INCENTIVE · contINuous deCentralized lEarNing of ioT devIces' behaVioural profilEs
„Хоризонт Европа“ — Действия „Мария Склодовска-Кюри“
- Период
- 2023-03-01 → 2025-04-30
- Финансиране от ЕС
- 181 153 €
- Участници
- 3
- Схема
- HORIZON-TMA-MSCA-PF-EF
Линиите свързват координатора с партньорите.
Накратко на български
Поведението на IoT устройствата, като смарт камери и рутери, се анализира, за да се разпознаят отклонения от нормалната им работа. Това помага за по-бързото откриване на кибератаки, които могат да застрашат услугите в здравеопазването, транспорта и индустрията.
Кратко обяснение, генерирано от езиков модел по текста на CORDIS. Оригиналът е по-долу.
Резултати накратко
contINuous deCentralized lEarNing of ioT devIces' behaVioural profilEs
Modern societies are hyperconnected, relying on IoT devices in critical areas like healthcare, transport, industry, and homes. This connectivity brings convenience but also expands the “attack surface” for cyber threats. In recent years, significant incidents have shown how attackers can exploit insecure IoT devices; for example, the Mirai botnet hijacked thousands of smart cameras and routers by using their default passwords, turning them into a network of attack. Such events underscore the risk: a successful attack on IoT systems can disrupt services affecting even citizens’ safety. The challenge is that many IoT devices are resource-constrained (with limited computing power and memory) and often deployed in large numbers, making traditional security measures difficult to apply. INCENTIVE was conceived to address some of these challenges by developing new methods that help secure IoT devices in line with these evolving needs. The project’s overarching objective is to proactively detect cyberattacks on IoT devices by continuously learning their “normal” behavior patterns. Instead of reacting after a breach, INCENTIVE’s approach is preventive, so it constantly monitors and learns from device activity to quickly flag abnormal behaviors. This is especially important for IoT, where attacks might not be immediately obvious. To achieve its aim, INCENTIVE has four key objectives: • O1. To understand IoT device behavior (with human factors) by developing enriched profiles of how IoT devices behave under normal conditions over time. This includes the influence of human interaction (e.g., how people manage settings, usage patterns, maintenance habits). These behavior profiles form a baseline to compare against and spot irregularities that could indicate a security threat. • O2. Continuous decentralized learning through the design of a secure learning process that updates these behavior profiles using Federated Learning (FL). This allows the detection model to improve over time as devices generate new data, without relying on centralized data collection. • O3. Trust and integrity in the learning process by ensuring that collaborative learning is trustworthy and tamper-resistant, to prevent attackers from poisoning the system with false data. INCENTIVE integrates robust aggregation approaches to guarantee that only legitimate devices participate and that the model updates they contribute cannot be maliciously modified. • O4. Validation in different scenarios through the verification of the developed framework in various deployment settings. The goal is to demonstrate that the approach works in practice by measuring how well it detects intrusions, how it impacts device performance, and identifying any trade-offs. These evaluations ensure that the solution can be adapted to different IoT environments and inform further refinements needed for real-world adoption. Through such objectives, INCENTIVE provides a practical approach to improving the security of IoT systems. Its methods are designed to work within the real-world limitations of connected devices, while also considering how people interact with them. Therefore, the project contributes to building more resilient and user-aware IoT environments, helping to reduce risks and support safer everyday use of connected technologies.
Текст от CORDIS, на английски · Данни: CORDIS, © Европейски съюз
Цел на проекта
In an increasingly hyperconnected society, cybersecurity concerns take on a broader dimension, which can impact citizens safety. This has been widely recognized in the EU through specific legal instruments, such as the Cybersecurity Act and the recent Cybersecurity Strategy for the Digital Decade. The development of the IoT technologies have fostered the deployment of data-driven services for everyday scenarios, such as transport, health and energy, but have also increased the probability and impact of new cybersecurity threats. Recent and well-known attacks have demonstrated the need to develop AI-based techniques to identify such attacks in IoT scenarios. In this context, the objective of this project is to build a decentralized framework to learn the IoT devices intended behavior throughout their lifecycle, in order to distinguish abnormal behavior that may reflect a security attack or threat. The proposal will build an edge-based and federated learning architecture to enable IoT devices to participate in the learning process by using lightweight security protocols. This architecture will include the use of blockchain through a novel approach in which different ledgers will be interconnected to improve the performance and practicability of existing approaches. Furthermore, the proposal will be the first effort to quantify the impact of human-machine interactions on the devices intended behavior. The project will be validated quantitatively and qualitatively to identify potential tradeoffs for its deployment in different IoT-enabled scenarios. It will leverage the candidates extensive knowledge and experience in IoT cybersecurity, which will be strengthened by the host institution to improve his technical and transferable skills in a multidisciplinary environment. The proposed project represents a unique contribution to reinforcing the culture of cybersecurity in the EU that will boost the candidate's professional development during and after the fellowship.
Оригинален текст от CORDIS (на английски).
Участници
- UNIVERSIDAD DE MURCIA · MurciaКоординаторИспания
- TELEFONICA INNOVACION DIGITAL SL · MADRIDИспания
- UNIVERSITY OF KENT · Canterbury, KentОбединеното кралство
Връзки
- Виж в CORDIS
- DOI: 10.3030/101065524
- https://ec.europa.eu/research/participants/documents/downloadPublic?documentIds=080166e510aa531c&appId=PPGMS
- https://ec.europa.eu/research/participants/documents/downloadPublic?documentIds=080166e51c12f3c8&appId=PPGMS
Данни: CORDIS, © Европейски съюз
