错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SoK: Telemetry-Aware Runtime Assurance for Always-On On-device Intrusion Detection

  • Nuonan Ouyang,
  • Adrian Shatte,
  • Zhigang Lu,
  • Chao Chen,
  • Wei Xiang

摘要

Always-on intrusion detection is increasingly required on embedded and edge devices where connectivity, latency, or governance constraints limit cloud offloading. This Systematization of Knowledge (SoK) examines telemetry-aware, on-device network intrusion detection under resource constraints through a structured analysis of 102 peer-reviewed papers. We make four contributions. First, we develop a three-axis taxonomy spanning telemetry, actuation, and objective/constraint semantics. With inter-rater reliability \(\kappa \ge 0.70\) on a 30-paper random sub-sample, this taxonomy shows that, within the scoped corpus and for the deployment target studied here, no paper jointly combines all three telemetry classes in a closed-loop adaptive IDS with shield-enforced step-wise safety invariants. Second, we audit 31 runtime-aware IDS papers and identify a recurring semantic mismatch: expectation-based mechanisms are often used for step-wise physical safety requirements, whose limitation we relate to CMDP LP-duality. Third, we present TQS-IDS, a corpus-grounded design synthesis organized around typed contracts I1–I4 that make explicit missing composition interfaces among shielding, safe RL, and TinyML building blocks. TQS-IDS is a design template and interface specification, not an implemented system or empirical validation. Fourth, we provide a reproducibility framework with device-class-tiered evaluation standards and an eight-item checklist for empirical follow-up. The corpus evidence recasts deployable on-device IDS as a composition problem centered on telemetry, constraint semantics, and runtime interfaces.