Source-linked AI summary

A Survey on Intelligent Internet of Things: Applications, Security, Privacy, and Future Directions

Ons Aouedi, Thai-Hoc Vu, Alessio Sacco, Dinh C. Nguyen, Kandaraj Piamrat, Guido Marchetto, Quoc-Viet Pham

arXiv:2406.03820v2cs.NIcs.AIcs.CRcs.ETcs.LG

TL;DR

IIoT research requires a comprehensive account of how AI-enabled IoT systems address applications, security, and privacy. This survey synthesizes IIoT applications and learning-based approaches, examines security and privacy threats, and identifies challenges and future directions. Its supported conclusion is that IIoT requires continued work on efficient privacy preservation, secure communications, model protection, and multidisciplinary research.

  • Problem

    IIoT systems process sensitive data through continuous device and cloud communication, creating challenges for privacy, confidentiality, integrity, and protection against adversarial attacks.

  • Method

    The paper conducts a comprehensive survey of IIoT applications, AI and learning techniques, security issues, privacy threats, countermeasures, and future challenges.

  • Results

    The survey covers smart healthcare, smart grids, transportation, and industry, and analyzes security issues plus data, location, and model privacy leakage.

  • Takeaways & Limitations

    The paper concludes that IIoT research should develop efficient privacy preservation, secure communication channels, and protections for AI models through multidisciplinary approaches.

Abstract

from arXiv · show

The rapid advances in the Internet of Things (IoT) have promoted a revolution in communication technology and offered various customer services. Artificial intelligence (AI) techniques have been exploited to facilitate IoT operations and maximize their potential in modern application scenarios. In particular, the convergence of IoT and AI has led to a new networking paradigm called Intelligent IoT (IIoT), which has the potential to significantly transform businesses and industrial domains. This paper presents a comprehensive survey of IIoT by investigating its significant applications in mobile networks, as well as its associated security and privacy issues. Specifically, we explore and discuss the roles of IIoT in a wide range of key application domains, from smart healthcare and smart cities to smart transportation and smart industries. Through such extensive discussions, we investigate important security issues in IIoT networks, where network attacks, confidentiality, integrity, and intrusion are analyzed, along with a discussion of potential countermeasures. Privacy issues in IIoT networks were also surveyed and discussed, including data, location, and model privacy leakage. Finally, we outline several key challenges and highlight potential research directions in this important area.

I. INTRODUCTION

The paper introduces Intelligent IoT (IIoT) as the integration of AI and ML across the IoT data lifecycle, then surveys its applications, security, privacy, and research challenges. It covers domains including healthcare, cities, transportation, and industry, alongside major learning paradigms and the survey’s organization.

  • IIoT integrates AI and ML across IoT data generation, collection, processing, and utilization, supporting applications such as healthcare, transportation, and smart industries.
  • A. State-of-the-Art and Our Contributions: The survey addresses a literature gap by reviewing ML, DL, FL, and DRL for IIoT security and privacy concerns.
  • A. State-of-the-Art and Our Contributions: It surveys IIoT applications across smart healthcare, smart cities, smart transportation, and smart industry.
  • A. State-of-the-Art and Our Contributions: Its security discussion covers network attacks, confidentiality, integrity, and intrusion, including potential countermeasures.
  • A. State-of-the-Art and Our Contributions: Its privacy discussion focuses on data, location, and model privacy leakage in IIoT networks and applications.
  • A. Machine/Deep Learning-based IIoT: The survey introduces supervised, unsupervised, semi-supervised, and reinforcement learning, and describes deep-learning architectures including CNNs, RNNs, and autoencoders.

B. Reinforcement Learning-based IIoT

IIoT applies learning-based methods to enable adaptive decisions, cooperative devices, and privacy-preserving distributed training across IoT networks.

