SoK: Telemetry-Aware Runtime Assurance for Always-On On-device Intrusion Detection

Ouyang, Nuonan, Shatte, Adrian, Lu, Zhigang, Chen, Chao, and Xiang, Wei (2026) SoK: Telemetry-Aware Runtime Assurance for Always-On On-device Intrusion Detection. In: Lecture Notes in Computer Science (16794) pp. 163-183. From: ACISP 2026: 31st Australasian Conference on Information Security and Privacy, 6-9 July 2026, Perth, WA, Australia.

[img] PDF (Publisher Accepted Version) - Accepted Version
Restricted to Repository staff only

View at Publisher Website: https://doi.org/10.1007/978-981-92-3018-...
 
2


Abstract

Always-on intrusion detection is increasingly required on embedded and edge devices where connectivity, latency, or governance constraints limit cloud offloading. This Systematization of Knowledge (SoK) examines telemetry-aware, on-device network intrusion detection under resource constraints through a structured analysis of 102 peer-reviewed papers. We make four contributions. First, we develop a three-axis taxonomy spanning telemetry, actuation, and objective/constraint semantics. With inter-rater reliability on a 30-paper random sub-sample, this taxonomy shows that, within the scoped corpus and for the deployment target studied here, no paper jointly combines all three telemetry classes in a closed-loop adaptive IDS with shield-enforced step-wise safety invariants. Second, we audit 31 runtime-aware IDS papers and identify a recurring semantic mismatch: expectation-based mechanisms are often used for step-wise physical safety requirements, whose limitation we relate to CMDP LP-duality. Third, we present TQS-IDS, a corpus-grounded design synthesis organized around typed contracts I1–I4 that make explicit missing composition interfaces among shielding, safe RL, and TinyML building blocks. TQS-IDS is a design template and interface specification, not an implemented system or empirical validation. Fourth, we provide a reproducibility framework with device-class-tiered evaluation standards and an eight-item checklist for empirical follow-up. The corpus evidence recasts deployable on-device IDS as a composition problem centered on telemetry, constraint semantics, and runtime interfaces.

Item ID: 93132
Item Type: Conference Item (Research - E1)
ISBN: 978-981-92-3018-1
Keywords: Systematization of Knowledge, Intrusion Detection, On-device and Edge Security, Runtime Assurance
Copyright Information: © The Editor(s) (if applicable) and The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2026
Date Deposited: 05 Aug 2026 23:15
FoR Codes: 46 INFORMATION AND COMPUTING SCIENCES > 4604 Cybersecurity and privacy > 460499 Cybersecurity and privacy not elsewhere classified @ 100%
SEO Codes: 22 INFORMATION AND COMMUNICATION SERVICES > 2204 Information systems, technologies and services > 220405 Cybersecurity @ 100%
Downloads: Total: 2
Last 12 Months: 2
More Statistics

Actions (Repository Staff Only)

Item Control Page Item Control Page