Source-linked AI summary

A Survey of Machine and Deep Learning Methods for Internet of Things (IoT) Security

Mohammed Ali Al-Garadi, Amr Mohamed, Abdulla Al-Ali, Xiaojiang Du, Mohsen Guizani

arXiv:1807.11023v1cs.CRcs.LGcs.NI

TL;DR

IoT’s heterogeneous, distributed, and resource-constrained nature creates broad security challenges that conventional mechanisms do not fully address. The paper surveys IoT threats, attack surfaces, ML/DL methods, layer-specific applications, and open challenges, concluding that intelligent security approaches can support anomaly detection and evolving threat protection while facing major data and privacy challenges.

  • Problem

    IoT’s heterogeneous devices, constrained resources, expanding attack surfaces, and evolving threats make effective security difficult across diverse deployments.

  • Method

    The paper comprehensively surveys IoT threats, attack surfaces, ML/DL methods, layer-specific applications, advantages, disadvantages, challenges, and future directions.

  • Results

    The reviewed studies report ML/DL applications for detecting anomalies and abnormal behavior, adapting to evolving threats, and securing IoT layers and environments.

  • Takeaways & Limitations

    The survey provides a structured manual for developing end-to-end, security-based intelligent approaches for IoT systems.

  • Takeaways & Limitations

    High-quality, realistic training datasets containing diverse IoT attack types remain a major challenge for ML/DL security methods.

Abstract

from arXiv · show

The Internet of Things (IoT) integrates billions of smart devices that can communicate with one another with minimal human intervention. It is one of the fastest developing fields in the history of computing, with an estimated 50 billion devices by the end of 2020. On the one hand, IoT play a crucial role in enhancing several real-life smart applications that can improve life quality. On the other hand, the crosscutting nature of IoT systems and the multidisciplinary components involved in the deployment of such systems introduced new security challenges. Implementing security measures, such as encryption, authentication, access control, network security and application security, for IoT devices and their inherent vulnerabilities is ineffective. Therefore, existing security methods should be enhanced to secure the IoT system effectively. Machine learning and deep learning (ML/DL) have advanced considerably over the last few years, and machine intelligence has transitioned from laboratory curiosity to practical machinery in several important applications. Consequently, ML/DL methods are important in transforming the security of IoT systems from merely facilitating secure communication between devices to security-based intelligence systems. The goal of this work is to provide a comprehensive survey of ML /DL methods that can be used to develop enhanced security methods for IoT systems. IoT security threats that are related to inherent or newly introduced threats are presented, and various potential IoT system attack surfaces and the possible threats related to each surface are discussed. We then thoroughly review ML/DL methods for IoT security and present the opportunities, advantages and shortcomings of each method. We discuss the opportunities and challenges involved in applying ML/DL to IoT security. These opportunities and challenges can serve as potential future research directions.

I. INTRODUCTION

IoT’s scale, heterogeneity, constrained devices, and broad attack surfaces create security challenges that conventional defenses cannot fully address. This survey organizes IoT threats and reviews ML/DL methods as intelligence-based approaches for securing IoT systems.

  • IoT security context: IoT combines billions of heterogeneous devices and applications, creating a large, distributed, and vulnerable security surface.Its interconnected and multidisciplinary deployment introduces security challenges across devices, networks, cloud services, and applications.
  • IoT security context: Conventional encryption, authentication, access control, network, and application defenses are challenging and insufficient for large IoT systems with inherent vulnerabilities.The paper notes that attackers can develop new attacks to circumvent mechanisms designed for specified threats.
  • ML/DL motivation: ML/DL can learn normal and abnormal interaction patterns from IoT data to identify malicious behavior, including new or zero-day attacks.Monitoring and investigating inputs from IoT components supports early detection of malicious behavior.
  • Survey scope: The survey reviews IoT attack surfaces and threats, ML/DL algorithms, layer-specific applications, advantages, disadvantages, challenges, and future directions.Its taxonomy covers physical devices, network services, cloud services, web and application interfaces, and an additional surface arising from interdependent IoT environments.
  • Related work: Existing IoT-security surveys generally did not focus specifically on ML/DL applications, whereas this work compares recent ML/DL methods and their IoT-security uses.The paper positions its review as a practical guide for developing end-to-end, security-based intelligent approaches.