  • Reinforcement Learning: Reinforcement learning enables agents to make sequential decisions by interacting with dynamic environments and maximizing cumulative reward.Agents explore to gather information, receive rewards or penalties, and update their knowledge to improve action selection.
  • Reinforcement Learning: In dynamic IoT networks, reinforcement-learning agents can adapt to changes and cooperate in multi-agent systems to perform tasks more efficiently.The framework supports devices learning and working together toward common goals.
  • Federated Learning: Federated learning trains shared models across distributed devices while keeping training data at their points of origin instead of sending it directly to third parties.Training is delegated to the network edge, supporting cooperative learning with potential network-resource and privacy benefits.
  • Federated Learning: Federated learning includes Horizontal FL, Vertical FL, and Federated Transfer Learning, distinguished by how client sample and feature spaces are distributed.Examples include intrusion detection with HFL, smart-city loan prediction with VFL, and disease detection through cross-country hospital cooperation with FTL.
  • IIoT Foundations: IIoT combines ML, DL, RL, FL, analytics, cloud, and edge computing so connected devices can learn from collected data and make decisions.IoT devices include sensors, smartphones, computers, and RFID devices, while security and privacy remain critical concerns for sensitive data and communications.

III. IIOT APPLICATIONS

IIoT applications span smart healthcare, COVID-19 detection, and smart-grid energy management, using AI, deep learning, and federated learning to address monitoring, privacy, personalization, and resource constraints.

  • IIoT applications include smart healthcare, smart cities, smart transportation, and smart industries, with AI techniques applied across representative use cases.
  • 1) Ambient Assisted Living (AAL):: CNN, CNN-LSTM, and federated-learning approaches support ambient-assisted living and human-activity recognition, balancing feature extraction, temporal modeling, personalization, and computational cost.DeepConvLSTM improves F1 score over a CNN baseline on OPPORTUNITY, while CondConv improves performance without compromising inference speed.
  • 1) Ambient Assisted Living (AAL):: Healthcare federated learning addresses sensitive data, labeling difficulty, non-IID data, and straggler clients through semi-supervised training, personalization, and resource-aware client selection.FedPARL uses model pruning, resource-aware selection, and adaptive local epochs for constrained IoT devices.
  • 2) COVID-19 Detection:: Transfer learning and federated learning are used for COVID-19 detection from small or institution-local medical datasets, with federated architectures exchanging model parameters rather than sensitive images.The reviewed approaches include CT and X-ray analysis and privacy-preserving communication among medical institutions.
  • 1) IIoT for Smart Grids:: Smart-grid research applies machine learning to energy management and stability prediction, including GPR-based management and multidirectional LSTM models.The MLSTM approach is reported to outperform conventional ML methods in performance.

2) IIoT for Underwater:

IIoT supports underwater and water-management applications alongside intelligent transportation, where learning methods address water quality, traffic prediction, traffic-sign recognition, and electric-vehicle energy demand.

  • 2) IIoT for Underwater:: Smart water management covers wastewater management, irrigation, rainwater harvesting, water reuse, and sustainable sourcing from natural resources.
  • 2) IIoT for Underwater:: A BiLSTM model predicts water quality from six years of monthly Yamuna River data while also imputing missing values.
  • IIoT-based transportation systems process sensor data for real-time decisions, including autonomous traffic-sign recognition and electric-vehicle charging support.
  • 1) Autonomous and Electric Vehicles:: FedSNN addresses traffic-sign data privacy and limited computing resources, while lightweight student models reduce redundant parameters with comparable accuracy.
  • 1) Autonomous and Electric Vehicles:: Electric-vehicle studies use prediction and reinforcement-learning methods to forecast charging demand and reduce long-term charging costs.A charging-demand system was tested on real Dundee City charging-station data collected between 2017 and 2018.
  • Machine-learning traffic prediction models handle high-dimensional nonlinear relationships more effectively than classical statistical approaches for complex traffic data.Deep learning combines recurrent models with CNNs or graph neural networks to capture spatial and temporal traffic features.

D. IIoT-based Smart Industry

IIoT supports Industry 5.0 by combining AI-enabled industrial systems with human–machine collaboration, while enabling learning-based robotics, resource allocation, privacy, and edge collaboration.

