Aug 2026· Future Internet· 0 citations· 47 references
TL;DR
A Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning is proposed.
Abstract
The integration of Artificial Intelligence (AI) into Internet of Things (IoT) ecosystems has enabled the development of advanced cyber–physical systems, including smart appliances, while introducing security, privacy, and AI governance risks that extend beyond the scope of traditional threat models. Existing approaches often address cybersecurity, AI risk management, and regulatory compliance in isolation, leaving manufacturers without a systematic method for translating identified threats into architectural controls and certification requirements. To address this gap, this study proposes a Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning. The resulting cross-layer analysis informs a four-level certification model (L1–L4) that deterministically maps each appliance configuration to a set of mandatory security and governance controls according to its degree of autonomy and AI capability. The framework is instantiated and evaluated using a physical smart-refrigerator prototype, demonstrating how threat identification can be systematically translated into design decisions and certification requirements. The proposed framework provides manufacturers, certification bodies, and researchers with a reproducible engineering pathway for designing and evaluating secure, governance-aligned AI-enabled IoT appliances.
The rapid proliferation of Internet of Things (IoT) technologies has transformed the modern home into a complex cyber–physical ecosystem encompassing hundreds of millions of connected devices globally. Smart homes support automation, energy management, and healthcare monitoring, but they also introduce a broad and evolving range of security and privacy challenges. This review examines 233 sources published between 2018 and May 2025, selected through a PRISMA-informed process covering five major academic databases and relevant standards and technical reports. It discusses communication protocols, including Matter, develops a Threat-Layer-Defense synthesis matrix covering ten attack categories; examines the practical limitations of AI-based anomaly detection and blockchain-based trust management; and derives recommendations for manufacturers, platform providers, users, and regulators. Privacy challenges, regulatory frameworks, and user behavior are considered alongside technical threats. The findings suggest that scalable smart home security requires coordinated progress in protocol standardization, enforceable device update lifecycles, gateway-level anomaly detection, and privacy-preserving local analytics rather than reliance on a single technical solution.
Dalibor Radovanovic, Nikola Savanović, Jelena Janackovic et al.· Big Data and Cognitive Compu...· 0 citations
This narrative review examines the evolving landscape of AI-based security in Cyber–Physical Systems 2.0 (CPS 2.0) within the context of AI-driven autonomous cybersecurity solutions for the Internet of Things (IoT). This article presents a narrative review, supported by a structured literature search inspired by the PRISMA 2020 project and descriptive publication statistics. It combines transparent study selection with qualitative conceptual synthesis, rather than a formal systematic review or bibliometric analysis. CPS 2.0 represents a new generation of interconnected systems that tightly integrate physical processes with intelligent computational components, enabling increased autonomy and operational efficiency. However, this growing complexity introduces advanced security threats and privacy challenges that traditional centralized security frameworks are ill-equipped to address due to limitations in scalability, latency, and data sensitivity. The paper explores how artificial intelligence (AI), machine learning (ML), and generative AI (GenAI) enhance real-time threat detection, prediction, and response in distributed environments. It highlights the role of edge computing in decentralizing intelligence, thereby reducing latency and limiting exposure of sensitive data. Additionally, federated learning (FL) is discussed as a privacy-preserving paradigm that enables collaborative model training across distributed nodes without sharing raw data. The integration of GenAI, FL, and edge computing is presented as a synergistic approach that enables adaptive, context-aware, and proactive defense mechanisms against dynamic and evolving cyber threats. The review further analyzes architectural frameworks, key advantages, and inherent vulnerabilities of CPS 2.0, along with mitigation strategies and real-world applications, particularly in industrial control systems. By synthesizing current advancements and challenges, this work provides a comprehensive roadmap for designing resilient, scalable, and privacy-aware CPS infrastructures. The findings contribute to the development of secure and intelligent systems aligned with the future demands of Industry 4.0, 5.0, and beyond.
Izabela Rojek, P. Kotlarz, D. Mikołajewski· Electronics· 0 citations
The Internet of Things (IoT) is transforming industries and daily life by connecting billions of devices, enabling smart homes, cities and industrial systems. This rapid expansion, however, introduces significant cybersecurity vulnerabilities, leaving IoT systems increasingly exposed to both established and emerging attack techniques. This paper presents a structured critical review of IoT cybersecurity, distinguished from prior general surveys by three contributions: first, a cross-layer mapping of named, dated case studies to the specific Security-by-Design principles that would have mitigated them; second, a comparative, feasibility-based evaluation of lightweight cryptographic primitives and blockchain consensus protocols for resource-constrained devices, rather than a descriptive overview; and third, a critical appraisal of the operational limitations of AI-based and blockchain-based defences, including adversarial manipulation, data scarcity and energy cost, set against the claims commonly made for these technologies. We examine the current state of IoT security across the perception, network and application layers; the common vulnerabilities that affect these systems, from insecure device design and weak default credentials to unencrypted communications; and the real-world consequences of these flaws through recent, named case studies, including the Aisuru botnet which is active since 2024 and 2024 vulnerability disclosures affecting Mitsubishi Electric and OMRON industrial controllers. We argue that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and we identify where current technological and regulatory responses fall short of that goal.
K. Curran, J. Kyle, Lovepreet Singh· Recent Progress in Science a...· 0 citations
The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.
It is found that traditional risk assessment and testing approaches are insufficient for AI-powered CPS, and a prototype implementation and experimental evaluation are presented along with a case study of protecting a smart manufacturing plant during a ransomware attack using the proposed approach.
Vikram Kulothungan, Deepti Gupta, Raju Dhakal et al.· Italian National Conference...· 0 citations
This paper investigates a secure-by-design engineering process focusing on the initial architectural design and examines the role that AI-powered agents can play in supporting it, as well as the conditions required for their effective and reliable use.
C. Ponsard, Jean-François Daune· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.