arXiv:2606.14987cs.CRcs.LG2026-06

IoT持续学习中存在隐蔽后门攻击,可长期潜伏并触发恶意行为。

Continual Backdoor Training in IoT/CPS

  • 针对物联网持续学习设计新型后门攻击,利用增量更新植入恶意逻辑。
  • 攻击在正常运行时保持静默,仅在特定触发条件下激活,难以检测。
  • 揭示工业物联网持续学习系统的安全短板,适合安全研究者参考。

物联网(IoT)与网络物理系统(CPS)日益依赖持续学习(CL)以适应动态环境、设备异构性及概念漂移,从而提升整体实用性。然而,持续适应虽必要,却也引入了新的安全漏洞。特别是,后门攻击可利用增量更新、回放缓冲区和表征复用,在持续学习流程中植入持久的恶意行为——这些行为在正常运行时保持沉默,仅在特定触发条件下激活。本文提出一种面向物联网/网络物理系统持续学习的后门攻击方法。为此,我们构建了适用于物联网/网络物理系统的威胁模型,分析了为何持续学习会加剧后门在物联网数据流中的持久性,并在不同条件下评估了该技术的有效性。分析揭示了在物联网/网络物理系统及工业物联网(IIoT)环境中实现终身学习安全的重大挑战,凸显了加强安全控制的迫切需求。

原文摘要 · Abstract (English)

Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility. While continual adaptation is essential for long-lived IoT deployments where data patterns evolve, it also introduces new security vulnerabilities. In particular, backdoor attacks can exploit incremental updates, replay buffers, and representation reuse to implant persistent malicious behaviors that remain dormant during normal operation but activate upon specific triggers. In this paper, we present a backdoor attack in continual learning used in IoT/CPS systems. To this end, we formalize an IoT/CPS-specific threat model, analyze why continual learning amplifies backdoor persistence in IoT pipelines, and evaluate our technique under varying conditions. Our analysis highlights critical open challenges in securing lifelong learning in IoT/CPS and industrial IoT (IIoT) environments, as well as the need for heightened security controls.

后门攻击持续学习物联网安全工业物联网

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。