Hardware Anomaly Detection in Microcontrollers Through Watchdog-Assisted Property Enforcement
Maksym Melnyk, Jacob K. Kandathil Thomas, Max Wandera, Ajesh Koyatan Chathoth, Michael Zuzak · 2025
The development of anomaly detection and trust mechanisms for low-end microcontroller units (MCUs) has received substantial attention. Prior approaches generally explore either hardware or co-design-based security techniques to secure low-end devices. However, in some cases, the necessary hardware support is more expensive than the MCU itself, rendering these approaches infeasible in some applications. In this work, we propose a novel security mechanism that adapts prior custom-hardware-assisted trust mechanisms to leverage only standard on-chip hardware for anomaly detection and trust in low-end MCUs. Specifically, we propose a runtime security property enforcement mechanism that periodically checks user-defined security properties to detect anomalous behavior using hardware watchdog (HWD) timers. Since HWD timers are standard in most low-end microprocessors, no additional hardware modifications are necessary. For evaluation, we implemented the proposed anomaly detection framework in an ARM Cortex-M4 device. A set of 11 MITRE Common Weakness Enumeration (CWE) benchmarks were implemented and executed on the MCU to evaluate the approach. All benchmarks were detected within 40ms, with a corresponding memory overhead of 5.1kB and performance overhead of less than 0.1%, highlighting the detector's practicality and low overhead.