Anomaly detection in IoT devices using side-channel power consumption

Loading...
Thumbnail Image
Files
LightbodyG_Phd2026.pdf(34.21 MB)
Full Text E-thesis
Date
2026-04-23
Authors
Lightbody, Dominic
Journal Title
Journal ISSN
Volume Title
Publisher
University College Cork
Published Version
Research Projects
Organizational Units
Journal Issue
Abstract
The Internet of Things (IoT) has transformed modern infrastructure, but its pervasive connectivity has introduced significant security challenges. Many IoT devices lack adequate protection, leaving critical systems vulnerable to compromise. Intrusion detection systems (IDS) for IoT are often focused on network traffic analysis, which can overlook alternative fundamental behavioural signals present within electronic devices, such as device-level side-channel data. One such signal is device power consumption—a ubiquitous, low-level indicator of computation. This thesis investigates side-channel power data as a modality for IoT intrusion detection, progressing from lightweight supervised models to advanced self-supervised architectures trained directly on unlabelled power traces. The research begins by demonstrating the feasibility of power-based intrusion detection using lightweight Convolutional Neural Networks (CNNs) trained on time-series power traces with synthetically injected anomalies. Implemented on an ultra-low-power microcontroller, this early system shows that IoT power behaviour contains distinct, repeatable structure that can be detected reliably at the edge. To address the limitations of synthetic anomalies, the thesis develops a comprehensive dataset of real IoT attack power traces using Raspberry Pi and DragonBoard-based testbeds (Dragon_Pi). Multiple attack classes—including reconnaissance, brute force, and denial of service—were executed, alongside a realistic multi-stage “capture-the-flag” scenario. The resulting dataset reveals the rich, multi-phase temporal structure of genuine intrusion behaviour and highlights the value of side-channel power data for forensic analysis. Building on these insights, the work transitions to self-supervised learning trained exclusively on normal behaviour. A Convolutional Autoencoder (CAE) and a dropout-enhanced variant establish that reconstruction-based anomaly detection can identify unseen attacks while remaining interpretable through reconstruction-error visualisation. The final contribution introduces CompMAE—a Compression-Enhanced Masked Autoencoder that integrates Conformer-style local–global modelling with a novel compression module tailored for anomaly detection. Trained on real normal power data, CompMAE sharply amplifies reconstruction errors for anomalous inputs, leading to far more detectable anomalies than the CAE models on the Dragon_Pi dataset. Despite its architectural sophistication, it remains lightweight and compatible with embedded hardware, bridging modern deep learning methods with practical IoT security constraints. Collectively, this thesis establishes side-channel power monitoring as an under explored yet viable modality for IoT intrusion detection. It presents a clear methodological progression—from supervised CNNs on synthetic data, to real attack characterisation, to initial self-supervised experiments with CAEs, to modern transformer-based self-supervised models—culminating in a robust, explainable, and edge-deployable IDS framework.
Description
Keywords
Internet of Things (IoT) security , Intrusion detection systems (IDS) , Anomaly detection , Side-channel analysis , Power consumption monitoring , Self-supervised learning , Autoencoders , Masked Autoencoders , Transformer models , Embedded machine learning , Time-series analysis
Citation
Lightbody, D. 2026. Anomaly detection in IoT devices using side-channel power consumption. PhD Thesis, University College Cork.
Link to publisher’s version