{"id":"https://openalex.org/W7125914194","doi":"https://doi.org/10.3389/frcmn.2025.1697204","title":"Autonomous federated defense for zero-day threats in IIoT: explainable agents with real-time edge inference","display_name":"Autonomous federated defense for zero-day threats in IIoT: explainable agents with real-time edge inference","publication_year":2026,"publication_date":"2026-01-28","ids":{"openalex":"https://openalex.org/W7125914194","doi":"https://doi.org/10.3389/frcmn.2025.1697204"},"language":"en","primary_location":{"id":"doi:10.3389/frcmn.2025.1697204","is_oa":true,"landing_page_url":"https://doi.org/10.3389/frcmn.2025.1697204","pdf_url":"https://public-pages-files-2025.frontiersin.org/journals/communications-and-networks/articles/10.3389/frcmn.2025.1697204/pdf","source":{"id":"https://openalex.org/S4210213607","display_name":"Frontiers in Communications and Networks","issn_l":"2673-530X","issn":["2673-530X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320527","host_organization_name":"Frontiers Media","host_organization_lineage":["https://openalex.org/P4310320527"],"host_organization_lineage_names":["Frontiers Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Communications and Networks","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://public-pages-files-2025.frontiersin.org/journals/communications-and-networks/articles/10.3389/frcmn.2025.1697204/pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033572800","display_name":"William Villegas-Ch","orcid":"https://orcid.org/0000-0002-5421-7710"},"institutions":[{"id":"https://openalex.org/I4210087759","display_name":"Universidad de las Am\u00e9ricas","ror":"https://ror.org/002kg1049","country_code":"NI","type":"education","lineage":["https://openalex.org/I4210087759"]}],"countries":["NI"],"is_corresponding":true,"raw_author_name":"William Villegas-Ch","raw_affiliation_strings":["Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas","institution_ids":["https://openalex.org/I4210087759"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124094345","display_name":"Rommel Gutierrez","orcid":null},"institutions":[{"id":"https://openalex.org/I4210087759","display_name":"Universidad de las Am\u00e9ricas","ror":"https://ror.org/002kg1049","country_code":"NI","type":"education","lineage":["https://openalex.org/I4210087759"]}],"countries":["NI"],"is_corresponding":false,"raw_author_name":"Rommel Gutierrez","raw_affiliation_strings":["Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas","institution_ids":["https://openalex.org/I4210087759"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002559820","display_name":"Jaime Govea","orcid":"https://orcid.org/0009-0005-5706-8422"},"institutions":[{"id":"https://openalex.org/I4210087759","display_name":"Universidad de las Am\u00e9ricas","ror":"https://ror.org/002kg1049","country_code":"NI","type":"education","lineage":["https://openalex.org/I4210087759"]}],"countries":["NI"],"is_corresponding":false,"raw_author_name":"Jaime Govea","raw_affiliation_strings":["Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Escuela de Ingenier\u00eda en Ciberseguridad, FICA, Universidad de Las Am\u00e9ricas","institution_ids":["https://openalex.org/I4210087759"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5124111161","display_name":"Pablo Palacios","orcid":null},"institutions":[{"id":"https://openalex.org/I911713783","display_name":"Universidad Diego Portales","ror":"https://ror.org/03gtdcg60","country_code":"CL","type":"education","lineage":["https://openalex.org/I911713783"]}],"countries":["CL"],"is_corresponding":false,"raw_author_name":"Pablo Palacios","raw_affiliation_strings":["Escuela de Inform\u00e1tica y Telecomunicaciones, Universidad Diego Portales"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Escuela de Inform\u00e1tica y Telecomunicaciones, Universidad Diego Portales","institution_ids":["https://openalex.org/I911713783"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5033572800"],"corresponding_institution_ids":["https://openalex.org/I4210087759"],"apc_list":{"value":1900,"currency":"USD","value_usd":1900},"apc_paid":{"value":1900,"currency":"USD","value_usd":1900},"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.13387266,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"6","issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.39559999108314514,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.39559999108314514,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10714","display_name":"Software-Defined Networks and 5G","score":0.1737000048160553,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.08139999955892563,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.7549999952316284},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.6668999791145325},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6567000150680542},{"id":"https://openalex.org/keywords/asynchronous-communication","display_name":"Asynchronous communication","score":0.5569999814033508},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5430999994277954},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.4616999924182892},{"id":"https://openalex.org/keywords/adaptability","display_name":"Adaptability","score":0.438400000333786},{"id":"https://openalex.org/keywords/latency","display_name":"Latency (audio)","score":0.40939998626708984},{"id":"https://openalex.org/keywords/emulation","display_name":"Emulation","score":0.4049000144004822}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7858999967575073},{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.7549999952316284},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6668999791145325},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6567000150680542},{"id":"https://openalex.org/C151319957","wikidata":"https://www.wikidata.org/wiki/Q752739","display_name":"Asynchronous communication","level":2,"score":0.5569999814033508},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5430999994277954},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.4616999924182892},{"id":"https://openalex.org/C177606310","wikidata":"https://www.wikidata.org/wiki/Q5674297","display_name":"Adaptability","level":2,"score":0.438400000333786},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.42590001225471497},{"id":"https://openalex.org/C82876162","wikidata":"https://www.wikidata.org/wiki/Q17096504","display_name":"Latency (audio)","level":2,"score":0.40939998626708984},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.4049000144004822},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4043999910354614},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.3693000078201294},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.35339999198913574},{"id":"https://openalex.org/C46743427","wikidata":"https://www.wikidata.org/wiki/Q1341685","display_name":"Inference engine","level":3,"score":0.34869998693466187},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3176000118255615},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.31700000166893005},{"id":"https://openalex.org/C62611344","wikidata":"https://www.wikidata.org/wiki/Q1062658","display_name":"Node (physics)","level":2,"score":0.31119999289512634},{"id":"https://openalex.org/C2776452267","wikidata":"https://www.wikidata.org/wiki/Q1503443","display_name":"Secrecy","level":2,"score":0.3059000074863434},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3043000102043152},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.2924000024795532},{"id":"https://openalex.org/C98025372","wikidata":"https://www.wikidata.org/wiki/Q477538","display_name":"Systems architecture","level":3,"score":0.2874000072479248},{"id":"https://openalex.org/C123745756","wikidata":"https://www.wikidata.org/wiki/Q1665949","display_name":"Interconnection","level":2,"score":0.27799999713897705},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.275299996137619},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.27320000529289246},{"id":"https://openalex.org/C13687954","wikidata":"https://www.wikidata.org/wiki/Q4826847","display_name":"Autonomous agent","level":2,"score":0.2689000070095062},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.2599000036716461},{"id":"https://openalex.org/C20136886","wikidata":"https://www.wikidata.org/wiki/Q749647","display_name":"Interoperability","level":2,"score":0.2581000030040741},{"id":"https://openalex.org/C46637626","wikidata":"https://www.wikidata.org/wiki/Q6693015","display_name":"Low latency (capital markets)","level":2,"score":0.25699999928474426}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.3389/frcmn.2025.1697204","is_oa":true,"landing_page_url":"https://doi.org/10.3389/frcmn.2025.1697204","pdf_url":"https://public-pages-files-2025.frontiersin.org/journals/communications-and-networks/articles/10.3389/frcmn.2025.1697204/pdf","source":{"id":"https://openalex.org/S4210213607","display_name":"Frontiers in Communications and Networks","issn_l":"2673-530X","issn":["2673-530X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320527","host_organization_name":"Frontiers Media","host_organization_lineage":["https://openalex.org/P4310320527"],"host_organization_lineage_names":["Frontiers Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Communications and Networks","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:11ccabe8fcb947ceba850ff5ccd2b242","is_oa":true,"landing_page_url":"https://doaj.org/article/11ccabe8fcb947ceba850ff5ccd2b242","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Frontiers in Communications and Networks, Vol 6 (2026)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.3389/frcmn.2025.1697204","is_oa":true,"landing_page_url":"https://doi.org/10.3389/frcmn.2025.1697204","pdf_url":"https://public-pages-files-2025.frontiersin.org/journals/communications-and-networks/articles/10.3389/frcmn.2025.1697204/pdf","source":{"id":"https://openalex.org/S4210213607","display_name":"Frontiers