Skip to content
Review Open access

ENTRUST: Closed-Loop Trust-Calibrated Autonomous Cyber Defense for Ambient IoT

Sep 2026 · Computers · 0 citations · 25 references

Abstract

Ambient Internet-of-Things (IoT) deployments place large fleets of battery-less, energy-harvesting devices in environments where human operators cannot review every security event. Autonomous Artificial-Intelligence (AI) defenders can reduce this burden, but incorrect autonomous containment can amplify incidents, whereas excessive deferral can overwhelm operators and distort appropriate reliance. Existing approaches typically configure detection, explanation, and autonomy separately. We present ENTRUST, which treats these capabilities as a closed-loop control problem. A calibrated detector estimates threat probability together with epistemic and aleatoric uncertainty. A trust-calibration controller tracks the gap between operator trust and the agent’s estimated reliability. A constrained co-adaptation policy then jointly selects one of five autonomy levels and one of four explanation-fidelity levels, subject to hard safety invariants for critical and irreversible actions. We formalize the problem and provide the co-adaptation and trust-update algorithms. The evaluation is simulation-based and uses an episodic simulator whose attack taxonomy, class priors, and device-criticality structure follow public IoT intrusion corpora. The reported numerical results should therefore be interpreted as comparative estimates under controlled conditions, not as measurements from a deployed ambient-IoT system. Across five threat conditions, 30 seeds, five baselines, and nine ablations, ENTRUST attains the lowest harmful-action rate and trust-calibration error in every evaluated condition while requiring roughly 70% fewer human interventions than mandatory-approval oversight. Under adversarial context injection, containment remains at 0.74, compared with 0.64 for unconstrained autonomy (Cliff’s δ=1.0, p<10−10). The nine ablations further isolate the mechanism: adaptive autonomy primarily affects safety, detection–explanation–autonomy coupling affects calibration, and uncertainty plus trust feedback affect adversarial robustness.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.