发表机构
Old Dominion University(奥尔多明尼安大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出一种基于LSTM序列预测的轻量级物联网传感器冒充检测方法,在边缘设备上实现高精度检测,并验证了量化部署的可行性。
AI 中文摘要
一些低成本的物联网(IoT)传感器部署缺乏设备级源认证,使其容易受到冒充或注入传感器读数的影响。我们在一个小型概念验证研究中提出了一种轻量级的传感器冒充检测方法。我们将检测问题表述为一个序列预测问题。一个包含三个LSTM层和两个全连接层的模型仅使用来自真实传感器的单变量温度读数进行训练,当窗口的平均绝对预测误差超过真实平均误差六个标准差以上时,该窗口的读数被标记为异常。该模型被转换为TensorFlow Lite,并以三种变体部署在Arduino Nano 33 BLE上:非量化(554 KB)、16位权重量化(298.5 KB)和8位权重量化(185 KB)。在受控测试平台上,冒充传感器放置在较热的室外位置,三种变体的检测准确率分别达到99.980%、99.972%和98.206%,并且每种变体都在测试序列从真实数据切换到冒充数据时标记了变化点。在我们的测量中,量化使模型更小但速度更慢。真实和冒充的数据分布分离良好,因此这些结果表明检测到了受控的分布偏移,不应被视为通用设备认证的证据。
英文摘要
Some low-cost Internet of Things (IoT) sensor deployments lack device-level source authentication, leaving them vulnerable to impersonation or injected sensor readings. We present a lightweight approach to sensor impersonation detection in a small proof-of-concept study. We formulate detection as a sequence-prediction problem. A model with three LSTM layers and two fully connected layers is trained only on univariate temperature readings from a genuine sensor, and a window of readings is flagged when its mean absolute prediction error exceeds the mean genuine error by more than six standard deviations. The model is converted to TensorFlow Lite in three variants, non-quantized (554 KB), 16-bit weight quantized (298.5 KB), and 8-bit weight quantized (185 KB), targeting an Arduino Nano 33 BLE aggregator. The variants were evaluated with the TensorFlow Lite interpreter on the local server, since on-device execution of LSTM models was not yet supported by TensorFlow Lite for Microcontrollers at the time of the study. On a controlled testbed with the impostor sensor placed in a hotter outdoor location, the three variants reached detection accuracies of 99.980%, 99.972%, and 98.206%, and each flagged the change point when a test sequence switched from genuine to impostor data. Quantization made the model smaller but slower in our measurements. The genuine and impostor distributions were well separated, so these results show detection of a controlled distribution shift and should not be read as evidence of general device authentication.