<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MQTT &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/mqtt/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Thu, 24 Sep 2026 23:12:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>MQTT &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Digital Twins Meet ESG: New Framework Aims to Make Smart Factories Predictive and Sustainable</title>
		<link>https://scienmag.com/digital-twins-meet-esg-new-framework-aims-to-make-smart-factories-predictive-and-sustainable/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 23:12:53 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[conceptual framework]]></category>
		<category><![CDATA[decision support]]></category>
		<category><![CDATA[decision support systems for manufacturing]]></category>
		<category><![CDATA[digital twin]]></category>
		<category><![CDATA[Digital twin integration]]></category>
		<category><![CDATA[digital twin simulation and decision-making]]></category>
		<category><![CDATA[discrete-event simulation]]></category>
		<category><![CDATA[ESG]]></category>
		<category><![CDATA[ESG-oriented smart factory framework]]></category>
		<category><![CDATA[event-driven industrial architecture]]></category>
		<category><![CDATA[heterogeneous industrial data management]]></category>
		<category><![CDATA[industrial communication protocols (MQTT]]></category>
		<category><![CDATA[industrial IoT]]></category>
		<category><![CDATA[Industry 5.0]]></category>
		<category><![CDATA[Industry 5.0 manufacturing]]></category>
		<category><![CDATA[IoT sensor data integration]]></category>
		<category><![CDATA[MQTT]]></category>
		<category><![CDATA[OPC UA]]></category>
		<category><![CDATA[predictive analytics for factories]]></category>
		<category><![CDATA[predictive production planning]]></category>
		<category><![CDATA[smart manufacturing]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[sustainability dashboards for Industry 4.0]]></category>
		<category><![CDATA[sustainable industrial automation]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=213039</guid>

					<description><![CDATA[Researchers have proposed a six-layer, event-driven digital twin framework that links live factory data, predictive simulation, and human-approved ESG-oriented decisions in smart manufacturing.]]></description>
										<content:encoded><![CDATA[<p>Smart manufacturing has spent the last decade collecting data at a staggering rate, yet most factories still treat their digital tools as isolated islands. A digital twin might simulate a production line, an industrial IoT network might shuttle sensor readings to the cloud, and a sustainability dashboard might track emissions, but rarely do these systems talk to each other in a coordinated, decision-ready way. A new conceptual framework published in Mobile Networks and Applications argues that this fragmentation is precisely what prevents Industry 5.0 ambitions from becoming operational reality, and it proposes a detailed architecture for knitting the pieces together.</p>
<p>The framework, developed by researchers at the Technical University of Košice in the Slovak Republic, integrates six distinct concerns that the literature has typically handled separately: heterogeneous industrial data, a discrete-event simulation-based digital twin, MQTT and OPC UA communication protocols, external predictive analytics, operational ESG-oriented evaluation, and planner decision support. Rather than treating each as a standalone project, the authors arrange them into a six-layer, event-driven architecture in which information flows between layers as discrete events, triggering analysis, prediction, and ultimately human-approved decisions on the factory floor.</p>
<p>At the heart of the proposal is the idea that events, not periodic reports, should drive production planning and control. In an event-driven design, every meaningful occurrence on the shop floor, such as a machine fault, a material shortage, or a completed batch, becomes a message that propagates through the architecture. Lightweight publish-subscribe protocols like MQTT can carry high-frequency telemetry from sensors to cloud services, while OPC UA provides the standardized, semantically rich interface that industrial equipment uses to expose its state. Prior performance studies of these protocols, cited in the paper, show they are well suited to exchanging data between industrial plants and cloud servers, which makes them natural candidates for the communication backbone of a digital twin.</p>
<p>The digital twin itself is built on discrete-event simulation, a modeling technique that represents a production system as a chronological sequence of events and state changes. This choice matters because discrete-event simulation can answer the questions production planners actually ask: what happens to throughput if a machine goes down for two hours, how a rush order reshapes the schedule, or where buffers will overflow. By coupling the simulation model to live industrial data streams, the twin becomes a predictive instrument rather than a static mirror, allowing planners to test candidate schedules and interventions in silico before committing resources on the floor.</p>
