Towards Enhancing Device Anonymity and Classification Resistance in IoT
Lalith Medury, Uday Kiran Kothapalli, Farah I. Kandah · 2025
IoT devices produce predictable communication patterns tied to their specific functionalities, such as repetitive sequences in packet lengths, protocols, and port usage. These distinct communication signatures enable the training of machine learning classifiers to accurately identify devices, classify events, and even infer user activities. However, such profiling techniques raise significant privacy concerns for both users and devices. Existing research aimed at protecting the privacy of IoT devices and their users has primarily focused on mitigating threats posed by external adversaries. Techniques such as traffic padding, shaping, and cover traffic injection have been effective in scenarios where the adversary can only observe encrypted WPA traffic. However, these methods offer limited protection against a local adversary capable of decrypting WPA traffic and employing advanced profiling techniques to identify devices and activities. To address this gap, we propose ProTOF, a protocol-based obfuscation framework designed to enhance the privacy of IoT devices and users against local adversaries. ProTOF mitigates device identification by crafting protocol-specific packets that mimic the traffic patterns of other devices. By leveraging data analysis and packet statistics, the framework injects obfuscated network packets to confuse machine learning classifiers. Experimental results demonstrate that ProTOF can serve as an effective self-protection mechanism, significantly reducing device identification accuracy from 95% to 31%. This is achieved without introducing transmission delays and with minimal bandwidth overhead, amounting to just 12 MB per day. Compared to existing privacy-preserving solutions, ProTOF excels in reducing classifier accuracy while maintaining competitive performance in terms of bandwidth overhead and entropy difference. This makes it a robust and efficient solution for safeguarding IoT devices and user privacy in the face of increasingly sophisticated local adversaries.