IJCNIS Vol. 18, No. 5, Oct. 2026
Cover page and Table of Contents: PDF (size: 855KB)
REGULAR PAPERS
The rapid growth of digital networks has made online platforms more vulnerable to Distributed Denial of Service (DDoS) attacks. These attacks can cause serious service interruptions and performance degradation. Traditional Intrusion Detection Systems (IDSs) often struggle with poor detection accuracy, frequent false alerts, and delays in recognizing ongoing attacks. This study proposes an improved hybrid IDS that uses the Honey Badger Algorithm (HBA) to choose essential traffic features, Light Gradient Boosting Machine (LightGBM) for accurate and fast classification, and Long Short-Term Memory (LSTM) networks to analyze time-based traffic patterns. The system was tested with the CICDDoS2019 dataset using 10-fold cross-validation. To ensure generalization and robustness, the proposed IDS was further validated on the NSL-KDD dataset. Comparative analysis demonstrates superior detection accuracy, faster convergence, and reduced false positive rates compared to traditional and recent hybrid IDS models. The study emphasizes novelty, includes multiple dataset evaluations, and presents ablation testing to demonstrate reliability. Results show that the model achieves more than 98% detection accuracy with a low false positive rate and quick processing time. Hence the proposed IDS provides a scalable and real-time-capable framework for modern DDoS detection across diverse network environments.
[...] Read more.The article examines the problem of ensuring the cyber resilience of critical information infrastructure in the context of the global transformation of cyberattack methods and the growing role of foreign state actors in destabilizing critical systems. Given the unprecedented increase in the number of incidents and the emergence of new threat vectors associated with the use of artificial intelligence, traditional approaches to security assessment are becoming insufficient. This creates a critical need to develop tools for quantitatively calculating the level of critical information infrastructure cybersecurity in order to respond quickly to challenges and objectively predict risks. Based on a systematic analysis of international standards and frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework, the article justifies the need for a formalized mathematical apparatus for the transition from a qualitative description of security measures to their quantitative measurement. The authors propose a hierarchical Multi-Criteria Decision Making model for calculating an integral indicator of the level of cybersecurity. This model is based on a synthesis of the theoretical-multiple approach, the Analytic Hierarchy Process, and non-compensatory gating thresholds. The mathematical apparatus allows for the inequality of different groups of cybersecurity measures to be taken into account by applying a system of weighting coefficients calculated on the basis of expert assessments using the Saaty scale. The development process includes eight distinct stages, from determining criteria sets to integrating non-compensatory gating mechanisms to prevent technical deficiencies from being masked by administrative achievements. Experimental testing of the model was conducted using a representative critical infrastructure facility grounded in anonymized real-world audit data from the energy sector. The results confirmed the model's effectiveness, yielding an integral indicator of 0.56, while specifically identifying the detection domain as a vulnerable segment with a score of 0.36. This confirms the practical significance of the model for supporting management decisions on priority resource allocation.
[...] Read more.Secure and efficient transmission of medical images requires integrating compression, encryption, and substitution mechanisms to protect sensitive patient data. Compression reduces image size, improving transmission and storage while preserving diagnostic quality. Encryption ensures confidentiality and the Health Insurance Portability and Accountability Act (HIPAA) compliance, safeguarding patient information from unauthorized access. Nonlinear substitution using dynamic S-boxes increases confusion and strengthens resistance to cryptanalysis. This paper presents a hybrid medical image encryption scheme comprising three sequential stages for high security and computational efficiency. In preprocessing, images are resized, normalized, partitioned into uniform blocks, and compressed using compressive sensing based on partial discrete Fourier transform sampling. The encryption stage applies adaptive S-boxes with block interleaving, followed by the Advanced Encryption Standard in Galois/Counter Mode to provide integrity-preserving encryption. During decryption, the Fast Iterative Shrinkage-Threshold Algorithm reconstructs images accurately. Experimental results demonstrate that the scheme preserves image quality, achieves effective compression, and resists statistical and cryptographic attacks, making it suitable for secure medical image communication in resource-limited environments.
