Physical Unclonable Functions (PUFs) and zero-knowledge proofs (ZKPs) offer a promising basis for secure, privacy-preserving authentication in blockchain-enabled Internet of Things (IoT) systems. This paper presents PUFZIN, a framework that integrates PUFs and ZKPs to support device authentication, privacy protection, and scalability under practical IoT resource constraints. We demonstrate the feasibility of PUFZIN in an Ethereum development environment, achieving an amortized proof-generation time of 65.3 ms on standard hardware and 3.87 s on resource-constrained devices. Under a simulated PUF noise model with (m, n, a) = (254, 254, 40) and noise levels from 0% to 10%, the system achieved 100% authentication success in the evaluated trials, while analytical FAR/FRR estimates indicate negligible FAR and FRR below 0.2% at the highest tested noise level. We further analyze the security of the framework against device impersonation, data tampering, and bounded-query PUF modeling attacks under standard cryptographic assumptions and the simulated PUF model used in this study. Results across different hardware configurations indicate that PUFZIN is practical for IoT-oriented deployments. Overall, the study supports secure and scalable blockchain-based IoT authentication under resource and deployment constraints.
Security for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this paper, we design and analyze NosyNeighbor , an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%.
The integration of Tiny Machine Learning (TinyML) into resource-constrained embedded systems enables real-time, on-device intelligence for Internet of Things (IoT) applications. This paper presents the design and evaluation of a real-time inference system using TensorFlow Lite Micro on an ESP32-S3 platform running FreeRTOS. A task-based architecture is implemented to support periodic inference alongside concurrent workloads, with fine-grained instrumentation to measure latency, jitter, and worst-case execution time (WCET). The experimental evaluation is conducted under multiple scenarios, including baseline execution, periodic scheduling, and priority-induced interference. The results show that system load and task priority configurations significantly affect timing predictability, leading to increased latency variability and missed deadlines under contention. Quantitative analysis using deadline miss ratio, latency distribution, and WCET metrics demonstrates the challenges of maintaining real-time guarantees in embedded TinyML systems. The findings emphasize the importance of scheduling strategies and workload management in achieving reliable performance. This work provides a practical evaluation framework for assessing the real-time behavior of TinyML applications on embedded platforms. It highlights the importance of scheduling-aware system design for reliable edge intelligence.
Time-Sensitive Networking enables deterministic communication in cyber-physical systems using time-aware shapers governed by Gate Control Lists (GCL). Although this mechanism improves reliability, it also introduces vulnerabilities exploitable through schedule-based attacks. We show that, by analyzing traffic patterns, adversaries can estimate GCL parameters and reconstruct the schedule to inject precisely timed traffic. These injections can cause priority inversions, where low-priority flows delay high-priority traffic, degrading latency and schedulability. Such schedule-based attacks are particularly stealthy as conventional Intrusion Detection Systems (IDS) may fail to detect them. We implement this attack and conduct randomized experiments to evaluate the impact on synthetic workloads and on off-the-shelf hardware.
Industrial control system (ICS) protocols face the threat of adversaries launching cyber-physical attacks against protocol endpoints. Vulnerability discovery approaches such as fuzzing can be effective at reducing the risk of such threats. In this paper, we present MCFICS, a coverage-guided greybox fuzzing framework that uses (1) active automata learning for stochastic reactive systems to infer the state machine of a stateful ICS protocol server implementation, and (2) guided fuzzing to explore the state space using this learned state machine. During fuzzing, new input sequences that increase code coverage are used to improve the state space exploration of the ICS protocol implementations. We implemented and tested MCFICS with six example server implementations spanning three widely used ICS protocol implementations. Experimental results show that MCFICS achieves higher branch coverage than the AFLNwe, AFLNet and StateAFL fuzzers by an average (mean of means) of 15.82%, 1.99%, and 37.52%, respectively, with an overall average of 18.44% increased branch coverage. Furthermore, using MCFICS we discovered a new bug in a protocol implementation that we have reported to its upstream maintainer.
This paper addresses the challenge of enhancing cybersecurity in Blockchain-based Internet of Things (BIoTs) systems, increasingly vulnerable to sophisticated cyberattacks. It introduces an AI-powered system model for the dynamic deployment of honeypots, utilizing an Intrusion Detection System (IDS) integrated with smart contract functionalities on IoT nodes. This model enables the transformation of regular nodes into decoys in response to suspicious activities, thereby strengthening the security of BIoT networks. Through a game-theoretic model, specifically Bayesian games, the paper analyses strategic interactions between potential attackers and the AI-enhanced IDS. The model focuses on understanding and predicting sophisticated attacks that may initially appear normal, emphasizing strategic decision-making, optimized honeypot deployment, and adaptive strategies in response to evolving attack patterns.