  • Industry 5.0: Industry 5.0 emphasizes collaboration between humans and machines, treating machines as partners rather than replacements for human labor.
  • Industry 5.0: IIoT supports Industry 5.0 through communication and interaction among machines and devices, enabling more intelligent industrial systems.
  • AI in Industry 5.0: Deep learning has been investigated for Industry 5.0 applications including predictive maintenance, quality control, system optimization, and automated decision-making.
  • Learning-based industrial systems: Multi-agent reinforcement learning and Deep Federated Q-Learning support cooperative caching, workload offloading, and slice-based resource allocation in industrial networks.
  • Learning-based industrial systems: Federated learning and blockchain are combined to address privacy, productivity, and poisoning-attack concerns in industrial IoT networks.
  • Robotics: Fog and edge computing provide computational, network, and storage resources for robots to share information, collaborate, and learn tasks collectively.

4) IIoT for Smart Industry:

Smart-industry IIoT combines AI with industrial automation, but its connected and heterogeneous architecture creates exposure to network and learning-system attacks requiring layered defenses.

  • IIoT for Smart Industry: AI in Industry 5.0 enhances human–machine interaction while supporting real-time decisions, predictive maintenance, and production-process optimization.
  • Security risks: IIoT networks face security risks because many connected devices and weak security standards can leave systems open to unauthorized attacks.
  • Security risks: Common network attacks include denial-of-service, poisoning, adversarial, and membership-inference attacks.
  • Denial-of-service attacks: Denial-of-service attacks flood devices or network layers with malicious traffic, disrupting operations and exhausting constrained resources.
  • Learning-system attacks: Poisoning attacks inject malicious or noisy data into learning systems, degrading model performance or producing harmful outputs.
  • Countermeasures: Network monitoring, anomaly detection, and learning-based IDS or IPS can identify anomalous or malicious traffic patterns.
  • Learning-system attacks: IIoT’s heterogeneous architectures and multiple devices or targets increase its vulnerability to poisoning attacks.

3) Adversarial Attacks:

Adversarial and membership-inference attacks threaten IIoT by manipulating model behavior, compromising connected devices and data, and revealing training-set membership.

  • Adversarial attacks: Adversarial attacks modify inputs to induce incorrect or undesirable model outputs during inference or testing.
  • Adversarial attacks: Adversarial attacks may be non-targeted or targeted and can operate with white-box, grey-box, or black-box model knowledge.
  • Adversarial attacks: Adversarial attacks can compromise the confidentiality and integrity of data processed by intelligent networks.
  • Adversarial attacks: Adversarial attacks can impersonate or hijack devices, disrupt network functions, and cause physical harm to vehicles, drones, or robots.
  • Countermeasures: Adversarial training and defensive distillation are proposed to increase model resistance to adversarial inputs.
  • Membership-inference attacks: Membership-inference attacks infer whether a user’s data appeared in a model’s training set, using model outputs, training information, or statistical analysis.
  • Membership-inference attacks: Membership inference can cause privacy violations, sensitive-information leakage, manipulated decisions, and reduced trust in smart applications.

5) Attack Measurements:

IIoT security evaluation and protection must address network properties, confidentiality, authentication, and resource constraints across heterogeneous deployments.

  • Attack measurements: Security evaluation can combine impact analysis, requirements engineering, security testing, and standards or certification schemes.
  • Confidentiality: Confidentiality restricts IIoT data and information to authorized users and systems through cryptography, access control, and information-flow tracking.
  • Cryptography: Cryptography protects data during transmission or storage, but decrypted data and resource limitations remain challenges for IoT devices.
  • Cryptography: Homomorphic encryption enables computation on encrypted data without decryption, but real-time response remains challenging in IoT networks.
  • Cryptography: Encrypted data aggregation can combine differential privacy and homomorphic encryption with distributed learning models.
  • Access control: Access control limits data access to authorized entities but cannot govern how data are used or propagated afterward.
  • Access control: IIoT authentication mechanisms address factors, tokens, processes, architectures, and tiers to manage device identities securely and scalably.
  • Access control: Authentication must account for perception, communication, and application tiers, including threats such as tag cloning, eavesdropping, and RF jamming.

C. Integrity

IIoT integrity spans trustworthy data collection, transmission, storage, and intrusion protection. The survey reviews integrity threats from wireless errors, device failures, tampering, and attacks, alongside learning-based detection, auditing, and prevention approaches.