[...] Read more.Cloud platforms generate massive API access logs, where abnormal patterns may indicate security breaches, insider threats, or compromised credentials, demanding intelligent and automated anomaly detection mechanisms. Conventional approaches employ segmentation, statistical profiling, clustering, recurrent networks, and supervised classifiers to model sequential API behavior and distinguish normal activities from malicious deviations. These techniques generally achieve high detection accuracy and improved threat visibility, enhancing cybersecurity monitoring systems while reducing manual auditing efforts in large-scale distributed cloud environments. However, they struggle with evolving attack patterns, high false-positive rates, limited temporal dependency modelling, data imbalance, and poor generalization across heterogeneous cloud infrastructures. This study proposes a self-supervised Temporal Convolutional Network with adaptive anomaly scoring, achieving robust sequential modelling, reduced false alarms, and improved detection stability in cloud APIs. A self-supervised Temporal Convolutional Network models sequential API behavior using causal dilated convolutions and adaptive scoring, enabling accurate, scalable, and real-time cloud anomaly detection.
[...] Read more.Edge computing has become a fundamental paradigm in real-time data processing of latency-sensitive applications like smart healthcare, Internet of Things (IoT), and financial systems. Nevertheless, current edge and cloud-based solutions do not provide a high level of privacy or have a high level of computational and communication overhead because of intensive cryptographic actions. In this paper, a lightweight privacy-conscious edge computing architecture is proposed and can be used to provide secure and low-latency computation on sensitive data based on a combination of feature-level selective lightweight homomorphic encryption, context-sensitive differential privacy, and fully edge-enforced privacy control. In contrast to traditional solutions, which use consistent encryption or fixed privacy controls, the proposed system only encrypts privacy-sensitive data characteristics and dynamically adjusts differential privacy noise depending on the actual system state. The design utilizes significantly fewer resources and offers superior scalability without compromising privacy guarantees. Extensive simulations in a realistic edge computing environment show that the proposed architecture can reduce the encryption overhead by up to 60 percent, reduce the communication latency to approximately 2 ms, and maintain an accuracy of over 98 percent under strict privacy requirements. The comparison of results indicates that the suggested framework is more efficient in computing, scalable, and compliant with regulations than cloud-based and current edge computing solutions. The suggested solution offers a realistic and scalable answer to real-time privacy-preserving edge analytics within resource-constrained environments.
[...] Read more.Context-sensitive smart defense represents a crucial element in protecting distributed cyber-physical systems against advanced and well-coordinated adversarial actions. The current defense architectures face serious issues, such as incompleteness of situational observability and a lack of cross-zone coordination during uncertainty conditions. In order to overcome these constraints, a context-aware smart defense system was proposed that integrates multi-source data and different learning approaches for Intrusion Detection System (IDS) and mitigation. The framework is a collection of data from a variety of sensors, surveillance cameras, radars, and threat databases scattered across numerous Defense Zones. During data transmission from multi-modality devices, there is a possibility of intrusion. For IDS, the network data is pre-processed using Deep Ladder Imputation Networks (DLIN) to fill in gaps and then dispersion-based normalization. Structured sensor and network data are used by the TabNet encoder, and cross-modal attention modules are used to preserve essential network features from different modalities. Graph Neural Networks are used to enable the spatial-temporal analysis to extract the contextual threat information. In the case of emerging or data-sparse zones, Auto Encoder-based Transfer-Learning (AE-TL) methods can be used to produce domain adaptation based on data-rich zones. When attacks are detected, a federated learning-based multi-agent reinforcement learning based on FedQMIX coordinates defense measures without violating data privacy. Bayesian threat inference is used to assess the possibility of future adversarial attacks in non-attack conditions. Empirical assessments indicate that the suggested transfer-learning approach achieves an accuracy of 98.50% and an F-beta of 97.85%. Federated learning combined with reinforcement learning attains an accuracy of 98.1% and 95.6% on attack data and generated data, respectively. Overall, the framework enhances threat detection and coordinated response capabilities, providing a solution to the protection of distributed cyber-physical infrastructures.
