{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:17:34Z","timestamp":1784996254315,"version":"3.55.0"},"reference-count":47,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,2,12]],"date-time":"2025-02-12T00:00:00Z","timestamp":1739318400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100012331","name":"VLAIO","doi-asserted-by":"publisher","award":["HBC.2021.089"],"award-info":[{"award-number":["HBC.2021.089"]}],"id":[{"id":"10.13039\/100012331","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012331","name":"VLAIO","doi-asserted-by":"publisher","award":["VOEWICS02"],"award-info":[{"award-number":["VOEWICS02"]}],"id":[{"id":"10.13039\/100012331","id-type":"DOI","asserted-by":"publisher"}]},{"name":"COST Action CA22104 Beingwise","award":["HBC.2021.089"],"award-info":[{"award-number":["HBC.2021.089"]}]},{"name":"COST Action CA22104 Beingwise","award":["VOEWICS02"],"award-info":[{"award-number":["VOEWICS02"]}]},{"name":"Cybersecurity Research Program Flanders-second cycle","award":["HBC.2021.089"],"award-info":[{"award-number":["HBC.2021.089"]}]},{"name":"Cybersecurity Research Program Flanders-second cycle","award":["VOEWICS02"],"award-info":[{"award-number":["VOEWICS02"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Emerging edge devices are transforming the Internet of Things (IoT) by enabling more responsive and efficient interactions between physical objects and digital networks. These devices support diverse applications, from health-monitoring wearables to environmental sensors, by moving data processing closer to the source. Traditional IoT systems rely heavily on centralized servers, but advances in edge computing and Tiny Machine Learning (TinyML) now allow for on-device processing, enhancing battery efficiency and reducing latency. While this shift improves privacy, the distributed nature of edge devices introduces new security challenges, particularly regarding TinyML models, which are designed for low-power environments and may be vulnerable to tampering or unauthorized access. Since other IoT entities depend on the data generated by these models, ensuring trust in the devices is essential. To address this, we propose a lightweight dual attestation mechanism utilizing Entity Attestation Tokens (EATs) to validate the device and ML model integrity. This approach enhances security by enabling verified device-to-device communication, supports seamless integration with secure cloud services, and allows for flexible, authorized ML model updates, meeting modern IoT systems\u2019 scalability and compliance needs.<\/jats:p>","DOI":"10.3390\/fi17020085","type":"journal-article","created":{"date-parts":[[2025,2,12]],"date-time":"2025-02-12T12:12:16Z","timestamp":1739362336000},"page":"85","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Secure Tiny Machine Learning on Edge Devices: A Lightweight Dual Attestation Mechanism for Machine Learning"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7151-1236","authenticated-orcid":false,"given":"Vlad-Eusebiu","family":"Baciu","sequence":"first","affiliation":[{"name":"Department of Electronics and Informatics (ETRO), Vrije Universiteit Brussel (VUB), 1050 Brussels, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9965-915X","authenticated-orcid":false,"given":"An","family":"Braeken","sequence":"additional","affiliation":[{"name":"Department of Electronics and Informatics (ETRO), Vrije Universiteit Brussel (VUB), 1050 Brussels, Belgium"},{"name":"Department of Engineering Technology (INDI), Vrije Universiteit Brussel (VUB), 1050 Brussels, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6071-0026","authenticated-orcid":false,"given":"Laurent","family":"Segers","sequence":"additional","affiliation":[{"name":"Department of Electronics and Informatics (ETRO), Vrije Universiteit Brussel (VUB), 1050 Brussels, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4877-9688","authenticated-orcid":false,"given":"Bruno da","family":"Silva","sequence":"additional","affiliation":[{"name":"Department of Electronics and Informatics (ETRO), Vrije Universiteit Brussel (VUB), 1050 Brussels, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,2,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Mikhaylov, D., Polonelli, T., and Magno, M. (2024, January 23\u201325). On-Sensor TinyML Event-Based Fault Detection Strategies on Wind Turbine Blades. Proceedings of the 2024 IEEE Sensors Applications Symposium (SAS), Naples, Italy.","DOI":"10.1109\/SAS60918.2024.10636542"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Gkogkidis, A., Tsoukas, V., Papafotikas, S., Boumpa, E., and Kakarountas, A. (2022, January 8\u201310). A TinyML-based system for gas leakage detection. Proceedings of the 2022 11th International Conference on Modern Circuits and Systems Technologies (MOCAST), Bremen, Germany.","DOI":"10.1109\/MOCAST54814.2022.9837510"},{"key":"ref_3","unstructured":"Huckelberry, J., Zhang, Y., Sansone, A., Mickens, J., Beerel, P.A., and Reddi, V.J. (2024). TinyML Security: Exploring Vulnerabilities in Resource-Constrained Machine Learning Systems. arXiv."},{"key":"ref_4","unstructured":"(2024, November 21). Confidential Computing Consortium. Confidential Computing: Outreach Whitepaper. Available online: https:\/\/confidentialcomputing.io\/wp-content\/uploads\/sites\/10\/2023\/03\/CCC_outreach_whitepaper_updated_November_2022.pdf."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Segers, L., Talebi, B., da Silva, B., Touhafi, A., and Braeken, A. (2024). Trustworthy Environmental Monitoring Using Hardware-Assisted Security Mechanisms. Sensors, 24.","DOI":"10.3390\/s24144720"},{"key":"ref_6","unstructured":"Costan, V. Intel SGX explained. IACR Cryptol EPrint Arch. Paper 2016\/086, 1\u2013118."},{"key":"ref_7","first-page":"1450","article-title":"Strengthening VM isolation with integrity protection and more","volume":"53","year":"2020","journal-title":"White Pap. January"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3291047","article-title":"Demystifying arm trustzone: A comprehensive survey","volume":"51","author":"Pinto","year":"2019","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_9","unstructured":"Cheang, K., Rasmussen, C., Lee, D., Kohlbrenner, D.W., Asanovi\u0107, K., and Seshia, S.A. (2022). Verifying RISC-V physical memory protection. arXiv."},{"key":"ref_10","unstructured":"(2024, November 18). Confidential Computing Consortium. Common Terminology for Confidential Computing. Available online: https:\/\/confidentialcomputing.io\/wp-content\/uploads\/sites\/10\/2023\/03\/Common-Terminology-for-Confidential-Computing.pdf."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Birkholz, H., Thaler, D., Richardson, M., Smith, N., and Pan, W. (2023). Remote attestation procedures (RATS) architecture. RFC 9334.","DOI":"10.17487\/RFC9334"},{"key":"ref_12","unstructured":"Weidner, J. (2024, December 19). ARM Confidential Compute Architecture. Available online: https:\/\/sys.cs.fau.de\/extern\/lehre\/ws22\/akss\/material\/arm-cca.pdf."},{"key":"ref_13","unstructured":"(2024, November 23). Trusted Firmware-M Documentation. Available online: https:\/\/trustedfirmware-m.readthedocs.io\/en\/latest\/index.html."},{"key":"ref_14","unstructured":"(2024, November 23). Silicon Labs Gecko Platform: Secure Element Manager API Documentation. Available online: https:\/\/docs.silabs.com\/gecko-platform\/3.0\/service\/api\/group-sl-se-manager."},{"key":"ref_15","unstructured":"(2024, November 23). STM32 MCU Secure Manager Documentation. Available online: https:\/\/www.st.com\/resource\/en\/user_manual\/um3254-secure-manager-for-stm32h573xx-microcontrollers-stmicroelectronics.pdf."},{"key":"ref_16","unstructured":"Asokan, N., Brasser, F., Ibrahim, A., Sadeghi, A.R., Schunter, M., Tsudik, G., and Wachsmann, C. (2015, January 12\u201316). Seda: Scalable embedded device attestation. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"102189","DOI":"10.1016\/j.inffus.2023.102189","article-title":"Federated learning for IoT devices: Enhancing TinyML with on-board training","volume":"104","author":"Ficco","year":"2024","journal-title":"Inf. Fusion"},{"key":"ref_18","unstructured":"Lundblade, L., Mandyam, G., O\u2019Donoghue, J., and Wallace, C. (2024, November 23). The Entity Attestation Token (EAT). Available online: https:\/\/www.ietf.org\/archive\/id\/draft-ietf-rats-eat-11.html."