Anomaly-Based Intrusion Detection for IoT Microcontrollers Using Power Side-Channel Fingerprinting
Abstract
This study introduces a unified evaluation framework for device-level intrusion detection using power side-channel fingerprints under an open-set threat model. We target post-enrollment device substitution: an adversary replaces a legitimate Commercial Off-The-Shelf (COTS) node with a counterfeit of the same model and firmware after enrollment, during deployment or maintenance, making the substitution invisible to credential-based authentication. To address this scenario, we evaluate seven ESP32-WROOM-32 and seven Arduino Uno R3 devices across four sessions spanning 45 days. Each platform group is drawn from a single manufacturing batch so that measured differences reflect within-batch variation; results are correspondingly established at this scale and for this sourcing. Unlike most prior studies that evaluate fingerprinting under isolated assumptions, this study treats intrusion detection as a system-level problem that requires the joint consideration of temporal stability, open-set recognition, and feature representation. We conduct a two-tier evaluation. Tier 1 characterizes device uniqueness and temporal stability using handcrafted statistical features and neural embeddings trained via triplet + Additive-Margin Softmax (AM-Softmax) loss, analyzed via separation ratios, d′ scores, F1-scores, and statistical power. Tier 2 applies embeddings to an open-set intrusion-detection protocol using percentile-based thresholding. This analysis reveals that temporal viability is strongly influenced by feature representation under the evaluated conditions. Over 45 days, under an identical Leave-One-Run-Out protocol and scoring rule, neural embeddings achieve a 93.9% true positive rate at a 9.9% false acceptance rate, whereas the same rule applied to handcrafted statistical features yields 66.4% and 35.8%. When each device identity is withheld from training altogether, embeddings hold a 26.0% false acceptance rate against 39.0% for statistical features. Platform comparison shows that ESP32 achieves a 1.80× higher separation ratio than Arduino (3.06 vs. 1.70), with architecture-dependent discriminability. Statistical power analysis yields 89.1% power at d=0.774. These results identify representation-level robustness as a key requirement for practical power-based intrusion detection, while longer-term validation remains an important direction for future work.