arrow
Return

Device behavioural blueprint (DB2): A risk-aware framework for unique device behaviour profiling using microarchitectural variations

delete2026-06-03
delete0
delete
OA
AI
M
Muthupavithran Selvam *
S
Safwana Haque
A
Amit Kumar Singh
Z
Zhan Cui
R
Rajarajan Muttukrishnan
DOI:10.1016/j.jnca.2026.104526delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
This paper introduces DB2, a risk-aware behavioural identity framework that derives device identity from CPU–RTC timing deviation and Performance Monitoring Unit (PMU) microarchitectural events, without relying on GPUs, radios, sensors, or dedicated hardware. The method captures oscillator-coupled timing variation and execution behaviour through a structured signal-processing pipeline, producing device-specific behavioural signatures that remain distinguishable across reboots, temperature variation, and core transitions. DB2 structures identity assurance into three layers: closed-set identification, calibrated open-set rejection, and stability-aware risk scoring. Evaluation under a strict three-way split with reboot separation for training, calibration, and unseen testing yields a macro-F1 of 0.957 on unseen reboots. The open-set layer rejects previously unseen devices with a mean true-positive rate of 0.990 at a calibrated event-level false-reject rate of approximately 0.08 under strict leave-one-device-out validation, with operating-point selection performed exclusively on the calibration split. A Dynamic-Aware Identification and Risk (DAIR) mechanism decomposes behavioural stability across temperature, reboot, and core factors to provide interpretable posture monitoring for enrolled devices. Under identity-claim manipulation via spoofing, Sybil, and relabelling scenarios involving cloning, targeted identities exhibit reduced identification consistency and elevated risk, while non-targeted devices remain stable under identical calibration settings. These results show that behavioural fingerprints can be derived from standard CPU, RTC, and PMU-accessible resources on edge devices, enabling device-identity and behavioural-assurance monitoring in IoT and edge environments without specialised hardware.
Keywords:
Device fingerprinting
Microarchitectural behaviour
CPU–RTC timing drift
PMU-based identification
Closed-set identification
Open-set recognition
DAIR risk scoring
Edge device security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Network and Computer Applications cover
Journal of Network and Computer Applications
IF:
8
Papers:
3.6K
Citations:
1.1W

Organization

U
university of london
Scholars:
21.5W
Papers: 19.7W
Citations: 305
U
university of essex
Scholars:
658
Papers: 438
Citations: 0
B
bt group
Scholars:
4
Papers: 4
Citations: 0
researcher View more organizations