Tracing and verifying data flows in IoT systems to detect anomalies, ensure accountability, and improve transparency in resource-constrained environments.
Data provenance — the ability to trace the origin and history of data as it moves through a system — is a powerful tool for security and accountability. In cyber-physical systems (CPS) and IoT environments, where devices are often resource-constrained and interconnected, provenance tracking introduces unique challenges.
My doctoral work established trace-based provenance collection frameworks for IoT devices, enabling lightweight capture of data flow information even on embedded systems with limited memory and processing power.
By modeling provenance as graphs, we can apply anomaly detection algorithms to identify unusual data flows that may indicate compromise, misconfiguration, or attack — providing a fundamentally new lens for CPS security that complements traditional signature-based approaches.