Selvam, Muthupavithran and Haque, Safwana and Singh, Amit Kumar and Cui, Zhan and Muttukrishnan, Rajarajan (2026) Device Behavioural Blueprint (DB²): A Risk-Aware Framework for Unique Device Behaviour Profiling Using Microarchitectural Variations. Journal of Network and Computer Applications. (In Press)
Selvam, Muthupavithran and Haque, Safwana and Singh, Amit Kumar and Cui, Zhan and Muttukrishnan, Rajarajan (2026) Device Behavioural Blueprint (DB²): A Risk-Aware Framework for Unique Device Behaviour Profiling Using Microarchitectural Variations. Journal of Network and Computer Applications. (In Press)
Selvam, Muthupavithran and Haque, Safwana and Singh, Amit Kumar and Cui, Zhan and Muttukrishnan, Rajarajan (2026) Device Behavioural Blueprint (DB²): A Risk-Aware Framework for Unique Device Behaviour Profiling Using Microarchitectural Variations. Journal of Network and Computer Applications. (In Press)
Abstract
This paper introduces DB², a risk-aware behavioural identity framework that derives device identity from CPU–RTC timing deviation and Performance Monitoring Unit (PMU) microarchitectural events, without relying on GPUs, radios, sensors, or dedicated hardware. The method captures oscillator-coupled timing variation and execution behaviour through a structured signal-processing pipeline, producing device-specific behavioural signatures that remain distinguishable across reboots, temperature variation, and core transitions. DB² structures identity assurance into three layers: closed-set identification, calibrated open-set rejection, and stability-aware risk scoring. Evaluation under a strict three-way split with reboot separation for training, calibration, and unseen testing yields a macro-F₁ of 0.957 on unseen reboots. The open-set layer rejects previously unseen devices with a mean true-positive rate of 0.990 at a calibrated event-level false-reject rate of approximately 0.08 under strict leave-one-device-out validation, with operating-point selection performed exclusively on the calibration split. A Dynamic-Aware Identification and Risk (DAIR) mechanism decomposes behavioural stability across temperature, reboot, and core factors to provide interpretable posture monitoring for enrolled devices. Under identity-claim manipulation via spoofing, Sybil, and relabelling scenarios involving cloning, targeted identities exhibit reduced identification consistency and elevated risk, while non-targeted devices remain stable under identical calibration settings. These results show that behavioural fingerprints can be derived from standard CPU, RTC, and PMU-accessible resources on edge devices, enabling device-identity and behavioural-assurance monitoring in IoT and edge environments without specialised hardware.
| Item Type: | Article |
|---|---|
| Uncontrolled Keywords: | Device Fingerprinting; Microarchitectural Behaviour; CPU–RTC Timing Drift; PMU-Based Identification; Closed-Set Identification; Open-Set Recognition; DAIR Risk Scoring; Edge Device Security |
| Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
| SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
| Depositing User: | Unnamed user with email elements@essex.ac.uk |
| Date Deposited: | 12 Jun 2026 10:41 |
| Last Modified: | 12 Jun 2026 13:21 |
| URI: | http://repository.essex.ac.uk/id/eprint/43339 |
Available files
Filename: Device_Behavioural_Blueprint_DB2___A_Risk_Aware_Framework_for_Unique_Device_Behaviour_Profiling__Using_Microarchitectural_Variations_Revised_v1-accepted.pdf
Embargo Date: 1 January 2100