<p>The second major contribution is what the authors call a four-layer transformation logic, and it is here that the framework makes its most distinctive claim. Digital technologies, the authors argue, do not directly improve environmental, social, or governance outcomes. Instead, they influence ESG-relevant results only through changes in production planning and control processes and in managerial evaluation. A sensor network by itself reduces nothing; it is the rescheduled batch, the avoided machine failure, or the reweighted performance indicator, approved by a human planner, that translates digital capability into measurable sustainability impact. This mediating logic is intended to correct what the authors see as a common weakness in the literature, where digitalization and sustainability are linked loosely without specifying the causal pathway.</p>
<p>To make the framework concrete, the paper illustrates it with a hypothetical manufacturing scenario, a complete event trace showing how messages move through the six layers, and formal definitions of measurable indicators. The indicator definitions are designed to be operational, meaning they specify exactly what is measured, from what data, and how the resulting values feed into ESG-oriented evaluation. This level of specification is what separates a genuine decision-support architecture from a conceptual diagram: planners can, in principle, implement the indicators directly and audit how each recommendation was derived from underlying events.</p>
<p>Human oversight is built into the architecture rather than bolted on. The framework explicitly positions planner decision support as the final layer, so that predictive outputs and ESG evaluations arrive as recommendations that a human decision-maker reviews and approves before any change to production planning takes effect. This design reflects the broader Industry 5.0 movement, which, as the European policy literature cited in the paper emphasizes, seeks a sustainable, human-centric, and resilient industry rather than full autonomy. The authors position their work in this tradition, drawing on recent scholarship that frames Industry 5.0 as a corrective to the technology-first ethos of Industry 4.0.</p>
<p>The intellectual lineage of the framework is broad. It builds on established digital twin reference models and six-layer architectural patterns from the manufacturing literature, on systematic reviews of machine learning applications in production lines and predictive quality, and on a growing body of work connecting intelligent manufacturing to ESG performance, including empirical studies of Chinese manufacturing firms and recent analyses asking whether smarter production is also greener. By synthesizing these strands, the authors aim to provide what they describe as an explicit integration of technical event flows with human-approved, ESG-oriented production planning and control decisions, something they argue no single existing framework delivers.</p>
<p>The authors are candid about the limits of the current study. The framework is derived through a structured conceptual synthesis, and the paper does not report implemented or empirically validated performance results. No datasets were generated or analyzed, and the hypothetical scenario exists to illustrate the architecture, not to prove it. The authors list as future work a set of concrete validation steps: discrete-event simulation experiments, construction of an MQTT and OPC UA testbed, expert assessment, and industrial validation in real manufacturing settings. Until those studies are complete, the framework should be read as a rigorous design proposal and a research agenda rather than a demonstrated solution.</p>
<p>Even so, the timing of the proposal is significant. Manufacturers worldwide face simultaneous pressure to digitize operations and to report credible environmental, social, and governance performance, and regulators and investors increasingly demand that sustainability claims rest on verifiable operational data. A framework that traces a straight line from a sensor event, through a predictive simulation, to a planner-approved scheduling decision and a defined ESG indicator offers exactly the kind of auditable causal chain that both engineers and sustainability officers need. If the planned testbed and industrial validation bear out the design, event-driven digital twins could become the connective tissue that finally unifies the smart factory&#8217;s many brains, turning streams of industrial telemetry into decisions that are simultaneously faster, more predictive, and demonstrably more sustainable.</p>
<p><strong>Subject of Research:</strong> An event-driven digital twin framework for predictive production planning and ESG-oriented decision support in smart manufacturing</p>
