GRIOT-FENCE: Multi-View Adaptive Intrusion Detection for Trustworthy Consumer IoT Cyber Threat Analysis
Muhammad Faisal Shafiq, Penghui Li, Lihua Yin, Nada Abdulaziz Alasbali, Mohammad Mahtab Alam · IEEE Transactions on Consumer Electronics · 2025
The rapid proliferation of consumer IoT applications has embedded interconnected devices into daily life, creating highly dynamic and heterogeneous environments that pose significant security challenges. Diverse devices, protocols, and user-driven interactions complicate cyber threat analysis, while existing deep learning methods struggle with single-view models that fail to capture comprehensive behavioral patterns and multi-view approaches that suffer from ineffective feature fusion, leading to low generalization in dynamic scenarios. To address the problem, a novel technique named GRIOT-FENCE is first proposed. Then, based on GRIOT-FENCE, a new algorithm named DYNAMO-IoT is developed and designed. GRIOT-FENCE conducts comprehensive cyber threat analysis by modeling structural interactions, temporal dynamics, and statistical characteristics of network traffic across diverse consumer IoT devices, enhancing data security through robust threat detection. Its context-aware fusion module, FUSCONET, dynamically weights predictions based on device roles and network conditions, improving threat analysis transparency by highlighting critical behavioral features. The DYNAMO-IoT algorithm continuously monitors performance and triggers lightweight retraining of the fusion layer, ensuring adaptability to evolving cyber threats with minimal computational overhead, suitable for resource-constrained consumer environments. Experimental results demonstrate that GRIOT-FENCE achieves superior detection accuracy and robust threat analysis compared to state-of-the-art methods on benchmark IoT datasets, safeguarding consumer IoT applications and enhancing their trustworthiness through improved data security, system reliability, and transparent threat insights.