},{"key":"ref_19","unstructured":"Schaad, J. (2024, November 23). Cbor object Signing and Encryption (COSE). Technical Report. Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8152."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1007\/s43926-023-00045-2","article-title":"A survey on IoT & embedded device firmware security: Architecture, extraction techniques, and vulnerability analysis frameworks","volume":"3","author":"Singh","year":"2023","journal-title":"Discov. Internet Things"},{"key":"ref_21","unstructured":"Costin, A., Zaddach, J., Francillon, A., and Balzarotti, D. (2014, January 20\u201322). A Large-scale analysis of the security of embedded firmwares. Proceedings of the 23rd USENIX security symposium (USENIX Security 14), San Diego, CA, USA."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Ankerg\u00e5rd, S.F.J.J., Dushku, E., and Dragoni, N. (2021). State-of-the-art software-based remote attestation: Opportunities and open issues for Internet of Things. Sensors, 21.","DOI":"10.3390\/s21051598"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Kohnh\u00e4user, F., B\u00fcscher, N., and Katzenbeisser, S. (2019, January 17\u201319). A practical attestation protocol for autonomous embedded systems. Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden.","DOI":"10.1109\/EuroSP.2019.00028"},{"key":"ref_24","unstructured":"Eldefrawy, K., Tsudik, G., Francillon, A., and Perito, D. (2012, January 5\u20138). Smart: Secure and minimal architecture for (establishing dynamic) root of trust. Proceedings of the NDSS, San Diego, CA, USA."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Koeberl, P., Schulz, S., Sadeghi, A.R., and Varadharajan, V. (2014, January 14\u201316). TrustLite: A security architecture for tiny embedded devices. Proceedings of the Ninth European Conference on Computer Systems, Amsterdam, The Netherlands.","DOI":"10.1145\/2592798.2592824"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"102240","DOI":"10.1016\/j.sysarc.2021.102240","article-title":"Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes","volume":"119","author":"Ling","year":"2021","journal-title":"J. Syst. Archit."},{"key":"ref_27","unstructured":"Ott, S., Kamhuber, M., Pecholt, J., and Wessel, S. (September, January 29). Universal Remote Attestation for Cloud and Edge Platforms. Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento, Italy."},{"key":"ref_28","unstructured":"Ferro, L., and Lioy, A. (2024, January 9\u201311). Standard-Based Remote Attestation: The Veraison Project. Proceedings of the Italian Conference on Cybersecurity (ITASEC 2024), CEUR-WS, Salerno, Italy."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Siby, S., Abdollahi, S., Maheri, M., Kogias, M., and Haddadi, H. (2024, January 22). GuaranTEE: Towards Attestable and Private ML with CCA. Proceedings of the 4th Workshop on Machine Learning and Systems, Athens, Greece.","DOI":"10.1145\/3642970.3655845"},{"key":"ref_30","unstructured":"Jones, M., Camarillo, G., and Bormann, C. (2024, December 24). CBOR Web Token (CWT). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8392.html."},{"key":"ref_31","unstructured":"Internet Assigned Numbers Authority (IANA) (2024, December 24). JSON Web Token (JWT) Claims Registry. Available online: https:\/\/www.iana.org\/assignments\/jwt\/jwt.xhtml."},{"key":"ref_32","unstructured":"Bormann, C., and Hoffman, P. (2024, December 24). Concise Binary Object Representation (CBOR). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8949.html."},{"key":"ref_33","unstructured":"Internet Assigned Numbers Authority (IANA) (2024). CWT (CBOR Web Token) Parameters, IANA. Available online: https:\/\/www.iana.org\/assignments\/cbor-tags\/cbor-tags.xhtml."},{"key":"ref_34","unstructured":"Tschofenig, H., Smith, N., Frost, S., and Fuchs, A. (2024, December 20). Attestation Token for PSA. Internet-Draft draft-tschofenig-rats-psa-token-05. Available online: https:\/\/datatracker.ietf.org\/doc\/html\/draft-tschofenig-rats-psa-token-05."},{"key":"ref_35","unstructured":"O\u2019Donoghue, J. (2019). Towards Lightweight and Interoperable Trust Models: The Entity Attestation Token, The Institute of Engineering and Technology."},{"key":"ref_36","unstructured":"Internet Assigned Numbers Authority (IANA) (2024). COSE (Concise Binary Object Representation) Parameters, IANA. Available online: https:\/\/www.iana.org\/assignments\/cose\/cose.xhtml."},{"key":"ref_37","unstructured":"STMicroelectronics (2024, December 24). Discovery Kit with STM32H573II MCU. Available online: https:\/\/www.st.com\/resource\/en\/user_manual\/um3143-discovery-kit-with-stm32h573ii-mcu-stmicroelectronics.pdf."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"103262","DOI":"10.1016\/j.sysarc.2024.103262","article-title":"MLino bench: A comprehensive benchmarking tool for evaluating ML models on edge devices","volume":"155","author":"Baciu","year":"2024","journal-title":"J. Syst. Archit."},{"key":"ref_39","unstructured":"David, R., Duke, J., Jain, A., Reddi, V., Jeffries, N., Li, J., Kreeger, N., Nappier, I., Natraj, M., and Regev, S. (2020). Tensorflow lite micro: Embedded machine learning on tinyml systems. arXiv."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Tanabe, R., Purohit, H., Dohi, K., Endo, T., Nikaido, Y., Nakamura, T., and Kawaguchi, Y. (2021, January 17\u201320). MIMII DUE: Sound dataset for malfunctioning industrial machine investigation and inspection with domain shifts due to changes in operational and environmental conditions. Proceedings of the 2021 IEEE Workshop on Applications of Signal Processing to Audio and Acoustics (WASPAA), New Paltz, NY, USA.","DOI":"10.1109\/WASPAA52581.2021.9632802"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Purohit, H., Tanabe, R., Ichige, K., Endo, T., Nikaido, Y., Suefusa, K., and Kawaguchi, Y. (2019). MIMII Dataset: Sound dataset for malfunctioning industrial machine investigation and inspection. arXiv.","DOI":"10.33682\/m76f-d618"},{"key":"ref_42","unstructured":"Banbury, C., Reddi, V.J., Torelli, P., Holleman, J., Jeffries, N., Kiraly, C., Montino, P., Kanter, D., Ahmed, S., and Pau, D. (2021). Mlperf tiny benchmark. arXiv."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Novac, P.E., Boukli Hacene, G., Pegatoquet, A., Miramond, B., and Gripon, V. (2021). Quantization and deployment of deep neural networks on microcontrollers. Sensors, 21.","DOI":"10.3390\/s21092984"},{"key":"ref_44","unstructured":"(2024, December 22). tflite-find-arena-size. Available online: https:\/\/github.com\/Kanaderu\/tflite-find-arena-size."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"1394","DOI":"10.1016\/j.sysarc.2013.09.008","article-title":"Measurement-based research on cryptographic algorithms for embedded real-time systems","volume":"59","author":"Jiang","year":"2013","journal-title":"J. Syst. Archit."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Llisterri Gim\u00e9nez, N., Monfort Grau, M., Pueyo Centelles, R., and Freitag, F. (2022). On-device training of machine learning models on microcontrollers with federated learning. Electronics, 11.","DOI":"10.3390\/electronics11040573"},{"key":"ref_47","unstructured":"Trusted Computing Group (2020). DICE Attestation Architecture, Trusted Computing Group. Available online: https:\/\/trustedcomputinggroup.org\/wp-content\/uploads\/DICE-Attestation-Architecture-Version-1.1-Revision-18_pub.pdf."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/2\/85\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T16:32:10Z","timestamp":1760027530000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/2\/85"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,12]]},"references-count":47,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,2]]}},"alternative-id":["fi17020085"],"URL":"https:\/\/doi.org\/10.3390\/fi17020085","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,12]]}}}