<p><strong>Article Title:</strong> A Conceptual Framework for Event-Driven Digital Twin-Based Predictive Production Planning and ESG-Oriented Decision Support in Smart Manufacturing</p>
<p><strong>Article References:</strong> Karakai, M., &amp; Bobko, D. (2026). A Conceptual Framework for Event-Driven Digital Twin-Based Predictive Production Planning and ESG-Oriented Decision Support in Smart Manufacturing. <em>Mobile Networks and Applications</em>. <a href="https://doi.org/10.1007/s11036-026-02535-3" rel="noopener noreferrer">https://doi.org/10.1007/s11036-026-02535-3</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s11036-026-02535-3" rel="noopener noreferrer">10.1007/s11036-026-02535-3</a></p>
<p><strong>Keywords:</strong> digital twin, smart manufacturing, Industry 5.0, discrete-event simulation, MQTT, OPC UA, predictive production planning, ESG, decision support, industrial IoT, sustainability, conceptual framework</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">213039</post-id>	</item>
		<item>
		<title>Harley the Robot Brings Multilingual AI Home Automation for Under 10,000 Rupees</title>
		<link>https://scienmag.com/harley-the-robot-brings-multilingual-ai-home-automation-for-under-10000-rupees/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Sun, 13 Sep 2026 00:18:35 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[affordable domestic robotics]]></category>
		<category><![CDATA[affordable intelligent home automation solutions]]></category>
		<category><![CDATA[assistive robots]]></category>
		<category><![CDATA[conversational AI]]></category>
		<category><![CDATA[cost-effective smart home devices]]></category>
		<category><![CDATA[ESP32]]></category>
		<category><![CDATA[Google Gemini]]></category>
		<category><![CDATA[home automation]]></category>
		<category><![CDATA[home automation robot]]></category>
		<category><![CDATA[Indian-developed home automation technology]]></category>
		<category><![CDATA[indoor navigation]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[low-cost AI home assistant]]></category>
		<category><![CDATA[MQTT]]></category>
		<category><![CDATA[multilingual AI home automation systems]]></category>
		<category><![CDATA[multilingual speech recognition in robotics]]></category>
		<category><![CDATA[multilingual technology]]></category>
		<category><![CDATA[multilingual voice-controlled home robot]]></category>
		<category><![CDATA[navigation and appliance control robot]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[robotics]]></category>
		<category><![CDATA[robotics research in India]]></category>
		<category><![CDATA[voice interaction]]></category>
		<category><![CDATA[voice-controlled household robot for developing countries]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=199968</guid>

					<description><![CDATA[Researchers at Nirma University have built Harley, a sub-10,000-rupee robot that combines autonomous indoor navigation, MQTT-based appliance control, and multilingual conversational AI for home services.]]></description>
										<content:encoded><![CDATA[<p>A voice-controlled home robot that can navigate a house, switch appliances on and off, and hold a natural conversation in multiple languages has been built for less than 10,000 rupees — roughly one-fifth of the cost of comparable commercial systems. The robot, named Harley, was developed by Tanvi Chokshi of the Department of Electronics and Instrumentation and Dhaval Shah and Viranchi Pandya of the Department of Electronics and Communication at Nirma University in Ahmedabad, India, and described in the International Journal of Intelligent Robotics and Applications. The team set out to tackle three persistent problems in domestic robotics: prohibitive price tags, fragmented functionality that handles either navigation or smart-home control but rarely both, and the near-universal assumption that users speak English.</p>
<p>According to the researchers, existing voice-controlled home service robots typically cost between 150,000 and 250,000 rupees, placing them far beyond the reach of most households in developing economies. Those that are affordable tend to be narrow in capability, addressing a single subsystem such as autonomous movement or internet-of-things appliance control in isolation. And almost without exception, commercial platforms restrict voice interaction to English, excluding the hundreds of millions of users whose first languages are Hindi, Gujarati, or any of the other tongues spoken across linguistically diverse regions. Harley&#8217;s designers argue that no single commercial product currently combines mobile navigation, standard-protocol IoT control, and multilingual conversational AI at any comparable price point.</p>