[...] Read more.The shift towards a quantum-secured future has driven the demand for more practical ways of protecting files that can add post-quantum cryptographic components without creating a massive increase in computational or storage demands. This study proposes and tests a hybrid file-security approach combining a post-quantum key encapsulation mechanism and authenticated symmetric encryption for real-world file security. An experimental research design was followed with the use of a valid subset of GovDocs1 corpus as the evaluation sample, and the files were stratified based on the format, size and entropy characteristics. Three different architectures were designed, built and evaluated for design evolution from direct lattice-style architecture to standards-based hybrid architecture. Correctness, runtime, and ciphertext expansion were used to measure performance and compared to other files of various types and data characteristics. The results demonstrate the capability of the final framework to retain the exact reconstruction of the file and gain significantly in storage efficiency and execution time over previous model generations. A comparison of performance over different heterogeneous categories of files showed no significant difference, and overhead was seen to be a consistent decreasing function of file size. The results show that a hybrid design that can provide quantum resistant key protection and efficient authenticated encryption can be used to provide practical post-quantum-ready file security. The study offers an empirically supported framework for the security of files in a post-quantum era and offers a repeatable foundation for research into implementing it for deployment.
[...] Read more.Malware developers employ advanced API obfuscation techniques, such as name randomization, dynamic resolution, call stack manipulation, parameter spoofing, and API chaining, to bypass detection. Existing unimodal analysis systems frequently fail to identify these threats due to their limited scope. To address this, we introduce a novel multi-modal deep learning framework that combines temporal, structural, and parametric analysis for malware detection. This multi‑modal method uses a temporal encoder with self‑attention to detect name obfuscation and API chaining, Graph attention networks analyze call graphs for call stack tampering and dynamic API resolution, while a contrastive learning module identifies anomalous parameter usage. A key novel approach is the dynamic fusion mechanism, which uses attention-based weighting to combine features, enhancing accuracy and interpretability. Additionally, adversarial training ensures robustness against evasion attempts, with theoretical guarantees on performance under variations. Evaluated on 29,505 real‑world malware samples, the proposed multi‑modal framework achieves a 94.2% F1‑score (an 18% improvement over unimodal baselines) and a 98.1% AUC‑ROC. The framework notably maintains 82% robustness against adversarial variations, significantly outperforming conventional LSTM‑based approaches (45%). Beyond detection, the proposed method provides explainable attention maps for forensic analysis and low latency (<1ms/sample), making it suitable for real-time security deployment. These results suggest that multi-modal fusion is critical for next-generation endpoint protection.
[...] Read more.As the Internet of Things (IoT) health monitoring systems expand, measures must be taken to ensure the safe, real-time handling of data, particularly for highly infectious diseases which limit the ability for human interaction. Blockchain provides the necessary transparency and immutability so that patient families and hospitals can align on trust with health data. Hyperledger Fabric is the most commonly used solution for these scenarios, as it operates on X.509 certificates for the authentication of device identity. Yet, with the frequent transmission of the IoT sensors, the need for repeated certificate authentication causes considerable computational lags, which can hinder critical real-time assessments in the care continuum. We propose CAVIC (Certificate Authentication Verification Intelligent Cache), which is aimed at simplifying the verification and caching processes with the goal of diminishing the effects of redundant cryptographic activities. CAVIC tracks the high-traffic IoT devices in a network, including temperature, heart rate, and oxygen saturation sensors, and creates a secured cache for their authenticated certificates. Further processes from these devices are verified via instant cache lookups rather than comprehensive certificate re-evaluations, which drastically reduce verification overhead. In situations where a patient's condition can worsen to an extent requiring immediate action from a doctor, CAVIC guarantees that the system's time is dedicated to the analysis of patient data instead of the continual validation of trusted sensors. Incorporating CAVIC into a Hyperledger-based healthcare testbed, we show reduced latency, lower computational costs, and better responsiveness, all of which add to the safety and efficiency of managing patients remotely.
