Detecting Rule Anomalies and Interference for Home Automation
Yuchen Zhao, Kai Dong, Lifu Wang, Jianjie Zhou, Zhen Ling, Ming Yang, Xinwen Fu
Abstract
Home Internet-of-Things (H-IoT) automation is increasingly threatened by single-rule anomalies (SRA) and cross-rule interference (CRI). These threats can produce outcomes diverging from or even contradicting user expectations, compromising H-IoT system security and potentially endangering user safety and property. Existing detection techniques for these threats are fundamentally limited as they overlook undocumented command side effects, creating a critical blind spot in security analysis. This paper introduces Cet-Miner, a method that obtains and models these side effects through black-box command testing. Cet-Miner models system behavior as a Bayesian-smoothed Markov Decision Process (MDP) to characterize the non-deterministic side effects. For side effects that are not immediately observable, it uncovers them by comparing semantic inferences with test results, and represents them via a latent state structure introduced into the MDP. Building on this method, we propose HA-Inspector, an end-to-end threat detection system that implements both a runtime SRA monitor and a CRI model checker. We evaluate our method and system on a real-world H-IoT testbed comprising 38 devices from 9 vendors. Results show Cet-Miner discovers 5 distinct types of side effects, and HA-Inspector outperforms state-of-the-art tools in detecting both SRA and CRI threats.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 19cc3f0e-6c8a-446d-9023-19ff420c8628Related papers
- CP-IoT: A Cross-Platform Monitoring System for Smart HomeHai Lin, Chenglong Li, Jiahai Yang, Zhiliang Wang et al.NDSS 2024
- HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart HomesChenglong Fu, Qiang Zeng, Xiaojiang DuUSENIX Security 2021 · 109 citations
- Temporal Specification Oriented Fuzzing for Trigger-Action-Programming Smart Home IntegrationsJinglin Dai, Yifan Xiong, Lezhi Ma, Shangqing Liu et al.ICSE 2026
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu et al.USENIX Security 2019 · 160 citations
- MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging ProtocolsQinying Wang, Shouling Ji, Yuan Tian, Xuhong Zhang et al.USENIX Security 2021 · 45 citations