<p>Technically, Harley rests on a deliberate division of labour between two compute tiers. A Raspberry Pi serves as the high-computing device, handling speech recognition, natural language understanding, navigation decision-making, and the coordination of subsystems. An ESP32 microcontroller sits at the other end of the architecture, tasked with driving the relays and circuits that switch high-power household appliances safely. The bridge between them is MQTT, the lightweight publish-subscribe messaging protocol that has become a de facto standard in industrial and consumer IoT deployments. By structuring communication around MQTT topics, the team decoupled the intelligence layer from the actuation layer, allowing the Raspberry Pi to issue commands to the ESP32 without direct electrical coupling and making the appliance-control subsystem extensible to any MQTT-compliant device.</p>
<p>The conversational layer is powered by the Google Gemini API, which the robot uses to interpret spoken commands and generate context-aware responses across multiple languages. Rather than relying on rigid, keyword-matched command grammars, Harley pipes captured speech to the large language model, which can handle paraphrase, mixed-language utterances, and open-ended questions in addition to discrete instructions such as switching off a fan or navigating to the kitchen. The researchers report that this integration enabled natural, context-aware communication, and that in experimental trials the system earned an average conversational quality rating of 4.1 out of 5.0 across multiple languages — a figure that, while drawn from their own residential evaluation, suggests the interaction model was judged substantially better than the brittle command-and-response behaviour typical of low-cost voice devices.</p>
<p>Navigation is the third pillar of the design. Harley supports voice-enabled navigation commands that direct the robot to predefined locations inside the home, using stored coordinates recorded within the environment. In practice, a user can ask the robot to travel to a named waypoint — a room, a charging dock, or a designated position — and the robot plans and executes the movement autonomously. The waypoint approach trades the complexity of full simultaneous localisation and mapping for a simpler, more robust scheme suited to static home layouts, and it keeps the computational burden low enough to run on modest hardware. The team notes that experimental validation in a residential setting measuring 75 square metres across four rooms demonstrated a high voice recognition accuracy and an improved navigation success rate alongside reliable appliance control with low latency.</p>
<p>The economics of the build are arguably its most striking feature. The researchers itemised the total component cost of Harley at 9,247 rupees, which they benchmarked against a mid-range alternative configuration assembled from commercial off-the-shelf parts at 47,850 rupees — an 80 percent component-level saving. Compared with the 150,000 to 250,000 rupee range quoted for existing voice-controlled home service robots, Harley comes in at roughly 19 percent of the cost of an equivalent system, and a small fraction of the premium end of the market. The authors frame this not merely as an engineering achievement but as a question of access: high-performance home automation robotics, they argue, is achievable at a fraction of current market cost, with particular relevance to multilingual and cost-sensitive environments, including those serving elderly users in developing economies.</p>
<p>That last point carries social weight. India&#8217;s ageing population, like much of Asia&#8217;s, is growing faster than the infrastructure available to support it, and voice-first interfaces are among the most accessible technologies for users with limited mobility, declining eyesight, or low digital literacy. A robot that understands commands in a user&#8217;s native language and can physically move through the home — fetching itself to a bedside, switching appliances, answering questions — addresses a genuinely different user group than the wall-mounted smart speakers and app-controlled plug ecosystems that dominate the consumer market. The researchers position Harley within a broader body of work on service robots in aged care, noting that prior deployments have shown promise but frequently stumble on cost, language support, and the integration gap between mobility and control functions.</p>
<p>The study is candid about its experimental scope. Validation was conducted in a single residential setting rather than across a fleet of homes, and the waypoint-based navigation scheme presumes a relatively stable floor plan, meaning a significant rearrangement of furniture would require re-recording stored coordinates. The conversational quality scores, while encouraging, originate from the development team&#8217;s own evaluation, and larger, independent user studies with elderly and non-technical participants would be needed to establish how the system performs under real-world acoustic conditions, accents, and background noise. The cloud dependence of the Gemini API also raises questions about latency, privacy, and behaviour during internet outages — a consideration the authors&#8217; own cited literature on offline voice interaction for elderly-care robots highlights as an open challenge in the field.</p>
