arXiv:2507.03064cs.CRcs.AI2025-07被引 4

用大模型自动配置临时物联网设备,实现安全无缝协作

LLM-Driven Auto Configuration for Transient IoT Device Collaboration

  • 用大模型将用户意图转为细粒度访问控制策略
  • 设备配置仅需约150毫秒,开销低至0.3毫秒
  • 适合非专家用户在临时环境中快速部署设备

当前物联网已从简单的传感执行设备演变为具备嵌入式处理和智能服务的设备,支持用户与设备间丰富协作。然而,在临时访问环境中,瞬时设备与宿主设备交互时,精细访问控制策略对保障安全至关重要,但手动配置对非专家用户不现实。系统需在运行时自动配置设备并强制执行细粒度访问控制规则,同时应对设备异构性问题。本文提出CollabIoT系统,支持瞬时物联网环境中的安全无缝设备协作。CollabIoT采用大语言模型(LLM)驱动方法,将用户高层意图转化为细粒度访问控制策略。为实现安全协作,系统采用基于能力的授权机制,并使用轻量级代理进行策略执行,提供硬件无关抽象。我们实现了CollabIoT的策略生成与自动配置原型,并在物联网测试床及大规模模拟环境中评估其有效性。结果表明,我们的LLM策略生成管道可100%准确生成功能正确策略。运行时评估显示,新设备配置耗时约150毫秒,代理数据平面网络开销最高2毫秒,访问控制开销最高0.3毫秒。

原文摘要 · Abstract (English)

Today's Internet of Things (IoT) has evolved from simple sensing and actuation devices to those with embedded processing and intelligent services, enabling rich collaborations between users and their devices. However, enabling such collaboration becomes challenging when transient devices need to interact with host devices in temporarily visited environments. In such cases, fine-grained access control policies are necessary to ensure secure interactions; however, manually implementing them is often impractical for non-expert users. Moreover, at run-time, the system must automatically configure the devices and enforce such fine-grained access control rules. Additionally, the system must address the heterogeneity of devices. In this paper, we present CollabIoT, a system that enables secure and seamless device collaboration in transient IoT environments. CollabIoT employs a Large language Model (LLM)-driven approach to convert users' high-level intents to fine-grained access control policies. To support secure and seamless device collaboration, CollabIoT adopts capability-based access control for authorization and uses lightweight proxies for policy enforcement, providing hardware-independent abstractions. We implement a prototype of CollabIoT's policy generation and auto configuration pipelines and evaluate its efficacy on an IoT testbed and in large-scale emulated environments. We show that our LLM-based policy generation pipeline is able to generate functional and correct policies with 100% accuracy. At runtime, our evaluation shows that our system configures new devices in ~150 ms, and our proxy-based data plane incurs network overheads of up to 2 ms and access control overheads up to 0.3 ms.

物联网大模型访问控制自动配置

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。