  • Data Integrity: Integrity requires maintaining the accuracy and completeness of IoT data despite transmission errors, erasures, attenuation, distortion, noise, and storage problems.These conditions make integrity an open challenge in wireless IoT applications.
  • Data Integrity: Wearable sensors support health monitoring, but their broad deployment complicates intelligent learning and data-integrity assurance.Automated systems therefore examine data-impact anomalies and classify potential integrity problems.
  • Data Integrity: Smart-home device coexistence creates integrity concerns, while multistep security algorithms can increase device power consumption.The cited response uses symmetric cryptography with BAN logic and the Scyther tool.
  • Data Integrity: Cloud integrity protection addresses hardware failures, software corruption, malicious intrusions, key leakage, and tampered-file replacement through signatures, replication, and multicopy auditing.A provable multicopy scheme simplifies authentication using two hash operations and indistinguishable obfuscation.
  • Intrusion Detection: Intrusion can compromise IIoT confidentiality, integrity, and availability, motivating IDS deployments across hosts, networks, protocols, applications, and hybrid locations.Signature-based IDSs detect known patterns, whereas anomaly-based systems can identify unknown attacks but produce more false positives.
  • Intrusion Detection and Prevention: Learning-based intrusion systems report strong detection results, including FL-based RL accuracy of 0.985 and detection rate of 96.5%, while hybrid IPS results reach 99.99% accuracy.Other reported outcomes include BoT-IoT binary accuracy of 99.75 and five-dataset subset-testing accuracy of 100%.

E. Countermeasures

IIoT countermeasures combine encryption, learning-based protection, decentralized training, and secure on-device inference to address security, privacy, reliability, and resource constraints.

  • IIoT security challenges include data breaches, identity theft, unauthorized access, and attacks against confidential information.
  • DRL can identify energy-efficient, fault-tolerant WSN routes before AES-based encryption produces cipher blocks.
  • Lightweight cryptography is needed because symmetric solutions remain resource-intensive for constrained IoT devices.
  • DL-protected aggregation can use enrollment, challenges, PUF-generated keys, timestamp checks, and aggregation without maintaining a shared secret key.
  • Practical DL approaches remain limited by interpretability, data requirements, parameter tuning, and computational complexity.
  • Secure IIoT learning frameworks combine federated learning for unreliable agents with intrusion detection or prevention strategies.
  • On-device AI reduces cloud transmission and communication latency but requires model-privacy protection when using untrusted accelerators.

V. PRIVACY ISSUES IN IIOT

Privacy in IIoT concerns information exposed through devices, communications, data processing, and machine-learning models. The survey organizes privacy principles, threats, applications, and protection challenges across diverse deployments.

  • IIoT privacy spans sensor payloads, contextual information such as location, and machine-learning model parameters during collection, transmission, analysis, and training.
  • Privacy in IIoT primarily concerns exposure of information from smart objects and requires regulation of personal-information use and distribution.
  • Privacy-by-design incorporates privacy into defaults, organizational priorities, objectives, design processes, and operational planning.
  • Key privacy principles include data minimization, informed consent, transparency, preventive protection, accuracy, and consent withdrawal.
  • Privacy-by-design does not guarantee absolute protection, and omitting it leaves IIoT vulnerable to eavesdropping, spoofing, and RF jamming.
  • Common IIoT privacy threats include identification, location tracking, profiling, interaction exposure, retained data after ownership transfer, inventory attacks, and linking connections.
  • Privacy protection must address diverse applications including patient monitoring, energy control, traffic control, parking, inventory management, and data streams.
  • Transmission can expose personal information by linking identities to specific objects, creating risks involving tracking, localization, and personalization.

2) Smart Grid:

IIoT location privacy risks arise from sensitive smart-grid, UAV, wireless-sensor, and mobile-network data, while proposed defenses combine routing, traffic obfuscation, cryptography, and distributed learning.

