SoK: Telemetry-Aware Runtime Assurance for Always-On On-device Intrusion Detection
Ouyang, Nuonan, Shatte, Adrian, Lu, Zhigang, Chen, Chao, and Xiang, Wei (2026) SoK: Telemetry-Aware Runtime Assurance for Always-On On-device Intrusion Detection. In: Lecture Notes in Computer Science (16794) pp. 163-183. From: ACISP 2026: 31st Australasian Conference on Information Security and Privacy, 6-9 July 2026, Perth, WA, Australia.
|
PDF (Publisher Accepted Version)
- Accepted Version
Restricted to Repository staff only |
Abstract
Always-on intrusion detection is increasingly required on embedded and edge devices where connectivity, latency, or governance constraints limit cloud offloading. This Systematization of Knowledge (SoK) examines telemetry-aware, on-device network intrusion detection under resource constraints through a structured analysis of 102 peer-reviewed papers. We make four contributions. First, we develop a three-axis taxonomy spanning telemetry, actuation, and objective/constraint semantics. With inter-rater reliability on a 30-paper random sub-sample, this taxonomy shows that, within the scoped corpus and for the deployment target studied here, no paper jointly combines all three telemetry classes in a closed-loop adaptive IDS with shield-enforced step-wise safety invariants. Second, we audit 31 runtime-aware IDS papers and identify a recurring semantic mismatch: expectation-based mechanisms are often used for step-wise physical safety requirements, whose limitation we relate to CMDP LP-duality. Third, we present TQS-IDS, a corpus-grounded design synthesis organized around typed contracts I1–I4 that make explicit missing composition interfaces among shielding, safe RL, and TinyML building blocks. TQS-IDS is a design template and interface specification, not an implemented system or empirical validation. Fourth, we provide a reproducibility framework with device-class-tiered evaluation standards and an eight-item checklist for empirical follow-up. The corpus evidence recasts deployable on-device IDS as a composition problem centered on telemetry, constraint semantics, and runtime interfaces.
| Item ID: | 93132 |
|---|---|
| Item Type: | Conference Item (Research - E1) |
| ISBN: | 978-981-92-3018-1 |
| Keywords: | Systematization of Knowledge, Intrusion Detection, On-device and Edge Security, Runtime Assurance |
| Copyright Information: | © The Editor(s) (if applicable) and The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2026 |
| Date Deposited: | 05 Aug 2026 23:15 |
| FoR Codes: | 46 INFORMATION AND COMPUTING SCIENCES > 4604 Cybersecurity and privacy > 460499 Cybersecurity and privacy not elsewhere classified @ 100% |
| SEO Codes: | 22 INFORMATION AND COMMUNICATION SERVICES > 2204 Information systems, technologies and services > 220405 Cybersecurity @ 100% |
| Downloads: |
Total: 2 Last 12 Months: 2 |
| More Statistics |
