Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Knowledge-driven cyber-physical anomaly exploration for smart homes

Alsufyani, Azhar 2026. Knowledge-driven cyber-physical anomaly exploration for smart homes. PhD Thesis, Cardiff University.
Item availability restricted.

[thumbnail of 2026alsufyaniaphd.pdf] PDF - Accepted Post-Print Version
Restricted to Repository staff only until 17 July 2027 due to copyright restrictions.
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (14MB) | Request a copy
[thumbnail of Cardiff University Electronic Publication Form] PDF (Cardiff University Electronic Publication Form) - Supplemental Material
Restricted to Repository staff only

Download (164kB) | Request a copy

Abstract

Smart-home systems are becoming a core part of modern buildings, integrating heterogeneous devices and networked services to monitor and manage physical environments. Yet, ensuring robust security in smart homes remains challenging because threats span both cyber and physical layers, and device behavior is highly contextual. Many existing defenses rely on data driven methods (e.g., machine/deep learning) that require large training datasets and often struggle to explain decisions or generalize across diverse home configurations. In contrast, knowledge-driven approaches aim to reason over device context, policies, and semantics, but remain underexplored and inconsistently evaluated. This research investigates the role of knowledge in smart-home security—how events can be understood, reasoned about, and used to support stronger detection and response. I synthesize the literature by proposing a taxonomy of security decision-making approaches, cataloging common vulnerabilities, attacks, and threats, analyzing countermeasures, and reviewing how smart-home security has been evaluated in prior work. I further identify key practical challenges that limit current solutions and motivate knowledge-driven schemes. To ground these findings in user needs and realistic operation, I adopted a mixed-method study combining quantitative and qualitative components. I collected preliminary perceptions via a questionnaire and then conducted focus-group interviews with 36 participants using interactive, scenario-based discussions. From these studies I derived artifacts including representative device setups and floor-plan configurations, a structured taxonomy of smart home security threats, and scenario examples illustrating how cyber–physical anomalies arise and how users expect them to be handled. These results informed a set of criteria for enabling collaborative anomaly exploration, emphasizing transparency, contextual reasoning, and practical response behaviors aligned with user expectations. Building on the identified challenges and user-driven requirements, I propose a context aware cyber–physical security framework that combines device-level MAPE-K control loops, a shared Brick-based semantic context, and capability-constrained collaborative planning using large language models (LLMs) for post-detection intelligence gathering. Devices make local decisions, coordinate with nearby peers, and use Brick as a common semantic substratefor cross-device grounding and safer action selection. I evaluate the framework through (i) a controlled prototype testbed using three representative use cases (door unauthorized access, drain spoofing, and camera DoS) and (ii) large-scale simulations across studio, apartment, and villa layouts. Across layouts, the full framework maintains stable detection performance (≈ 92.5–95.3% accuracy and ≈ 92.7–95.9% F1 with high precision), while reasoning latency increases with contextual complexity; end-to-end response time remains low and comparable across layouts. Compared with baselines, semantic and context-based methods remain strong in this workload, whereas an IDS-only baseline performs poorly due to very low recall, highlighting the need for semantic grounding in cyber–physical anomalies. Planning results show clear trade-offs among LLMs: faster models reduce latency but may sacrifice plan overlap, while higher-overlap models incur higher reasoning cost; fine-tuning improves output reliability but does not consistently improve accuracy. Finally, I discuss limitations and outline future directions for knowledge-driven smart-home security, including richer sensing fidelity, broader threat coverage, and more human-centered evaluation.

Item Type: Thesis (PhD)
Date Type: Completion
Status: Unpublished
Schools: Schools > Computer Science & Informatics
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Date of First Compliant Deposit: 17 July 2026
Date of Acceptance: 15 July 2027
Last Modified: 22 Jul 2026 14:38
URI: https://orca.cardiff.ac.uk/id/eprint/188290

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics