Closing the Loop in Embedded Security: Evolution of an AIOps Framework for Threat Hunting
Authors/Creators
Description
As the 6G and IoT eras usher in a massive deployment of bare-metal embedded devices, securing resourceconstrained hardware like the ARM Cortex-M4 remains a critical challenge. Without the protection layers of a traditional operating system, these devices are uniquely susceptible to buffer overflows and memory corruption via standard C library functions (e.g., memcpy, strncat). While AI has emerged as a powerful tool for detecting these vulnerabilities via side-channel data like power and instruction traces, the operational challenge lies in the lifecycle management of these models.
This paper presents an AIMLOps-driven approach to embedded security, using detection of vulnerable library functions to demonstrate AI pipeline evolution. We move beyond "one-off" model training to explore how an integrated MLOps framework enables sophisticated data analytics for high-frequency timeseries and real-time execution traces previously inaccessible to security operators. We detail the transition from manual feature engineering to autonomous pipeline stages: data ingestion from hardware probes, model validation for edge deployment, and continuous adaptation to windowing size and sampling frequency. Results show that treating the security model as an evolving asset within a managed lifecycle achieves high detection accuracy and robustness for zero-day vulnerability detection. This work provides a blueprint for managing AI workloads in embedded system time-series telemetry.
Files
Closing the Loop in Embedded Security Evolution of an AIOps Framework for Threat Hunting.pdf
Files
(3.4 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:2d364a9fe7fffc0be479061e5cfe7244
|
3.4 MB | Preview Download |