<p>Even so, the work signals a shift in what low-cost robotics can credibly deliver. By pairing commodity single-board computers with lightweight IoT protocols and cloud-scale language models, small academic teams can now assemble systems that until recently demanded enterprise budgets. If the cost trajectory holds, the practical consequences could reach well beyond gadget enthusiasts: assistive robots for elderly users who speak minority languages, affordable automation for small clinics and care homes, and educational platforms that let students experiment with integrated robotics without institutional funding. The Nirma University team, which received no specific grant from any funding agency and developed the system with laboratory facilities and laser-cutting equipment at the institute, has demonstrated that the barrier to a genuinely useful, multilingual, mobile home robot is no longer primarily technical or financial — it is a matter of integration, and Harley shows one concrete way to close it.</p>
<p><strong>Subject of Research:</strong> A low-cost multilingual voice-interactive home service robot integrating navigation, IoT control, and conversational AI</p>
<p><strong>Article Title:</strong> Harley: a voice interactive intelligent robot for home services and automation</p>
<p><strong>Article References:</strong> Chokshi, T., Shah, D., &amp; Pandya, V. (2026). Harley: a voice interactive intelligent robot for home services and automation. <em>International Journal of Intelligent Robotics and Applications</em>. <a href="https://doi.org/10.1007/s41315-026-00587-y" rel="noopener noreferrer">https://doi.org/10.1007/s41315-026-00587-y</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s41315-026-00587-y" rel="noopener noreferrer">10.1007/s41315-026-00587-y</a></p>
<p><strong>Keywords:</strong> robotics, home automation, voice interaction, MQTT, Raspberry Pi, ESP32, conversational AI, Google Gemini, indoor navigation, IoT, multilingual technology, assistive robots</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">199968</post-id>	</item>
		<item>
		<title>Marine Predator Algorithm Steers Smarter Fuzzing for Binary Protocols</title>
		<link>https://scienmag.com/marine-predator-algorithm-steers-smarter-fuzzing-for-binary-protocols/</link>
		
		<dc:creator><![CDATA[Hailey Crawford]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 19:02:07 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[AI-driven security testing]]></category>
		<category><![CDATA[automated fuzzing framework]]></category>
		<category><![CDATA[binary protocol vulnerability testing]]></category>
		<category><![CDATA[binary protocols]]></category>
		<category><![CDATA[CoAP]]></category>
		<category><![CDATA[coverage improvement in fuzzing]]></category>
		<category><![CDATA[crash discovery in binary protocols]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DTLS]]></category>
		<category><![CDATA[efficient network protocol analysis]]></category>
		<category><![CDATA[greybox fuzzing]]></category>
		<category><![CDATA[industrial control system security]]></category>
		<category><![CDATA[IoT protocol fuzzing]]></category>
		<category><![CDATA[marine predator algorithm]]></category>
		<category><![CDATA[Marine Predators Algorithm]]></category>
		<category><![CDATA[MQTT]]></category>
		<category><![CDATA[mutation scheduling]]></category>
		<category><![CDATA[nature-inspired fuzzing]]></category>
		<category><![CDATA[network protocol security]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[software testing]]></category>
		<category><![CDATA[vulnerability detection in binary formats]]></category>
		<category><![CDATA[vulnerability discovery]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=197624</guid>

					<description><![CDATA[Researchers have developed MPAuzz, a greybox fuzzer that uses the nature-inspired Marine Predators Algorithm to intelligently schedule mutations of binary protocol messages, dramatically improving test-case validity, code coverage, and crash discovery across MQTT, DTLS, DNS, and CoAP implementations.]]></description>
										<content:encoded><![CDATA[<p>Security researchers have unveiled a new fuzzing framework that borrows its search strategy from the hunting behavior of ocean predators, and the results suggest that nature-inspired optimization could reshape how the software industry hunts for vulnerabilities in binary network protocols. The tool, called MPAuzz, was developed by Chuan Jiang, Zheng Hong, Guomin Zhang, Yuxuan Li, and Jinbang Gu of the Army Engineering University of PLA in Nanjing, China, and is described in a study published in the open-access journal Cybersecurity. In head-to-head experiments against established protocol fuzzers, MPAuzz achieved a striking average valid-test-case ratio of 98.1 percent, improved branch coverage by 38.3 percent over AFLNet and 26.5 percent over StateAFL, and triggered the highest number of crashes across every target it was tested against.</p>