This paper presents a framework for securing blockchain-based IoT systems by integrating Physical Unclonable Functions (PUFs) and Zero-Knowledge Proofs (ZKPs) within a Hyperledger Fabric environment. Our approach leverages PUFs for robust device authentication and ZKPs for privacy-preserving transaction processing, addressing key challenges of security, privacy, and scalability in IoT systems. The framework's architecture utilizes Hyperledger Fabric's modular design and private channels to enhance scalability. Off-chain experimental results demonstrate the framework's feasibility, with compact proof sizes (median 805 bytes) and efficient processing times (average 2,800 ms end-to-end). A comprehensive security analysis shows the framework's resilience against various attacks, including device impersonation and data tampering. This work provides a foundation for secure and scalable blockchain-based IoT systems, with directions for future on-chain implementation and optimization for resource-constrained devices.
Named data networking (NDN) revolutionized IP-based communication by introducing a content-centric model, based on name-based communication. This paradigm shift offers benefits, including optimized network traffic through in-network caching, improved data security, and resilient communication for Internet of Things (IoT) applications. While these benefits are significant, the deterministic data delivery necessary for time-sensitive IoT applications cannot be guaranteed using the NDN's best effort routing mechanism. This article addresses this challenge by proposing Deterministic NDN of Things (D-NDNoT), a protocol-level integration of a schedulability algorithm into NDN, making it deadline-aware and addressing the specific requirements of time-sensitive IoT applications. We present a time-sensitive NDN protocol incorporating a critical deadline-first (CDF) scheduler to prioritize traffic. By integrating deadline awareness, quality of service metrics, and network characteristics, the algorithm ensures the delivery of time-sensitive data takes precedence over nontime-sensitive content. To validate the effectiveness of the proposed protocol, we evaluate using simulation experiments in OMNET++ and consider metrics, such as end-to-end latency, delay, and deadline. The results demonstrate that the deadline-aware deterministic NDN protocol effectively meets the communication needs of time-sensitive IoT applications, ensuring the timely delivery of critical data.
The integration of the Internet of Things (IoT) devices and solutions into passenger vehicles has transformed cars into a complex system with intelligence and a platform for extending information technology possibilities. These devices communicate through in-vehicle networks that use the controller area network (CAN) as a de facto standard for the safety-critical functionality of the vehicles. One creative exploit against CAN is the bus-off attack, which uses the fault tolerance capabilities of the CAN bus to coerce a victim electronic control unit (ECU) into the bus-off state from which it is not allowed to access the bus. As a result, the victim ECU is unable to send or receive messages. The WeepingCAN attack is a stealthy variation of the bus-off attack that reduces its observability and therefore the effectiveness of detection-based mitigation. In this paper, we introduce three software-based improvements that greatly increase both the efficiency and effectiveness of the WeepingCAN attack. First, we introduce a novel zero-phase approach for synchronizing the attack. Second, we discover an alternative approach to disable retransmissions, which is a key capability of WeepingCAN, that allows the attack to be conducted from more ECUs than before. Third, we identify a transitive attack strategy that enables an attacker to target many more ECUs than originally possible. We evaluate our improvements experimentally using a CAN benchmark and find that the zero-phase synchronization improves the attack success rate from 75% to over 90% and the transitive attack strategy enables all the ECUs in the benchmark to be attacked.
This paper addresses the challenge of Distributed Denial of Service (DDoS) attacks in the Internet of Robotic Things (IoRT) using a federated learning approach. We investigate the performance of Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM) networks, and Gated Recurrent Units (GRUs) for DDoS detection in IoRT systems. Our models are evaluated using the CICDDoS2019 dataset. The CNN-based model achieves the highest performance with an accuracy of 0.9810 and an F1-score of 0.9800, outperforming LSTM and GRU-based models. We analyze the models’ convergence properties and discuss their suitability for resource-constrained IoRT devices. Our results demonstrate the potential of federated learning for enhancing IoRT security while highlighting the trade-offs between model performance and efficiency.
Ransomware is increasingly targeting Internet of Things (IoT) devices, and the resource constraints of these devices make detecting and mitigating such attacks a significant challenge. Unlike traditional ransomware attacks, ransomware in IoT-based attacks aims to affect functionality rather than the availability of data, thus defeating traditional detection methods. To address this issue, this article introduces a lightweight intrusion detection system, L-IDS. It is designed based on the principle of defense in depth and combines multilayer controls, hardware-enhanced TEE such as TrustZone, with machine learning (ML) algorithms. L-IDS can effectively detect and mitigate ransomware attacks inside IoT systems with low resources compared to traditional security scanning methods. By integrating TEE, L-IDS will enhance the security and protection of IoT devices, while ML algorithms will help detect ransomware attacks more efficiently and accurately. Overall, the proposed approach provides a promising solution for protecting IoT systems against ransomware attacks, especially for resource-constrained devices.
