Security, Privacy and Accountability in AI-Driven IoT Systems
Principal lecturers: Prof Richard Mortier, Dr Vadim Safronov
Taken by: MPhil ACS, Part III
Code: R267
Term: Michaelmas
Hours: 16 (8 x 2hrs reading group sessions)
Class limit: max. 12 students
Prerequisites: Undergraduate courses (or equivalent) in Computer Networking/Systems and Cyber Security, familiarity with the main concepts of Machine Learning and Deep Learning.
timetable
Aims
This module examines the security, privacy and accountability challenges that arise as AI becomes increasingly integrated into IoT and cyber-physical systems. AI plays a dual role: it provides powerful tools for operating and protecting these systems while also introducing new vulnerabilities and expanding the attack surface. Each week centres on the critical reading and discussion of research papers, engaging students with key challenges in the field.
Objectives
- Critically evaluate primary research on security, privacy and accountability challenges in modern AI-driven IoT systems.
- Identify open research problems and formulate well-grounded research directions.
- Present and debate research ideas and complex trade-offs in written and oral form.
Syllabus
The module is delivered through seminar-style sessions organised around the following themes:
- IoT Threat Landscape
- AI-Enabled Threats
- IoT and Network Security
- IoT Privacy
- Transparency and Accountability
- Generative and Agentic AI for IoT
Sessions are based on the critical reading, presentation and discussion of research papers from leading security, IoT, networking, and systems venues, with an emphasis on critical analysis and open challenges.
Assessment
Assessment runs during weeks 2–8 and comprises:
- Weekly paper review: 80%
- Individual presentations: 10%
- Group presentations: 10%
Students submit a 1,000–1,200-word TPC-style review of one paper each week. In any week in which a student is assigned an individual presentation, the presentation replaces the written review.
Individual presentations follow a conference-style format. Students are assigned a paper and a presentation perspective, such as critical, neutral or supportive, in advance. Where a student gives multiple presentations, the final mark is the average of the marks awarded.
The group presentation takes the form of an in-session discussion of the weekly papers, in which students are assessed on their active and thoughtful engagement.
Recommended Reading
Keshav, S. (2007). How to Read a Paper. ACM SIGCOMM Computer Communication Review, 37(3), 83–84. https://dl.acm.org/doi/10.1145/1273445.1273458
Roscoe, T. (2007). Writing Reviews for Systems Conferences. ETH Zürich. https://people.inf.ethz.ch/troscoe/pubs/review-writing.pdf
Antonakakis et al. (2017). Understanding the Mirai Botnet. Proceedings of the 26th USENIX Security Symposium (USENIX Security '17), 1093–1110 https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/antonakakis
Ren et al. (2019). Information Exposure From Consumer IoT Devices. ACM IMC. https://dl.acm.org/doi/10.1145/3355369.3355577
Alrawi et al. (2019). SoK: Security Evaluation of Home-Based IoT Deployments. IEEE Symposium on Security and Privacy (SP), 1362–1380. https://ieeexplore.ieee.org/document/8835392