<p>Binary protocols, which encode data directly as compact byte sequences rather than human-readable text, form the backbone of much of the modern digital world. They underpin network devices, industrial control systems, and Internet of Things applications, where efficiency and low overhead are paramount. But their very compactness creates a security blind spot. Unlike text protocols, binary formats lack delimiters, tags, and other redundant markers that make field boundaries obvious. When implementations of these protocols mishandle malformed messages, the consequences can be severe. The researchers point to the infamous EternalBlue vulnerability in the SMB protocol, which arose from improper parsing of binary messages and enabled buffer overflow and remote code execution with global impact, as a stark reminder of what is at stake.</p>
<p>Mutation-based greybox fuzzing has become one of the most widely used techniques for discovering such flaws. Greybox fuzzers occupy a middle ground between blackbox and whitebox approaches: they do not require complete knowledge of a program&#8217;s internals, but they do use lightweight runtime feedback, such as coverage information gathered through instrumentation, to guide how inputs are mutated. Tools like AFL, AFL++, and MOPT generate malformed test cases by applying mutation operators such as bit flips and byte substitutions to well-formed seed messages, then monitor the target program for crashes, hangs, and other abnormal behavior. The approach has uncovered countless vulnerabilities, yet the authors argue that existing fuzzers stumble when confronted with structured binary messages.</p>
<p>The team identifies three core challenges. First, protocol parsing is difficult because binary protocols represent data as bit streams with unclear field boundaries and implicit semantics, making it laborious to determine which positions in a message can safely be mutated. Second, evaluating the mutation value of different fields is hard because the effect of changing a field depends on runtime behavior, field dependencies, and the target program&#8217;s responses, none of which can be reliably determined statically. Third, and perhaps most damaging, existing fuzzers schedule mutation operators blindly. A bit flip applied to a function code field may drive a program into entirely new logical states, while the same operation on a data field merely alters content. Worse, mutating a length field without adjusting the corresponding payload breaks the message structure, causing the test case to be discarded before it ever reaches deep parsing logic.</p>
<p>MPAuzz tackles these problems in two stages. The first is a feedback-based mutation position exploration module that partitions protocol messages at bit-level granularity rather than the coarser byte level used by most prior tools. This fine granularity matters: in an MQTT message, for example, the high four bits of the header flags field determine the message type while the low four bits serve as flags, a distinction that byte-level analysis cannot capture. The module flips one bit at a time, sends the mutated message to the target, and classifies the result. Normal responses mark a bit as mutable; format anomalies detected with protocol parsing tools such as Tshark mark it as restricted; and mutations of essential control fields such as protocol names and function codes mark regions as immutable. Adjacent bits with similar properties are then merged into continuous regions, giving the fuzzer a map of where mutation is safe, where it must respect constraints, and where it is forbidden.</p>
<p>The second stage is where the ocean comes in. MPAuzz formulates mutation operator scheduling as a multidimensional optimization problem in which each dimension corresponds to the operator choice for one mutation region, and it solves this problem using the Marine Predators Algorithm, a metaheuristic inspired by how marine predators forage. The historically best operator combination plays the role of the predator, while candidate combinations act as prey. The algorithm dynamically switches between Lévy flights, long-distance jumps that enable broad exploration, and Brownian motion, small-step searches that enable fine-grained exploitation. The researchers deliberately chose MPA over alternatives such as multi-armed bandit strategies and particle swarm optimization because mutating one region of a binary message often depends on other regions; treating each region as an independent arm can produce structurally invalid test cases, while PSO&#8217;s velocity-based updates risk premature convergence when early coverage gains come from only a few regions.</p>