This paper reviews the role of blockchain technology in enhancing the security of Internet of Things (IoT) systems and maintaining data integrity. We address the increased vulnerabilities and broader attack surface resulting from the integration of blockchain and IoT. The review emphasizes the potential of technologies like zero-knowledge proofs (ZKP) and post-quantum cryptography (PQC) to mitigate these security challenges. Additionally, we explore how game theory, machine learning, and cyber deception strengthen the defense of blockchain-based IoT systems against various threats. The paper also identifies open research areas, emphasizing the need for continued exploration to advance these fields. An additional contribution of this study is introducing a conceptual framework incorporating these technologies, laying the groundwork for developing advanced security solutions within the blockchain-enhanced IoT ecosystem.
This study proposes a framework to enhance privacy in Blockchain-based Internet of Things (BIoT) systems used in the healthcare sector. The framework addresses the challenge of leveraging health data for analytics while protecting patient privacy. To achieve this, the study integrates Differential Privacy (DP) with Federated Learning (FL) to protect sensitive health data collected by IoT nodes. The proposed framework utilizes dynamic personalization and adaptive noise distribution strategies to balance privacy and data utility. Additionally, blockchain technology ensures secure and transparent aggregation and storage of model updates. Experimental results on the SVHN dataset demonstrate that the proposed framework achieves strong privacy guarantees against various attack scenarios while maintaining high accuracy in health analytics tasks. For 15 rounds of federated learning with an epsilon value of 8.0, the model obtains an accuracy of 64.50 utilizing Ethereum, Ganache, Web3.py, and IPFS, exhibits an average transaction latency of around 6 seconds and consistent gas consumption across rounds, validating the practicality and feasibility of the proposed approach.
Named Data Networking (NDN) has evolved as a networking model that can facilitate Internet of Things (IoT) applications by providing a name-based communication model, innetwork caching, and inherent support for data-centric security. However, despite the benefits, the best-effort NDN cannot offer the deterministic data delivery required by safety-critical IoT applications. This paper proposes a novel deadline-aware NDN protocol that utilizes a critical deadline first scheduler to prioritize traffic based on the approaching deadline. Evaluation results show that the proposed deadline-aware NDN can meet the communication needs of time-sensitive IoT applications.
The Internet of Vehicles (IoV) is envisioned to improve road safety, reduce traffic congestion, and minimize pollution. However, the connectedness of IoV entities increases the risk of cyber attacks, which can have serious consequences. Traditional intrusion detection systems (IDS) transfer large amounts of raw data to central servers, leading to potential privacy concerns. Also, training IDS on resource-constrained IoV devices generally can result in slower training times and poor service quality. To address these issues, we propose a split learning-based privacy-preserving IDS that deploys IDS on edge devices without sharing sensitive raw data. In addition, we propose a regret minimization-based adaptive offloading technique that reduces the training time on resource-constrained devices. Our approach effectively detects anomalous behavior while preserving data privacy and reducing training time, making it a practical solution for IoV. Experimental results show the effectiveness of our approach and its potential to enhance the security of the IoV network.
In recent years, ransomware has evolved to target Internet of things (IoT) devices, such as medical equipment and thermostats. Traditional ransomware detection methods may not be effective for resource-constrained IoT devices as IoT-based ransomware is geared towards impairing functionality rather than accessing data. Therefore, this article proposes L-IDS, a lightweight hardware-assisted intrusion detection system that combines hardware-assisted security, such as Trusted Execution Environment, with machine learning algorithms to detect and mitigate ransomware inside an IoT system with fewer resources. The proposed approach can more effectively protect IoT systems from ransomware attacks and requires less resources than traditional security scanning methods.
Microservice architectures decompose web applications into loosely-coupled, distributed components that interact with each other to provide an overall service. While this popular software architecture paradigm has many advantages in development and deployment, it also introduces a wider attack surface that is vulnerable to both internal and external attackers. Potentially malicious third-party services or software packages, as well as increased communication endpoints, introduce a wide array of security concerns. To improve the resiliency of microservice-based applications, many of which store sensitive data, we propose a novel, path-based anomaly detection and access control infrastructure that requires no modifications to existing software. We propose leveraging trusted proxies deployed alongside each service for request inspection, anomaly detection and signed token propagation for end-user path validation. Our approach reduces the trusted computing base away from the microservices to a smaller set of components that allow for less trust and a smaller attack surface.