designing an intrusion detection method that is both efficient and lightweight enough for deployment on RSU devices remains an urgent challenge. To settle these issues, this paper proposes a novel intrusion detection rule generation method that optimise LLM-Generated Intrusion Detection Rules with support vector machine (SVM). This approach automates the generation of intrusion detection rules for new attack types and employs SVM to optimise the parameter values within these rules, making the LLM-generated rules more accurate. The generated detection rules are designed to achieve effective intrusion detection on most edge devices, providing a robust solution for enhancing the security of the RSU network. After the verification of the real machine experiment, the proposed IDS has a detection accuracy of 98.89% for the processed attack types.
With the increasing complexity of logistics operations, traditional static vehicle routing models are no longer sufficient. In practice, customer demands often arise dynamically, and multi-depot systems are commonly used to improve efficiency. This paper first introduces a vehicle routing problem with the goal of minimizing operating costs in a multi-depot environment with dynamic demand. New customers appear in the delivery process at any time and are periodically optimized according to time slices. Then, we propose a scheduling system TS-DPU based on an improved ant colony algorithm TS-ACO to solve this problem. The classical ant colony algorithm uses spatial distance to select nodes, while TS-ACO considers the impact of both temporal and spatial distance on node selection. Meanwhile, we adopt Cordeau’s Multi-Depot Vehicle Routing Problem with Time Windows (MDVRPTW) dataset to evaluate the performance of our system. According to the experimental results, TS-ACO, which considers spatial and temporal distance, is more effective than the classical ACO, which only considers spatial distance.
The inception of certificateless aggregate signature (CLAS) schemes in constrained bandwidth scenarios has made great progress in recent times. CLAS is used widely in many IoT applications such as vehicular ad-hoc networks (VANETs), healthcare sectors, industrial internet of things (IIoT), e-voting, smart homes, and an endless list. Very recently Xiong et al. proposed a collusion-resistant aggregate signature scheme without using certificates for VANETs. The security of the scheme was based on the hardness of ECDLP and security is shown by analyzing the random oracle model to imply that the scheme is unforgeable against the attack of Type ℐ and Type ℐℐ adversaries. Unfortunately, we demonstrate by performing a Type ℐℐ attack that the scheme is not suitable for deployment in practical IoT applications as it can not withstand the attack. Further, we also give the reason for its vulnerability. Then the improvement of the scheme is presented to make it more stable and to be able to withstand the Type ℐℐ adversary attack. The specific improvement of the scheme is to make the scheme Type ℐℐ attack-resistant. The improved scheme can be deployed in any network system that has constrained bandwidth scenarios with a large number of users.
Qiao et al. recently presented a novel approach to building certificateless aggregate signature (CLAS) schemes that guarantee the authenticity of clinical record in healthcare wireless medical sensor networks (HWMSNs). They start by developing a certificateless signature technique, from which they propose a CLAS technique by incorporating an aggregational and a verification algorithm. We argue in this paper that the Type I attacker who is capable to access secret keys of medical sensor nodes can forge valid signatures, making their CLAS scheme insecure. That is, their CLAS scheme does not truly attain the unforgeability. Ultimately, we apply our cryptanalysis to the real-world use case. That is, the adversary can cast a real attack against their CLAS technique using our attack method to forge signatures in the practical application of HWMSNs. Thus, Qiao et al.’s CLAS technique is completely breakable.
In insider threat detection, fake data significantly increases false alarms and obscures genuine threats. Currently, blockchain technology is widely used in the field of traceability. However, effectively enhancing the efficiency of blockchain-based traceability remains a critical research challenge. In this paper, we propose a multi-blockchain collaborative traceability framework - integrating consortium, public, and private blockchains - to mitigate fake data injection in insider threat detection. We categorize users into regular and VIP tiers, tailoring distinct traceability algorithms for each group to optimize operational efficiency. We finally present a public-private blockchain framework that markedly improves traceability efficiency. Experimental results demonstrate that the proposed framework is efficient compared to public-blockchain architecture.
Accurately segmenting various clinically significant lesion areas from whole-body computed tomography (CT) scans is crucial for automated diagnosis and treatment planning. Training an automatic segmentation model effectively is desirable, but it heavily relies on a large scale of pixel-wise labeled data, which is laborious, time-consuming, and expensive to obtain. Existing weakly-supervised segmentation approaches often struggle with regions nearby the lesion boundaries. This paper proposes a target-level incomplete annotation (TIA) for medical image annotation and a multi-lesion segmentation framework. TIA annotates only one complete target region per slice to accurately capture boundaries with minimal annotated effort. Multi-lesion segmentation framework is a weakly supervised learning method, which first implements a medical cut-paste segmentation branch to provide images with pure target pixels and boundaries for training the lesion segmentation model, second utilizes prior anatomical information in the prior-assisted target localization branch to locate and identify target regions, third generates high-confidence pseudo-labels by combining the outputs of cut-paste segmentation branch and prior-assisted target localization branch. A graph neural network (GNN) is adopted to correct noisy labels and propagate reliably labeled pixels to unlabeled pixels. By utilizing TIA, our framework can achieve state-of-the-art results for medical image segmentation, which is validated on Crohn's dataset.
Federated learning (FL) empowers privacy-aware consumer electronics but remains vulnerable to backdoor attacks that compromise safety-critical applications. We present SpecGuard, a server-side defense designed for communication-constrained consumer electronics and AIoT systems. SpecGuard characterizes client updates via a parameter-only sensitivity spectrum and filters malicious participants using the Wasserstein-1 distance to a benign prototype. Crucially, this approach requires no auxiliary data, trigger knowledge, client-side modification, or additional client communication. We evaluate SpecGuard on MNIST, CIFAR-10, and CIFAR-100 against representative adaptive attacks. Experiments using a MobileNet backbone, reduced-participation scenarios, dispersion-gate sensitivity analysis, anomaly-score visualization, and optimized server-side runtime measurement show that SpecGuard mitigates backdoors under the evaluated attacks while introducing no extra client communication and only limited server-side overhead.