<p>The scheduling unfolds across three adaptive stages that mirror the fuzzing lifecycle. In the early, high-speed exploration stage, Lévy-distributed random vectors drive wide-ranging tests of operator combinations to avoid premature convergence. In the middle, balanced coordination stage, the population splits: half fine-tunes the elite combination using Brownian perturbations governed by a quadratically decreasing convergence factor, while the bottom-performing half continues exploring with Lévy motion. In the final, low-speed exploitation stage, an enhanced social learning term pulls candidate combinations toward the best-known strategy, changing only one or a few region assignments at a time. Crucially, a candidate combination is retained only if it satisfies region-specific constraints and improves coverage feedback. The framework also includes a repairing step for restricted regions: when a mutable payload region changes size, the associated length field is recalculated automatically, with nested dependencies repaired from the innermost region outward.</p>
<p>To validate the design, the team evaluated MPAuzz on four widely used binary protocol implementations covering MQTT, DTLS, DNS, and CoAP, comparing it against AFLNet and StateAFL, two of the most prominent greybox protocol fuzzers. Each fuzzer ran continuously for 24 hours per target, with each experiment repeated ten times to account for the inherent randomness of fuzzing. The results were decisive. MPAuzz&#8217;s valid-test-case ratio exceeded 97 percent on every target, compared with 83.1 percent for a multi-armed bandit variant and 79.5 percent for a PSO variant of the same tool. It reached comparable coverage 3.47 times faster than AFLNet and 2.22 times faster than StateAFL on average, with Vargha-Delaney effect sizes mostly at or above 0.85, indicating a consistent statistical advantage.</p>
<p>The vulnerability discovery results were equally compelling. Instrumenting targets with AddressSanitizer to capture memory-related faults, the researchers found that MPAuzz produced more crashes than both baselines on all four targets. On the Mosquitto MQTT broker, MPAuzz triggered an average of 87.8 crashes per run, compared with 3.9 for AFLNet and 43.2 for StateAFL, and exposed its first crash just 32 minutes into testing, whereas AFLNet failed to crash the target within the allotted time at all. On Tinydtls, MPAuzz found its first crash in 15 seconds. Analysis of the proof-of-concept inputs showed that the anomalies detected in Mosquitto and Libcoap correspond to real, documented vulnerabilities: the medium-severity CVE-2021-28166, a null pointer dereference triggered when an authenticated client sends a mutated SUBSCRIBE message before the server issues a PUBLISH message, and the high-severity CVE-2024-46304. These findings demonstrate that the fuzzer can surface genuine security flaws arising from abnormal protocol-state sequences, not merely superficial parsing errors.</p>
<p>The authors are candid about limitations. MPAuzz currently leans on external parsers such as Tshark and Scapy for protocol-format feedback, so for proprietary or undocumented protocols the precision of restricted and immutable region identification may degrade, though the fuzzer can still operate using runtime responses and coverage feedback alone. The automatic repair mechanism primarily supports length-related constraints; checksums, authentication fields, and state-dependent constraints require protocol-specific rules. The evaluation, while rigorous, covers four protocol implementations, and the team notes that additional targets and longer experiments would strengthen the evidence. Still, the work makes a persuasive case that combining protocol-aware region classification with staged, nature-inspired operator scheduling is a practical path forward for binary-protocol fuzzing, and the researchers plan to reduce reliance on external parsers and extend support for proprietary protocols with complex field dependencies in future work.</p>
<p><strong>Subject of Research:</strong> A nature-inspired greybox fuzzing framework for discovering vulnerabilities in binary network protocol implementations</p>
<p><strong>Article Title:</strong> Binary protocol greybox fuzzing driven by marine predators algorithm</p>
<p><strong>Article References:</strong> Jiang, C., Hong, Z., Zhang, G., Li, Y., &amp; Gu, J. (2026). Binary protocol greybox fuzzing driven by marine predators algorithm. <em>Cybersecurity, 9</em>(1), Article 214. <a href="https://doi.org/10.1186/s42400-026-00646-8" rel="noopener noreferrer">https://doi.org/10.1186/s42400-026-00646-8</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s42400-026-00646-8" rel="noopener noreferrer">10.1186/s42400-026-00646-8</a></p>
<p><strong>Keywords:</strong> binary protocols, greybox fuzzing, Marine Predators Algorithm, vulnerability discovery, mutation scheduling, network security, MQTT, DTLS, DNS, CoAP, software testing, cybersecurity</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">197624</post-id>	</item>
	</channel>
</rss>