in Communications and Networks","issn_l":"2673-530X","issn":["2673-530X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320527","host_organization_name":"Frontiers Media","host_organization_lineage":["https://openalex.org/P4310320527"],"host_organization_lineage_names":["Frontiers Media"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Communications and Networks","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.6041150093078613}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W7125914194.pdf"},"referenced_works_count":39,"referenced_works":["https://openalex.org/W2799758613","https://openalex.org/W3042513331","https://openalex.org/W3139512517","https://openalex.org/W3164964481","https://openalex.org/W4224209533","https://openalex.org/W4285079201","https://openalex.org/W4293192745","https://openalex.org/W4312494597","https://openalex.org/W4317810332","https://openalex.org/W4365816927","https://openalex.org/W4379033976","https://openalex.org/W4380982224","https://openalex.org/W4385626989","https://openalex.org/W4386350812","https://openalex.org/W4386396915","https://openalex.org/W4387333462","https://openalex.org/W4388430674","https://openalex.org/W4388573166","https://openalex.org/W4388893622","https://openalex.org/W4389104772","https://openalex.org/W4389169163","https://openalex.org/W4389170038","https://openalex.org/W4389506101","https://openalex.org/W4390605115","https://openalex.org/W4391707534","https://openalex.org/W4391929666","https://openalex.org/W4391986380","https://openalex.org/W4392509909","https://openalex.org/W4392850107","https://openalex.org/W4392894612","https://openalex.org/W4395084645","https://openalex.org/W4402924078","https://openalex.org/W4403597597","https://openalex.org/W4405844464","https://openalex.org/W4405993585","https://openalex.org/W4409047211","https://openalex.org/W4409491027","https://openalex.org/W4412453539","https://openalex.org/W4414333426"],"related_works":[],"abstract_inverted_index":{"The":[0,127,181],"growing":[1],"interconnection":[2],"of":[3,14,162,168,174],"industrial":[4,69],"devices":[5],"in":[6,49,65,131],"IIoT":[7,81],"networks":[8,82],"has":[9],"significantly":[10],"increased":[11],"the":[12,92,149,156,195],"exposure":[13],"critical":[15],"infrastructures":[16],"to":[17,41,43,141],"sophisticated":[18],"cyberattacks,":[19],"including":[20],"0-day":[21,144],"threats,":[22],"sensor":[23],"spoofing,":[24],"and":[25,46,67,76,114,117,151,170,186,202],"lateral":[26],"propagation.":[27],"Conventional":[28],"intrusion":[29],"detection":[30,160],"systems,":[31],"based":[32,83],"on":[33,84],"static":[34],"rules":[35],"or":[36],"supervised":[37],"learning,":[38],"often":[39],"fail":[40],"generalize":[42],"unknown":[44],"patterns":[45],"lack":[47],"adaptability":[48],"decentralized":[50],"edge":[51],"environments.":[52],"Moreover,":[53],"most":[54],"AI-based":[55],"approaches":[56],"do":[57],"not":[58],"offer":[59],"real-time":[60,105,125],"interpretability,":[61],"hindering":[62],"their":[63],"deployment":[64],"regulated":[66],"auditable":[68],"contexts.":[70],"This":[71],"work":[72],"proposes":[73],"an":[74,119,132,171],"autonomous":[75],"distributed":[77],"defense":[78],"system":[79,157],"for":[80,124],"Deep":[85],"Deterministic":[86],"Policy":[87],"Gradient":[88],"agents":[89],"deployed":[90],"at":[91],"edge,":[93],"coordinated":[94],"through":[95],"asynchronous":[96],"federated":[97,182],"learning.":[98],"Each":[99],"agent":[100],"performs":[101],"local":[102],"inference":[103,172],"using":[104,148],"extracted":[106],"traffic":[107],"features,":[108],"such":[109],"as":[110],"entropy,":[111],"command":[112],"frequency,":[113],"inter-packet":[115],"time,":[116],"integrates":[118],"embedded":[120,196],"SHAP-based":[121],"XAI":[122],"module":[123],"explainability.":[126],"model":[128,187],"is":[129],"trained":[130],"open-world":[133],"setting,":[134],"excluding":[135],"entire":[136],"attack":[137,179],"classes":[138],"during":[139],"training":[140],"simulate":[142],"realistic":[143],"conditions.":[145,180],"Experimental":[146],"validation":[147],"TON_IoT":[150],"N-BaIoT":[152],"datasets":[153],"demonstrates":[154],"that":[155],"maintains":[158],"a":[159,164],"F1-score":[161],"92.0%,":[163],"false":[165],"positive":[166],"rate":[167],"4.1%,":[169],"latency":[173],"182":[175],"m":[176],"under":[177],"multi-node":[178],"architecture":[183],"ensures":[184],"robustness":[185],"continuity":[188],"even":[189],"with":[190],"unstable":[191],"node":[192],"participation,":[193],"while":[194],"interpretability":[197],"mechanism":[198],"enables":[199],"on-site":[200],"auditability":[201],"decision":[203],"traceability.":[204]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-01-29T00:00:00"}