II. OVERVIEW OF THE IOT SYSTEM

IoT systems interconnect massive heterogeneous devices through diverse communication patterns and commonly use application, network, and perception layers. Resource constraints, lossy links, and large-scale deployment increase the difficulty of securing these systems.

  • IoT architecture: IoT is defined as the interconnection of massive heterogeneous devices and systems communicating through thing-to-thing, human-to-human, or human-to-thing patterns.The architecture is generally organized into application, network, and perception layers.
  • IoT architecture: The IoT architecture generally contains application, network, and perception layers.These layers are presented as the basis for organizing the system and its analysis.
  • Perception layer: The perception layer uses physical sensors and actuators to sense, collect, and possibly process information.Examples include temperature, humidity, motion, and acceleration sensors, with plug-and-play configuration needed for heterogeneous sensors.
  • Perception layer: IoT sensors are resource-constrained because they rely on limited battery capacity, computation, and storage in lossy and noisy communication environments.Deployment therefore requires low-power communication and routing protocols that account for limited sensor memory and mobility.

C. Middleware

IoT middleware abstracts communication and computational complexity so applications can use heterogeneous objects cooperatively. The broader IoT environment remains difficult to secure because diverse devices, layers, data, and attack vectors expand the system’s vulnerabilities.

  • Middleware: Middleware provides a software level between applications, operating systems, and network communication, enabling cooperative processing among heterogeneous IoT objects.It hides system and hardware complexity so developers can focus on the issue being solved.
  • Data and applications: IoT devices generate large data volumes that require real-time analysis to produce useful knowledge and support smart services.The paper describes ML as an analytical means for building intelligent IoT systems.
  • Data and applications: IoT applications use sensor data for functions including healthcare monitoring, agriculture automation, and smart-grid management.Examples include patient warnings, irrigation and disease monitoring, and real-time electricity management.
  • Security implications: IoT security must account for diverse application requirements, heterogeneous protocols and devices, constrained resources, lossy links, and autonomous device interactions.A method effective for one application or requirement may be unsuitable for another, while autonomous control requires end-to-end protection.
  • Security implications: IoT threats include physical access, eavesdropping, spoofing, Sybil attacks, man-in-the-middle attacks, malicious inputs, data tampering, and denial of service.Security properties discussed for addressing these threats include confidentiality, integrity, authentication, and authorisation.

A. Threats in IoT

IoT threats include passive information exposure, active manipulation and disruption, and physical access or damage. Their scale and diversity make attacks difficult to distinguish and contain.

  • Cyber threats: Passive threats eavesdrop on communication channels to collect information or track sensor holders.Personal health information is particularly valuable on black markets, reported at $50 versus $1.50 for credit-card information and $3 for a social-security number.
  • Cyber threats: Active threats modify IoT systems to change configurations, control communication, or deny services.Examples include impersonation, malicious inputs, data tampering, and denial-of-service attacks.
  • Cyber threats: Distributed denial-of-service attacks use multiple IP addresses, making malicious traffic harder to distinguish from normal device traffic.Compared with attacks involving huge traffic volumes or fewer devices, DDoS traffic can be more difficult to discriminate.
  • Physical threats: Physical threats can terminate services by affecting reachable IoT objects and may arise from attacker access or natural and human-caused disasters.Sensors and cameras are expected to be widely deployed and physically accessible.

B. Attack Surfaces

The survey organizes IoT attack surfaces into physical devices, network services, cloud services, and web or application interfaces, while also examining threats created by IoT environments.

  • Surface taxonomy: IoT attack surfaces comprise physical devices, network services, cloud services, and web and application interfaces.The survey also identifies threat surfaces introduced by the new IoT environment.
  • Physical Device Surface: Resource-constrained physical devices containing valuable information are vulnerable to tracking, denial of service, eavesdropping, spoofing, counterfeiting, and physical attacks.Physical devices are especially exposed because attackers can often access them directly.
  • Network Service Surface: Expanded IoT connectivity and mobility increase network-service exposure to hacking, interruption, spoofing, denial of service, man-in-the-middle attacks, tunnelling, and interception.Traditional TCP/IP connectivity also exposes IoT systems to viruses, intrusion, replay attacks, and identity theft.
  • Cloud Service Surface: Cloud integration creates privacy and confidentiality risks, while loopholes, client-code insertion, privilege misuse, and insider attacks can enable unauthorized operations.Authorized cloud users may misuse permissible access to gain unauthorized privileges and launch internal denial-of-service attacks.
  • IoT environments: Interdependent and interconnected IoT environments can expose sensitive information and allow one infected device to affect many others at large scale.The survey describes large-scale propagation as IoT going nuclear.

