article Open access

Lightweight Anomaly Detection in IoT-Integrated Cyber-Physical Systems for Smart Homes

  • IEEE Access
  • Institute of Electrical and Electronics Engineers
Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Öz

This paper presents a method for detecting attacks in smart home cyber-physical systems that combines network traffic analysis with physical sensor data. We apply the Shiryaev-Roberts and CUSUM change-point procedures to two data streams: packet counts at the residential gateway and motion readings from occupancy sensors, and compare four strategies for combining evidence from both streams. The system was tested on 31 hours of residential traffic with 16 synthetically injected Mirai-style attacks; both the attack traffic and the corresponding physical shifts are injected into the dataset. Score Fusion achieved an F1-score of 0.822 and the lowest false alarm rate of all seven methods tested (0.040). The network-only detector responded in 1.3 minutes on average but produced false alarms at roughly twice the rate. The physical stream detector caught all 16 attacks but took (4.4 minutes with the centered window used in this study; 5.4 minutes with a causal trailing window because the injected physical shift is applied after a modelled propagation delay. When attacks produce no physical effect, the cyber-only detectors are unaffected while fusion methods that depend on the physical stream drop to near-zero recall. Running the full pipeline on a Raspberry Pi 4 took 71 milliseconds for the entire dataset, the approach therefore runs on low-cost gateway hardware without specialist acceleration.

Record transparency

Publication details

DOI
10.1109/access.2026.3702518
OpenAlex
W7164132014
Document type
article
Language
EN
Source
IEEE Access
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.