[...] Read more.Energy consumption has emerged as a critical concern in next-generation wireless communication networks due to the increasing demand for high data rates and seamless connectivity. Ultra-Dense Networks (UDNs) in fifth-generation (5G) systems have been identified as a promising solution to support this demand by deploying a large number of small cell base stations (SBSs) alongside macro base stations (MBSs). However, the dense deployment significantly increases overall power consumption, especially when SBSs remain active under low traffic conditions caused by user mobility.
To address this issue, this paper proposes a novel adaptive sleep mode optimization framework that integrates traffic prediction with the Grasshopper Optimization Algorithm (GOA). Specifically, historical traffic patterns are analyzed to predict future traffic loads at each base station, and these predicted loads are used as input to the GOA to optimally determine the operational mode (active, light sleep, deep sleep, or off) of SBSs under QoS and coverage constraints. This predictive optimization enables dynamic and energy-efficient network adaptation.
The proposed approach enhances the overall energy efficiency (EE) and spectral efficiency (SE) of a two-tier heterogeneous network. Simulation results demonstrate that the proposed method achieves up to 29% improvement in energy efficiency and 21% improvement in spectral efficiency compared to existing approaches.
Industrial IoT systems generate massive telemetry streams, requiring intelligent predictive maintenance models to detect failures early, reduce downtime, and improve operational reliability and safety. Traditional approaches employ statistical analysis, sequence segmentation techniques, CNN-LSTM hybrids, and graph-based classification models to capture spatial-temporal dependencies and identify abnormal device behaviour patterns. These methods typically achieve high classification accuracy but often exhibit moderate RUL estimation performance, demonstrating strong fault detection capability across industrial, energy, and smart infrastructure applications. However, static graph structures, limited temporal attention, imbalanced fault distributions, and poor generalization under noisy conditions restrict robustness and real-world deployment scalability. This paper proposes a dynamic graph-based GAT-BiLSTM with cross-attention and gated fusion, achieving 99.50% accuracy and superior RUL prediction stability under noisy conditions. The framework incorporates adaptive adjacency learning and multi-task optimization to enhance predictive maintenance accuracy and robustness in IoT sensor networks.
[...] Read more.The aim of the study is to quantitatively assess the execution time consistency of UI in distributed systems to identify invariant risk profiles and degradation mechanisms and justify consistency-first, event-aware orchestration . The methodology integrates baseline-profiling, latency-, offline-replay- and concurrency-induction with event-level telemetry, replication and non-parametric inference. The purpose is causal isolation of the degradation mechanisms for execution time consistency of UI in distributed systems. It is empirically established that the execution time consistency of UI in distributed client systems is an infrastructure invariant that systematically degrades under perturbations. Median shifts of ≈+6%, +9% and +13% ΔSDR were recorded, respectively, with large effect sizes (r≈0.57–1.00) for latency, offline→replay, and concurrency. A stable risk profile of UI components was identified. It was maintained in 65–85% of cases regardless of the type of failures and was explained by confirmation delays, merge conflicts, and causal/order violations. Statistical verification confirmed the significance of all effects (p<0.01 after Holm–Bonferroni) with non-overlapping 95% bootstrap CIs, which indicates generalized non-artifact degradation and justifies the necessity of event/state-aware orchestration. Further research prospects are the expansion of domains and multi-tenant architectures, the integration of causal tracing and idempotency auditing, and the combination of infrastructure and UX metrics to reduce ΔSDR ≥30% in distributed scenarios.
[...] Read more.