Skip to content

FH Technikum Wien

Secure Edge AI Gateway for IoT Sensor Networks

Lightweight Detection of Sensor-Data Integrity Attacks

MIO-3 Master's Project · 2026–2027 · In progress

MSc Internet of Things & Intelligent Systems

Working title · current research scope; final alignment with the supervisor is pending.

Overview

IoT sensor systems continuously generate operational data. Manipulated observations can compromise data integrity and downstream decisions. This project investigates whether lightweight anomaly detection can run directly on a resource-constrained edge gateway. Environmental sensor data provides the legitimate behavioural baseline and experimental workload; generic environmental anomaly detection is not the primary research problem. Controlled manipulations will be generated only in an isolated research testbed. Evaluation will cover detection effectiveness and edge-resource usage.

Research objective

The objective is to design and experimentally evaluate a reproducible edge-based security monitoring prototype for Sensor-Data Integrity using lightweight statistical and machine-learning approaches. Implementation and experimental results are still pending.

Research questions

Current draft

RQ1
How can normal multivariate IoT sensor behaviour be represented to support the detection of sensor-data integrity attacks?
RQ2
How effectively can lightweight anomaly-detection methods detect different forms of sensor-data manipulation compared with a statistical baseline?
RQ3
What trade-offs arise between attack-detection performance and edge-resource consumption when detection is executed on a resource-constrained IoT gateway?

System architecture

System architecture of the isolated Secure Edge AI IoT research testbed with ESP32-S3 sensor node, controlled attack injection and Raspberry Pi 5 edge security gateway.
Open original-size diagram

Planned live path: ASAIR AM2302 → ESP32-S3 → Wi-Fi / MQTT → pass-through or Controlled Attack Injection → Raspberry Pi 5 Edge Security Gateway → statistical / ML detection → normal or security alert. Historical environmental data may be replayed into the same Isolated Research Testbed once access is clarified. FH production infrastructure is outside the attack scope.

Experimental approach

Legitimate sensor data → preprocessing → normal-behaviour modelling → Controlled Attack Injection → independent comparison of detection methods → Raspberry Pi 5 deployment → detection and resource evaluation. RQ1 maps to normal-behaviour modelling; RQ2 to detection methods and detection evaluation; RQ3 to edge deployment and resource evaluation.

Research methodology from problem and research questions through normal-behaviour modelling, controlled attack injection, independent detection methods, edge deployment and evaluation; RQ1 maps to modelling, RQ2 to detection, RQ3 to edge resources.
Open original-size diagram

Planned detection methods

  • Statistical Baseline
  • Isolation Forest
  • One-Class SVM

The Statistical Baseline provides a transparent reference. Isolation Forest and One-Class SVM offer alternative approaches to identifying deviations from normal sensor behaviour. One method will be evaluated independently per experiment; no ranking has been established.

Controlled security scenarios

These manipulations are planned exclusively as controlled experiments inside the isolated research testbed.

  • Spike / False-Data Injection
  • Persistent Bias
  • Gradual Drift
  • Stuck / Frozen Values
  • Replay — optional later experiment

Experimental platform

Hardware

  • Raspberry Pi 5
  • ESP32-S3-DevKitC-1
  • ASAIR AM2302
  • microSD storage and local networking

Software / protocols (planned)

  • Linux / Raspberry Pi OS
  • Wi-Fi / MQTT
  • Python · pandas / NumPy · scikit-learn
  • Jupyter for exploratory analysis where appropriate

Evaluation

The study will investigate the trade-off between detection effectiveness and computational cost at the edge gateway. No measurement results are available yet.

Detection effectiveness

  • Precision
  • Recall
  • F1-score
  • False-Alarm Rate
  • Detection Delay, where applicable

Edge resources

  • Inference Latency
  • CPU Usage
  • Memory Usage

Research scope

Sensor-Data Integrity Monitoring through controlled manipulation of sensor observations is in scope. Generic IDS, malware detection, firmware exploitation, Wi-Fi attacks, credential attacks, MQTT broker exploitation, cryptographic attacks and attacks against FH production infrastructure are outside scope.

Current status

Available / designed

  • Initial research scope defined
  • Raspberry Pi 5, ESP32-S3 and ASAIR AM2302 available
  • Initial system architecture and research methodology designed

In preparation / planned

  • Final scope alignment and data-access clarification
  • Testbed setup and data acquisition
  • Statistical baseline implementation and ML experiments
  • Edge benchmarking