  • Smart Grid: Detailed smart-grid consumption data can reveal users’ habits and behaviors when intercepted or misused.
  • UAV Privacy: UAV images may expose GPS coordinates and shooting times through header metadata, even after visual modifications.Compression can remove most header information, suggesting one privacy-preserving approach.
  • IIoT Challenges: IIoT applications must address scalability, distributed processing, real-time analytics, and privacy during real-time learning.
  • Data-Source Location Privacy: The Panda Hunter Game models adversaries inferring a data source’s location by analyzing multihop wireless traffic without decrypting payloads.The same problem applies to monitoring patients, doctors, and friendly soldiers in other IIoT settings.
  • Countermeasures: Location privacy defenses include flooding, random walks, dummy injection, cross-layer routing, and limited node detectability.Federated learning instead keeps user-related information locally and shares model-related information, preserving privacy to a certain degree.

2) Location Privacy of Base Station:

Base-station location privacy is threatened by traffic asymmetry and timing patterns in multihop WSNs, while defenses obscure payloads, routing relationships, transmission rates, and traffic patterns.

  • Local Adversaries: Local adversaries can infer parent-child relationships from forwarding delays and trace transmissions toward the base station.Payload confidentiality addresses location information in transmitted content, but not traffic-derived topology clues.
  • Defensive Mechanisms: Defenses include hop-by-hop re-encryption, multiple parents, random-walk routing, and randomized sending times.
  • Resilience: A multiple-base-station scheme preserves data collection after one base station is compromised but does not protect the base stations themselves.It delays, rather than prevents, local-adversary identification of base-station locations.
  • Global Adversaries: Techniques effective against local adversaries are ineffective against a global adversary monitoring all WSN traffic.
  • Threat Model: Nodes near the base station forward distant nodes’ data, creating traffic patterns that can reveal and compromise the base station.An attacker may also manipulate the sink node and disrupt WSN operation.
  • Traffic Obfuscation: Equalizing sensor transmission rates by delaying actual data can hide asymmetric traffic patterns.

D. Model Privacy Leakage

Model privacy leakage accompanies the large, sensitive datasets needed for IIoT machine learning, motivating privacy-preserving approaches spanning anonymization, differential privacy, cryptography, federated learning, and synthetic data.

  • Privacy Risks: Large IIoT training datasets create risks of sensitive-information leakage, while regulations increasingly restrict privacy-sensitive data access and use.Trained models may also be vulnerable to adversarial attacks.
  • Limitations: Anonymization does not guarantee protection against re-identification, and future work remains necessary for rich IIoT data such as gaze maps and temporal eye movements.
  • Protection Strategies: IIoT privacy-preservation methods include clustering, differential privacy, lightweight cryptography, secure multiparty computation, and machine-learning methods.
  • Anonymization: k-anonymity requires each person’s information to be indistinguishable from at least k −1 others in the dataset.Identifiers, non-identifiers, and quasi-identifiers receive different treatment in the dataset.
  • Differential Privacy: Differential privacy provides theoretical protection by limiting detectable differences between randomized outputs on adjacent datasets.Rényi differential privacy tracks cumulative privacy loss across multiple mechanisms.
  • Differential Privacy: Differential privacy supports IIoT applications such as smart-city services and fog-based recommendations while preserving statistical features.
  • Federated Learning: Privacy-preserving federated-learning aggregation can conceal user models through secret sharing and reduce local training overhead by cloud offloading.PRCL adds Gaussian noise, uses homomorphic encryption, and achieves precision comparable to state-of-the-art techniques.

4) Secure Multi-party Computation:

Secure multiparty computation protects confidential inputs and outputs in distributed learning, but its computation and communication costs motivate hybrid, partial, and hierarchical designs.

  • SMPC Foundations: Secure multiparty computation lets distributed parties jointly compute arbitrary functions without disclosing confidential inputs or outputs.
  • Challenges: Generic SMPC protocols remain computationally intensive, limiting practical deployment despite their privacy capabilities.
  • SMPC and FL: SMPC differs from federated learning: SMPC distributes computation across parties, whereas federated learning sends local model updates to a central server.
  • Two-Party Privacy: In a two-party setting, SMPC can protect both a user’s private data and a provider’s trained model.After execution, the provider learns nothing about the user’s data, while the user learns as little as possible about the model.
  • Hybrid Cryptography: Gazelle selects homomorphic encryption or SMPC according to computation and communication tradeoffs.Homomorphic encryption has high computation and low communication, whereas SMPC has low computation and high communication.
  • Scalability: A two-phase SMPC-enabled federated-learning framework elects aggregation committees to reduce secret-share exchanges and communication overhead.
  • ML-Based Methods: Machine-learning privacy defenses include risk assessment, personal privacy management assistants, and private data release.These methods evaluate data streams, manage preferences and policies, or publish privacy-guaranteed datasets.

