Federated Risk Learning for Adaptive Post-Quantum IoT Authentication
Abstract
Smart-home Internet of Things (IoT) security requires behavioral adaptation without exposing household traffic or weakening authentication during post-quantum migration. Existing work advances private learning, robust aggregation, and cryptographic authentication, but leaves open how uncertain device behavior should guide a certified key lifecycle. This work presents FALCON-SDIoT, a software-defined networking architecture that connects federated risk classification to authenticated rekeying. Manufacturer profiles guide initial classification, clipped and noised edge updates support collaborative learning, and temporal trust determines asymmetric hardening and relaxation. Certified key establishment and nonce-bound proof-of-possession bind these decisions to device credentials. This work integrates federated risk assignment, credential binding, and coordinated class and key transitions under explicit privacy and security assumptions. Evaluation covers a controlled synthetic benchmark, public-traffic temporal and complete-device holdouts, repeated-seed federated tests, and an adaptive-policy sensitivity study. Results support manufacturer-informed risk classification, characterize performance under adversarial updates, and demonstrate the trade-off between detection delay and false alarms. Public-traffic tests assess temporal classification and unseen-device detection. These findings support the component interfaces under the evaluated settings; cryptographic costs remain accounting estimates, and the recurring proof is assessed within a classical random-oracle scope. The architecture supports studying behavior-driven authentication while distinguishing predictive confidence from cryptographic assurance.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.