Security, Privacy and Accountability in AI-Driven IoT Systems
Principal lecturers: Prof Richard Mortier, Dr Vadim Safronov
Taken by: MPhil ACS, Part III
Code: R267
Term: Michaelmas
Hours: 16 (8 x 2hrs reading group sessions)
Class limit: max. 12 students
Prerequisites: Undergraduate courses (or equivalent) in Computer Networking/Systems and Cyber Security, familiarity with the main concepts of Machine Learning and Deep Learning.
timetable
Aims
This module examines the security, privacy and accountability challenges that arise as AI becomes ubiquitous across IoT and cyber-physical systems. AI plays a dual role throughout: it offers powerful tools for protecting resource-constrained IoT deployments, enabling smarter and faster threat detection, and privacy-preserving decentralised learning; yet it simultaneously introduces new vulnerabilities and expands the attack surface. The resource constraints inherent to IoT/CPS networked systems such as limited compute and communication capacity, shape both sides of this tension, restricting where and how AI can be deployed, making secure, accountable and privacy-preserving design significantly harder. Each week is centred on critical reading and discussion of research papers, engaging students with state-of-the-art work in the field.
Objectives
Analyse the security, privacy, and accountability threat models of wireless IoT and AI-enabled IoT systems; Critically evaluate primary research from top-tier venues, assessing threat models, empirical methodology, validity of results and limitations of proposed approaches; Assess AI-based security and privacy mechanisms for constrained IoT/CPS environments, distinguishing between AI applied externally to IoT systems and AI deployed on or across IoT devices, and evaluate the associated trade-offs and risks of each; Identify open research problems at the intersection of AI, IoT/CPS networked systems security, and articulate well-formed research directions in both written and oral form; Presenting and debating research ideas and complex tradeoffs.
Syllabus
Week 1: The IoT Threat Landscape (Intro lecture, led by the instructor): Overview of network security, privacy and accountability threat vectors across wireless smart environments and resource-limited IoT/CPS technologies. Antonakakis et al. (2017). Understanding the Mirai Botnet. Proceedings of the 26th USENIX Security Symposium (USENIX Security '17), 1093–1110. Alrawi et al. (2019). SoK: Security Evaluation of Home-Based IoT Deployments. IEEE Symposium on Security and Privacy (SP), 1362–1380. Ren et al. (2019). Information Exposure From Consumer IoT Devices. ACM IMC.
Week 2: Towards AI-driven IoT: AI Amplifies Every Threat Vector: How embedding AI in constrained wireless IoT systems expands the attack surface across all three threat dimensions (i.e. across network security, privacy and accountability). Arp et al. (2022). Dos and Don’ts of Machine Learning in Computer Security. USENIX Security. Melis et al. (2019). Exploiting Unintended Feature Leakage in Collaborative Learning. IEEE S&P.
Week 3: Network Security I: AI-based Threat Detection and Its Limits How ML/AI-driven intrusion detection can be deployed efficiently on constrained edge devices; who enforces policy when devices lack the resources to do so themselves; and whether detection remains effective as the network evolves over time. Mirsky et al., "Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection," NDSS 2018 Fu, Zeng, Du, "HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart Homes", USENIX Security 2021
Week 4: Network Security II: AI-based Fingerprinting, Traffic Classification, and Access Control How AI-driven traffic analysis identifies and monitors diverse IoT devices at scale; the dual-use nature of encrypted wireless traffic fingerprinting as both a security tool and a privacy threat; and how access control failures in AIoT infrastructure expose devices across deployment contexts. Trimananda et al. (2020). Packet-Level Signatures for Smart Home Devices. NDSS. Wang et al. (2021). MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging Protocols. USENIX Security.
Week 5: Privacy I: What Wireless Traffic Reveals: Constrained wireless IoT devices produce predictable traffic patterns they cannot normalise themselves; techniques on how AI enables both traffic inference attacks and privacy-preserving mechanisms deployed at the network or gateway layer. Sharma et al. (2022). Lumos: Identifying and Localizing Diverse Hidden IoT Devices in an Unfamiliar Environment. USENIX Security. Apthorpe et al. (2019). Keeping the Smart Home Private with Smart(er) IoT Traffic Shaping. PoPETS.
Week 6: Privacy II: Decentralised Learning and Its Limits Keeping raw data on devices and sharing only model updates is the canonical privacy-preserving approach for on-device AI for decentralised learning. Exploring whether that holds under adversarial conditions, and why architectures natural for wireless IoT mesh deployments can be more vulnerable than centralised alternatives. Shejwalkar & Houmansadr (2021). Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning. NDSS. Pasquini et al. (2023). On the (In)security of Peer-to-Peer Decentralized Machine Learning. IEEE S&P.
Week 7: IoT Transparency and Accountability: Accountability in IoT systems across three layers: the network behaviour devices expose, the software components present in device firmware and associated supply chain risks, and the provenance and integrity of AI models running on constrained hardware. Wang et al. (2018). Fear and Logging in the Internet of Things. NDSS. Nan et al. (2023). Are You Spying on Me? Large-Scale Analysis on IoT Data Exposure through Companion Apps. USENIX Security.
Week 8: Generative and Agentic AI Over IoT: Language model-powered agents integrate into IoT and cyber-physical systems as reasoning and control layers, introducing security, privacy and architectural risks.
Recommended Reading
Keshav, S. (2007). How to Read a Paper. ACM SIGCOMM Computer Communication Review, 37(3), 83–84. https://dl.acm.org/doi/10.1145/1273445.1273458;
Roscoe, T. (2007). Writing Reviews for Systems Conferences. ETH Zürich. https://people.inf.ethz.ch/troscoe/pubs/review-writing.pdf;
Week 1 materials to read before the introductory session: Antonakakis et al. (2017). Understanding the Mirai Botnet. USENIX Security. https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/antonakakis; Alrawi et al. (2019). SoK: Security Evaluation of Home-Based IoT Deployments. IEEE S&P. https://ieeexplore.ieee.org/document/8835392; Ren et al. (2019). Information Exposure From Consumer IoT Devices. ACM IMC. https://dl.acm.org/doi/10.1145/3355369.3355577
Assessment
Assessment runs during weeks 2–8 and consists of:
- An essay reviewing one paper per week (10% each, 7 weeks)
- Individual presentations throughout the course (15%)
- Group presentations throughout the course (15%)
Each essay will be approximately 1000–1200 words and structured as a TPC-style review of a student-selected paper from that week, following a provided template. The review will comment on the paper’s strengths and weaknesses, problem motivation, solution, methodology, and evaluation. At the end of the review, students will also be asked to connect ideas discussed across the papers and identify open research questions and challenges spanning all papers covered during that week.
Individual presentations will consist of a 15-min presentation plus 5-min Q&A about one paper from the session. Students will be assigned both the paper they will present and the nature of their presentation (e.g. critical, neutral, advocate). For those students selected to deliver more than one individual presentation, the mean average mark across all presentations delivered will be awarded.
Group presentations will be marked based on active and thoughtful engagement in the class discussions; and clear and insightful comparison among the papers in, and where relevant, between sessions.