IV. REVIEW OF MACHINE LEARNING AND DEEP LEARNING APPLICATIONS IN IOT SECURITY

The survey reviews traditional machine-learning algorithms and deep-learning methods for IoT security, covering their learning paradigms, applications, advantages, and limitations. Reported studies include intrusion, malware, anomaly, attack, and privacy-related security applications.

  • Learning paradigms: Learning algorithms improve task performance through training from experience, including classification of system behaviour as normal or abnormal.The review distinguishes supervised, unsupervised, and reinforcement learning according to how training information is provided.
  • Traditional ML methods: The review covers traditional ML algorithms including decision trees, SVMs, Bayesian methods, KNN, random forests, association rules, ensembles, k-means, and PCA.It discusses each method’s advantages, disadvantages, and IoT-security applications.
  • Traditional ML methods: Decision trees classify samples through feature-based branching and have been used with fog-based systems to detect suspicious traffic and DDoS behaviour.Tree construction includes induction and inference, with samples assigned labels at leaves.
  • Traditional ML methods: SVMs divide data using a hyperplane and were reported to outperform naïve Bayes, random forest, and decision trees for Android malware detection.Another study found SVM, KNN, perceptron, ensemble learning, and sparse logistic regression effective for known and unknown smart-grid attacks.
  • Traditional ML methods: Random forests combine multiple decision trees for robust voting, but constructing several trees may be impractical for some real-time applications with large training datasets.The review also notes association-rule scalability and assumption limitations in IoT-security settings.
  • Applications and results: Reported applications include lightweight ensemble anomaly detection, intrusion and Sybil detection through clustering, and PCA-based classifiers designed for time- and computing-efficient real-time IoT use.The ensemble method outperformed each individual classifier, while PCA was combined with softmax regression and KNN.

B. Deep learning (DL) methods for IoT Security

DL methods learn hierarchical or complex representations and are reviewed for diverse IoT security tasks, including malware, anomaly, and malicious-traffic detection. Their advantages include automated feature learning and suitability for large datasets, but computational cost and training instability constrain deployment.

  • DL is suited to IoT systems that produce large datasets because it can automatically extract complex representations.
  • DL uses multiple non-linear processing layers to learn hierarchical representations for pattern analysis.
  • Convolutional neural networks (CNNs): CNNs reduce parameters through sparse interaction, parameter sharing, and equivariant representation, improving scalability and training-time complexity.
  • Convolutional neural networks (CNNs): CNNs automatically learn features from raw data, but their high computational cost challenges onboard security on resource-constrained devices.A distributed architecture can place a lightweight model on-device while completing full classification in the cloud.
  • Recurrent neural networks (RNNs): RNNs capture temporal dependencies in sequential inputs, supporting threat detection when malicious patterns depend on time.Their main drawback is vanishing or exploding gradients.
  • A discriminative RBM enabled semi-supervised network-anomaly detection with incomplete training data, but performance declined on a different network dataset.
  • GAN-based architectures showed effectiveness in detecting abnormal IoT system behaviour, while GAN training remains unstable and difficult.GANs may generate samples resembling zero-day attacks, but discrete-data generation is challenging.
  • Recurrent neural networks (RNNs): RNNs can classify network traffic with high accuracy for malicious-behaviour detection and show potential for time-series-based IoT threats.

C. Reinforcement learning (RL) methods for IoT security

Reinforcement learning trains agents to map situations to actions that maximise rewards. In IoT security, it has been applied to anti-jamming policies, including aggressive jamming environments.

  • RL learns a policy mapping situations to actions to achieve the highest rewards.
  • RL-based anti-jamming schemes learned sub-band selection policies using jammer and interference information.
  • RL was found promising for developing schemes against aggressive jamming in tactical mobile networking.

