Anomaly detection in IoT devices using side-channel power consumption

dc.contributor.advisorPopovici, Emanuel
dc.contributor.advisorMurphy, Colin
dc.contributor.advisorTemko, Andriy
dc.contributor.authorLightbody, Dominicen
dc.contributor.funderInsight SFI Research Centre for Data Analyticsen
dc.date.accessioned2026-05-25T09:22:28Z
dc.date.available2026-05-25T09:22:28Z
dc.date.issued2026-04-23en
dc.date.submitted2026-04-23
dc.description.abstractThe Internet of Things (IoT) has transformed modern infrastructure, but its pervasive connectivity has introduced significant security challenges. Many IoT devices lack adequate protection, leaving critical systems vulnerable to compromise. Intrusion detection systems (IDS) for IoT are often focused on network traffic analysis, which can overlook alternative fundamental behavioural signals present within electronic devices, such as device-level side-channel data. One such signal is device power consumption—a ubiquitous, low-level indicator of computation. This thesis investigates side-channel power data as a modality for IoT intrusion detection, progressing from lightweight supervised models to advanced self-supervised architectures trained directly on unlabelled power traces. The research begins by demonstrating the feasibility of power-based intrusion detection using lightweight Convolutional Neural Networks (CNNs) trained on time-series power traces with synthetically injected anomalies. Implemented on an ultra-low-power microcontroller, this early system shows that IoT power behaviour contains distinct, repeatable structure that can be detected reliably at the edge. To address the limitations of synthetic anomalies, the thesis develops a comprehensive dataset of real IoT attack power traces using Raspberry Pi and DragonBoard-based testbeds (Dragon_Pi). Multiple attack classes—including reconnaissance, brute force, and denial of service—were executed, alongside a realistic multi-stage “capture-the-flag” scenario. The resulting dataset reveals the rich, multi-phase temporal structure of genuine intrusion behaviour and highlights the value of side-channel power data for forensic analysis. Building on these insights, the work transitions to self-supervised learning trained exclusively on normal behaviour. A Convolutional Autoencoder (CAE) and a dropout-enhanced variant establish that reconstruction-based anomaly detection can identify unseen attacks while remaining interpretable through reconstruction-error visualisation. The final contribution introduces CompMAE—a Compression-Enhanced Masked Autoencoder that integrates Conformer-style local–global modelling with a novel compression module tailored for anomaly detection. Trained on real normal power data, CompMAE sharply amplifies reconstruction errors for anomalous inputs, leading to far more detectable anomalies than the CAE models on the Dragon_Pi dataset. Despite its architectural sophistication, it remains lightweight and compatible with embedded hardware, bridging modern deep learning methods with practical IoT security constraints. Collectively, this thesis establishes side-channel power monitoring as an under explored yet viable modality for IoT intrusion detection. It presents a clear methodological progression—from supervised CNNs on synthetic data, to real attack characterisation, to initial self-supervised experiments with CAEs, to modern transformer-based self-supervised models—culminating in a robust, explainable, and edge-deployable IDS framework.en
dc.description.statusNot peer revieweden
dc.description.versionAccepted Versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.citationLightbody, D. 2026. Anomaly detection in IoT devices using side-channel power consumption. PhD Thesis, University College Cork.
dc.identifier.endpage217
dc.identifier.urihttps://hdl.handle.net/10468/18851
dc.language.isoenen
dc.publisherUniversity College Corken
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/Research Centres Programme
dc.rights© 2026, Dominic Lightbody.
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subjectInternet of Things (IoT) security
dc.subjectIntrusion detection systems (IDS)
dc.subjectAnomaly detection
dc.subjectSide-channel analysis
dc.subjectPower consumption monitoring
dc.subjectSelf-supervised learning
dc.subjectAutoencoders
dc.subjectMasked Autoencoders
dc.subjectTransformer models
dc.subjectEmbedded machine learning
dc.subjectTime-series analysis
dc.titleAnomaly detection in IoT devices using side-channel power consumption
dc.typeDoctoral thesisen
dc.type.qualificationlevelDoctoralen
dc.type.qualificationnamePhD - Doctor of Philosophyen
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
LightbodyG_Phd2026.pdf
Size:
34.21 MB
Format:
Adobe Portable Document Format
Description:
Full Text E-thesis
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
5.2 KB
Format:
Item-specific license agreed upon to submission
Description: