Knowledge-driven Cyber-Physical Anomaly Exploration for Smart Homes

No Thumbnail Available

Date

2026

Journal Title

Journal ISSN

Volume Title

Publisher

Saudi Digital Library

Abstract

Smart-home systems are becoming a core part of modern buildings, integrating heterogeneous devices and networked services to monitor and manage physical environments. Yet, ensuring robust security in smart homes remains challenging because threats span both cyber and physical layers, and device behavior is highly contextual. Many existing defenses rely on data driven methods (e.g., machine/deep learning) that require large training datasets and often struggle to explain decisions or generalize across diverse home configurations. In contrast, knowledge-driven approaches aim to reason over device context, policies, and semantics, but remain underexplored and inconsistently evaluated. This research investigates the role of knowledge in smart-home security—how events can be understood, reasoned about, and used to support stronger detection and response. I synthesize the literature by proposing a taxonomy of security decision-making approaches, cataloging common vulnerabilities, attacks, and threats, analyzing countermeasures, and reviewing how smart-home security has been evaluated in prior work. I further identify key practical challenges that limit current solutions and motivate knowledge-driven schemes. To ground these findings in user needs and realistic operation, I adopted a mixed-method study combining quantitative and qualitative components. I collected preliminary perceptions via a questionnaire and then conducted focus-group interviews with 36 participants using interactive, scenario-based discussions. From these studies I derived artifacts including representative device setups and floor-plan configurations, a structured taxonomy of smar-thome security threats, and scenario examples illustrating how cyber–physical anomalies arise and how users expect them to be handled. These results informed a set of criteria for enabling collaborative anomaly exploration, emphasizing transparency, contextual reasoning, and practical response behaviors aligned with user expectations. Building on the identified challenges and user-driven requirements, I propose a context-aware cyber–physical security framework that combines device-level MAPE-K control loops, a shared Brick-based semantic context, and capability-constrained collaborative planning using large language models (LLMs) for post-detection intelligence gathering. Devices make local decisions, coordinate with nearby peers, and use Brick as a common semantic substrate for cross-device grounding and safer action selection. I evaluate the framework through (i) a controlled prototype testbed using three representative use cases (door unauthorized access, drain spoofing, and camera DoS) and (ii) large-scale simulations across studio, apartment, and villa layouts. Across layouts, the full framework maintains stable detection performance (≈92.5–95.3% accuracy and ≈92.7–95.9% F1 with high precision), while reasoning latency increases with contextual complexity; end-to-end response time remains low and comparable across layouts. Compared with baselines, semantic and context-based methods remain strong in this workload, whereas an IDS-only baseline performs poorly due to very low recall, highlighting the need for semantic grounding in cyber–physical anomalies. Planning results show clear trade-offs among LLMs: faster models reduce latency but may sacrifice plan overlap, while higher-overlap models incur higher reasoning cost; fine-tuning improves output reliability but does not consistently improve accuracy. Finally, I discuss limitations and outline future directions for knowledge-driven smart-home security, including richer sensing fidelity, broader threat coverage, and more human-centered evaluation.

Description

Keywords

Smart Homes, Knoweldge, Cyber-Physical Security

Citation

Endorsement

Review

Supplemented By

Referenced By

Copyright owned by the Saudi Digital Library (SDL) © 2026