V. IOT SECURITY LAYERS BASED ON ML AND DL METHODS

The survey classifies ML and DL studies according to the IoT layers they protect. It notes that these methods may protect multiple layers or the end-to-end system.

  • The survey organises prior ML and DL studies by the IoT security layers they intend to protect.
  • ML and DL can protect more than one layer or the end-to-end IoT system.

A. Perception layer

Perception-layer applications include learning-based physical-layer and user authentication, as well as reinforcement-learning defenses against jamming. These approaches use wireless signals, behavioural features, or adaptive policies for constrained IoT environments.

  • Learning-based physical-layer authentication addresses the limited practicality of assumption-based techniques in dynamic networks.
  • A DNN used Wi-Fi channel-state information and daily activity distinctiveness to authenticate individuals without user participation.
  • RL was effective for developing a method against aggressive jamming in an IoT network.
  • Prior anti-jamming schemes used RL and Q-learning to learn policies that avoid jammer signals and interference.
  • Cognitive radio capability allows IoT devices to learn and change according to their dynamic environment.

B. Network layer

The network layer is reviewed as a major IoT attack surface, with ML/DL methods applied to intrusion, anomaly, malware, device, and attack-path detection. The surveyed studies show both promising detection capabilities and important dataset and generalisation constraints.

  • The network layer forms the largest IoT attack surface and carries data between perception-layer devices and storage functions.
  • Limitations: Discriminative RBM performance declined on network data differing from its training dataset, highlighting a generalisation limitation for anomaly detection.
  • Intrusion and attack detection: ANNs detected known and unknown DDoS attacks, with newer known-attack features improving detection probabilities for both attack types.
  • Intrusion and attack detection: DL models, including DBNs and autoencoders, improved malware or network-anomaly detection through automatic or latent feature learning.
  • Device and behaviour identification: ML methods identified IoT devices and unauthorised links, while profiling-based classifiers examined how partial sensed-data changes affect abnormal-behaviour detection.
  • Attack-path analysis: Network-security frameworks combined statistical attack-path analysis, visualisation, and model updates, but their integration with ML/DL remained an open research direction.

C. Application layer

The application layer includes ML/DL approaches for detecting Android malware and abnormal IoT-system behaviour. These studies emphasise automatic feature learning and DL-based behavioural classification, while the survey also summarises the broader study literature.

  • Android malware detection: DL models learned features from Android applications to detect unspecified Android malware accurately.
  • Android malware detection: CNN-based Android malware detection learned discriminative features from raw data while jointly performing feature learning and classification.
  • Behaviour detection: A GAN-integrated architecture classified IoT-system behaviour as normal or abnormal and showed effective DL-based abnormal-behaviour detection.
  • Study comparison: The surveyed application-layer studies are summarised in a comparison table covering ML and DL approaches for IoT security.

D. Enabling technology for ML/DL deployment for IoT security

ML/DL deployment for IoT security depends on data, software frameworks, and deployment strategies that balance device constraints, latency, computation, memory, and update requirements.

  • Data: IoT security deployment produces large volumes of behavioural data representing normal and attack modes for ML/DL systems.
  • Software frameworks: Dedicated ML/DL frameworks and libraries simplify implementation, support multiple languages, and use GPUs to optimise DL training.
  • Deployment strategies: Models can be deployed on-board, in the cloud, or at the edge, with the optimal strategy depending on resource, latency, detection, and update requirements.
  • Deployment trade-offs: Cloud or edge offloading reduces device computation and memory demands but may introduce latency that conflicts with real-time detection.
  • Deployment trade-offs: On-device deployment avoids communication-quality concerns but remains difficult because IoT devices have limited computation, memory, and power resources.
  • Technology tools: Figure 10 identifies technology tools intended to enable ML/DL deployment for IoT security.

VI. ISSUES, CHALLENGES AND FUTURE DIRECTIONS

The paper organises issues, challenges, and future directions for ML/DL-based IoT security across data, learning, environment, computational, integration, and trade-off considerations.

  • Future directions are classified by data, learning strategies, IoT environments, inherent ML/DL challenges, technology integration, computational complexity, and security trade-offs.

A. IoT data related issues

IoT security learning depends on realistic, diverse data, yet such datasets are difficult to obtain. The survey identifies augmentation, zero-day detection, lifelong learning, and transfer learning as opportunities for improving security intelligence.