F. Lessons Learned

IIoT privacy protection remains incomplete because many attacks are possible, while future systems must balance security, resource constraints, scalability, and model efficiency. Lightweight learning is needed because larger and more complex models can improve performance but increase computational, memory, transmission, and energy costs.

  • Lessons Learned: Many attacks remain possible in IIoT applications, and federated learning alone is considered unsatisfactory for preserving data privacy.Proposed protections include differential privacy, secure multiparty computation, artificial datasets, and ML-assisted defenses for models and data.
  • Lessons Learned: IIoT development faces security and privacy problems alongside resource-management, fairness, economic, and future-network challenges.These challenges span current deployments and the convergence of future IIoT networks with machine-learning models.
  • Resource Management: Heterogeneous, scalable, and dynamic IoT deployments require standardized resource management, scalable integrated learning frameworks, and solutions that adapt as devices join or leave.Limited device resources also constrain on-device classification, detection, encryption, and training through synchronization delays and power consumption.
  • Learning Model Design: Lightweight learning models must jointly consider model size, model complexity, and model accuracy.Size affects memory, transmission cost, and energy use; complexity affects computation; accuracy determines task performance and usability.
  • Learning Model Design: Increasing model size or algorithmic complexity can improve speed or accuracy but raises computational costs, and no universal lightweight-model standard yet exists.Quantization, pruning, compression, distillation, and hyperparameter tuning are identified as possible reduction techniques.

C. Fairness in IIoT

Fairness in IIoT concerns equitable resource allocation, balanced learning data, and unequal participation in blockchain-based processes. The paper connects these issues to heterogeneous deployments, data imbalance, limited device capabilities, privacy, security, and evolving network environments.

  • Economic Issues: IIoT fairness also includes data-market fairness, infrastructure and security costs, data ownership and privacy, and standards and interoperability.Centralized data-intensive applications may lack marketing fairness for IoT data sellers and third-party buyers.
  • Resource Allocation: Fair allocation of computing, storage, energy, bandwidth, and other communication resources is difficult because infrastructure, protocols, goals, restrictions, and policies differ.Potential responses include edge-distributed decision-making with federated learning and decentralized blockchain technology.
  • Learning Process: Inefficient or imbalanced IoT data can produce uncertain predictions, faulty decisions, or bias, including misdiagnosis from gender-imbalanced e-health datasets.Suggested responses include augmentation, weighting, transfer learning, and fairness metrics such as equal opportunity or disparate impact.
  • Blockchain Fairness: Blockchain consensus can create fairness disparities because IoT nodes often have less computing power than edge or cloud nodes and may face selfish-mining attacks.Transaction-ordering fairness can be assessed using FruitChain characteristics, probability analysis, and Euclidean-distance measures.
  • Future Networks: Future IIoT networks require continued investigation in 6G and integration with emerging technologies and computing paradigms amid privacy and security concerns around biometric, location, and environmental data.Concept drift makes IIoT data streams unpredictable, motivating online, ensemble, and adaptive learning methods.
  • Resource Management: Resource-management challenges include heterogeneous systems, scalable learning frameworks, dynamic device membership, and limited device capacity.Listed approaches include lightweight protocols, FedLab, token-based authentication, cooperative learning, blockchain, and lightweight cryptographic learning models.

VII. CONCLUSION

The paper surveys the convergence of IoT and AI through IIoT applications, security, privacy, challenges, and potential solutions. It covers major application domains, analyzes security and privacy leakage, and identifies research directions.

  • VII. CONCLUSION: The survey investigates IIoT applications, security issues, privacy concerns, lessons learned, and future research challenges.Applications include smart healthcare, smart grid, smart transportation, and smart industry; privacy coverage includes data, location, and model leakage.
Loading 2406.03820v2…