FH Technikum Wien
Secure Edge AI Gateway for IoT Sensor Networks
Lightweight Detection of Sensor-Data Integrity Attacks
MIO-3 Master's Project · 2026–2027 · In progress
MSc Internet of Things & Intelligent Systems
Working title · current research scope; final alignment with the supervisor is pending.
Overview
IoT sensor systems continuously generate operational data. Manipulated observations can compromise data integrity and downstream decisions. This project investigates whether lightweight anomaly detection can run directly on a resource-constrained edge gateway. Environmental sensor data provides the legitimate behavioural baseline and experimental workload; generic environmental anomaly detection is not the primary research problem. Controlled manipulations will be generated only in an isolated research testbed. Evaluation will cover detection effectiveness and edge-resource usage.
Research objective
The objective is to design and experimentally evaluate a reproducible edge-based security monitoring prototype for Sensor-Data Integrity using lightweight statistical and machine-learning approaches. Implementation and experimental results are still pending.
Research questions
Current draft
- RQ1
- How can normal multivariate IoT sensor behaviour be represented to support the detection of sensor-data integrity attacks?
- RQ2
- How effectively can lightweight anomaly-detection methods detect different forms of sensor-data manipulation compared with a statistical baseline?
- RQ3
- What trade-offs arise between attack-detection performance and edge-resource consumption when detection is executed on a resource-constrained IoT gateway?
System architecture

Planned live path: ASAIR AM2302 → ESP32-S3 → Wi-Fi / MQTT → pass-through or Controlled Attack Injection → Raspberry Pi 5 Edge Security Gateway → statistical / ML detection → normal or security alert. Historical environmental data may be replayed into the same Isolated Research Testbed once access is clarified. FH production infrastructure is outside the attack scope.
Experimental approach
Legitimate sensor data → preprocessing → normal-behaviour modelling → Controlled Attack Injection → independent comparison of detection methods → Raspberry Pi 5 deployment → detection and resource evaluation. RQ1 maps to normal-behaviour modelling; RQ2 to detection methods and detection evaluation; RQ3 to edge deployment and resource evaluation.

Planned detection methods
- Statistical Baseline
- Isolation Forest
- One-Class SVM
The Statistical Baseline provides a transparent reference. Isolation Forest and One-Class SVM offer alternative approaches to identifying deviations from normal sensor behaviour. One method will be evaluated independently per experiment; no ranking has been established.
Controlled security scenarios
These manipulations are planned exclusively as controlled experiments inside the isolated research testbed.
- Spike / False-Data Injection
- Persistent Bias
- Gradual Drift
- Stuck / Frozen Values
- Replay — optional later experiment
Experimental platform
Hardware
- Raspberry Pi 5
- ESP32-S3-DevKitC-1
- ASAIR AM2302
- microSD storage and local networking
Software / protocols (planned)
- Linux / Raspberry Pi OS
- Wi-Fi / MQTT
- Python · pandas / NumPy · scikit-learn
- Jupyter for exploratory analysis where appropriate
Evaluation
The study will investigate the trade-off between detection effectiveness and computational cost at the edge gateway. No measurement results are available yet.
Detection effectiveness
- Precision
- Recall
- F1-score
- False-Alarm Rate
- Detection Delay, where applicable
Edge resources
- Inference Latency
- CPU Usage
- Memory Usage
Research scope
Sensor-Data Integrity Monitoring through controlled manipulation of sensor observations is in scope. Generic IDS, malware detection, firmware exploitation, Wi-Fi attacks, credential attacks, MQTT broker exploitation, cryptographic attacks and attacks against FH production infrastructure are outside scope.
Current status
Available / designed
- Initial research scope defined
- Raspberry Pi 5, ESP32-S3 and ASAIR AM2302 available
- Initial system architecture and research methodology designed
In preparation / planned
- Final scope alignment and data-access clarification
- Testbed setup and data acquisition
- Statistical baseline implementation and ML experiments
- Edge benchmarking