  • Availability of security related datasets: High-quality, comprehensive, and diverse datasets are essential for training ML/DL models to recognize varied real-world IoT attacks.Training data should reflect nearly all attack strategies because they form the basis of model knowledge and can directly influence accuracy.
  • Availability of security related datasets: Crowdsourcing could generate richer IoT threat datasets for training and benchmarking newly proposed algorithms.The survey proposes datasets covering nearly all attack patterns to compare new algorithms with existing methods.
  • Augmentation of IoT security data: Data augmentation can expand limited IoT security datasets, but generated samples must preserve each class’s appropriate distribution.Developing suitable augmentation methods may improve learning-method classification accuracy, although domain knowledge is often required.
  • Zero-day attacks on IoT: ML/DL methods can detect evolving zero-day attacks and potentially predict new attacks that are derivatives or mutations of previously observed attacks.This capability supports moving IoT security beyond secure communication toward intelligent security systems.
  • Lifelong Learning for learning IoT threats: Lifelong learning addresses IoT dynamism, while transfer learning may reuse established attack-training samples across devices, wireless sensor networks, and cloud systems.Successful transfer across IoT elements may improve overall security performance with less effort.

C. ML and DL for IoT security in interdependent, interconnected and interactive environments

In interconnected IoT environments, ML/DL can analyze system-wide behavior and support early abnormality detection, but their use introduces cryptanalytic, privacy, and theoretical challenges. The survey also notes unresolved security issues in social IoT.

  • Interdependent and interconnected environments: ML/DL can extend security analysis from individual devices to the operational behavior of entire interconnected IoT systems.This system-level perspective matches environments where devices control or depend on one another.
  • Interdependent and interconnected environments: Because IoT infections can spread across densely connected devices, security must consider both attack surfaces and attack magnitude.An infected device may enable a destructive attack affecting many devices or a substantial part of a city.
  • Interdependent and interconnected environments: ML/DL can detect abnormal behavior in individual devices or groups and automatically respond early, potentially reducing attack impact and informing prevention.The proposed strategy uses understanding of current causes to support learning about similar future attacks.
  • Interactive environments: Securing social IoT requires instructions for selecting appropriate object relationships because these choices affect service outputs and sensitive-information disclosure.The survey describes ML/DL as a potential contributor, but this research direction remains at an early stage.
  • Possible misuse of ML and DL algorithms by attackers: ML/DL can be misused against cryptographic implementations: SVMs outperformed template attacks, while CNN and AE algorithms outperformed SVM, RF, and template attacks.These results show that learning methods can threaten security as well as defend IoT systems.
  • Privacy of ML and DL: DL systems face privacy risks because federated, distributed, and decentralized approaches can be broken, while model interfaces can enable sensitive-data extraction.The survey also describes attacks using GAN-generated samples and model inversion.
  • Insights into DL architecture: The lack of a theory explaining how DNN architecture determines behavior limits understanding of required data quantities, layer counts, and resource reduction.The survey identifies architectural theory as important for interpreting and designing DL systems.

E. Integrating DL/ML with Other Technology for IoT

Integrating ML/DL with edge computing and blockchain can support more responsive, scalable, and data-informed IoT security. However, resource constraints and application-specific security trade-offs remain central design challenges.

  • Edge computing: Edge deployment of ML/DL can minimise delays, enable near-real-time detection, improve energy efficiency, and enhance scalability for lightweight IoT objects.
  • Blockchain: Blockchain provides a decentralised ledger whose distributed authentication model aligns with the distributed nature of IoT systems.
  • Synergic integration: ML/DL can improve blockchain’s decision-making and data evaluation, while blockchain can provide distributed data that supports accurate and generalisable ML/DL models.
  • Computational complexity: Limited memory, computation, and energy constrain on-device ML/DL, while cloud offloading depends on wireless energy costs and network connectivity.
  • Computational complexity: Future work should improve GPUs, offloading strategies, and computationally efficient frameworks to support real-time IoT security detection and protection.
  • Security trade-offs: ML/DL-based security must balance application-specific trade-offs, such as device security and emergency accessibility in healthcare systems.
Loading 1807.11023v1…