Skip to content
Open access

Security-by-Design and Risk-Based Certification for AI-Enabled Smart Home

Aug 2026 · Future Internet · 0 citations · 47 references

TL;DR

A Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning is proposed.

Abstract

The integration of Artificial Intelligence (AI) into Internet of Things (IoT) ecosystems has enabled the development of advanced cyber–physical systems, including smart appliances, while introducing security, privacy, and AI governance risks that extend beyond the scope of traditional threat models. Existing approaches often address cybersecurity, AI risk management, and regulatory compliance in isolation, leaving manufacturers without a systematic method for translating identified threats into architectural controls and certification requirements. To address this gap, this study proposes a Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning. The resulting cross-layer analysis informs a four-level certification model (L1–L4) that deterministically maps each appliance configuration to a set of mandatory security and governance controls according to its degree of autonomy and AI capability. The framework is instantiated and evaluated using a physical smart-refrigerator prototype, demonstrating how threat identification can be systematically translated into design decisions and certification requirements. The proposed framework provides manufacturers, certification bodies, and researchers with a reproducible engineering pathway for designing and evaluating secure, governance-aligned AI-enabled IoT appliances.

Read PDF

Similar papers

Review Open access Aug 2026

A Systematic Review of Smart Home IoT Security: Applications, Threat Taxonomy, Privacy Risks, and Emerging Defensive Solutions

It is suggested that scalable smart home security requires coordinated progress in protocol standardization, enforceable device update lifecycles, gateway-level anomaly detection, and privacy-preserving local analytics rather than reliance on a single technical solution.

Dalibor Radovanovic, Nikola Savanović, Jelena Janackovic et al. · 0 citations
Review Open access Jul 2026

AI-Based Autonomous Security for Cyber–Physical Systems 2.0 in IoT Ecosystems—A Narrative Review

This narrative review examines the evolving landscape of AI-based security in Cyber–Physical Systems 2.0 (CPS 2.0) within the context of AI-driven autonomous cybersecurity solutions for the Internet of Things (IoT). This article presents a narrative review, supported by a structured literature search inspired by the PRISMA 2020 project and descriptive publication statistics. It combines transparent study selection with qualitative conceptual synthesis, rather than a formal systematic review or bibliometric analysis. CPS 2.0 represents a new generation of interconnected systems that tightly integrate physical processes with intelligent computational components, enabling increased autonomy and operational efficiency. However, this growing complexity introduces advanced security threats and privacy challenges that traditional centralized security frameworks are ill-equipped to address due to limitations in scalability, latency, and data sensitivity. The paper explores how artificial intelligence (AI), machine learning (ML), and generative AI (GenAI) enhance real-time threat detection, prediction, and response in distributed environments. It highlights the role of edge computing in decentralizing intelligence, thereby reducing latency and limiting exposure of sensitive data. Additionally, federated learning (FL) is discussed as a privacy-preserving paradigm that enables collaborative model training across distributed nodes without sharing raw data. The integration of GenAI, FL, and edge computing is presented as a synergistic approach that enables adaptive, context-aware, and proactive defense mechanisms against dynamic and evolving cyber threats. The review further analyzes architectural frameworks, key advantages, and inherent vulnerabilities of CPS 2.0, along with mitigation strategies and real-world applications, particularly in industrial control systems. By synthesizing current advancements and challenges, this work provides a comprehensive roadmap for designing resilient, scalable, and privacy-aware CPS infrastructures. The findings contribute to the development of secure and intelligent systems aligned with the future demands of Industry 4.0, 5.0, and beyond.

Izabela Rojek, P. Kotlarz, D. Mikołajewski · 0 citations
Review Open access Aug 2026

Cybersecurity in the IoT Era: Protecting the Expanding Internet of Things

It is argued that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and where current technological and regulatory responses fall short of that goal is identified.

K. Curran, J. Kyle, Lovepreet Singh · 0 citations
Review Open access Aug 2026

Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures

A multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains is developed.

Kennedy Owino Jaramba, Samwel Oonge · 0 citations
Review Open access Aug 2026

AI-Driven Problem Solving for Cyber-Physical Systems Security: An Assessment Framework

It is found that traditional risk assessment and testing approaches are insufficient for AI-powered CPS, and a prototype implementation and experimental evaluation are presented along with a case study of protecting a smart manufacturing plant during a ransomware attack using the proposed approach.

Vikram Kulothungan, Deepti Gupta, Raju Dhakal et al. · 0 citations
Conference Open access 2026

Towards AI-Guided Security Hardening of Industrial Systems Based on IEC 62443

This paper investigates a secure-by-design engineering process focusing on the initial architectural design and examines the role that AI-powered agents can play in supporting it, as well as the conditions required for their effective and reliable use.

C. Ponsard, Jean-François Daune · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.