{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T19:13:21Z","timestamp":1777662801959,"version":"3.51.4"},"reference-count":51,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T00:00:00Z","timestamp":1767830400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>LoRaWAN is widely used for IoT environmental monitoring, but its lightweight security mechanisms leave the physical layer vulnerable to availability attacks such as jamming and battery-depletion. These risks are particularly critical in mission-critical environmental monitoring systems. This paper proposes a multi-attribute physical-layer authentication (PLA) framework that supports uplink legitimacy assessment by jointly exploiting radio, energy, and temporal attributes, specifically RSSI, altitude, battery_level, battery_drop_speed, event_step, and time_rank. Using publicly available Brno LoRaWAN traces, we construct a device-aware semi-synthetic dataset comprising 230,296 records from 1921 devices over 13.68 days, augmented with energy, spatial, and temporal attributes and injected with controlled jamming and battery-depletion anomalies. Five classifiers (Random Forest, Multi-Layer Perceptron, XGBoost, Logistic Regression, and K-Nearest Neighbours) are evaluated using accuracy, precision, recall, F1-score, and AUC-ROC. The Multi-Layer Perceptron achieves the strongest detection performance (F1-score = 0.8260, AUC-ROC = 0.8953), with Random Forest performing comparably. Deployment-oriented computational profiling shows that lightweight models such as Logistic Regression and the MLP achieve near-instantaneous prediction latency (below 2 \u00b5s per sample) with minimal CPU overhead, while tree-based models incur higher training and storage costs but remain feasible for Network Server-side deployment.<\/jats:p>","DOI":"10.3390\/fi18010038","type":"journal-article","created":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T12:56:55Z","timestamp":1767877015000},"page":"38","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Multi-Attribute Physical-Layer Authentication Against Jamming and Battery-Depletion Attacks in LoRaWAN"],"prefix":"10.3390","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2294-7539","authenticated-orcid":false,"given":"Azita","family":"Pourghasem","sequence":"first","affiliation":[{"name":"Cybersecurity and Computing Systems Research Group, Department of Computer Science, University of Hertfordshire, Hatfield AL10 9AB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3921-6813","authenticated-orcid":false,"given":"Raimund","family":"Kirner","sequence":"additional","affiliation":[{"name":"Cybersecurity and Computing Systems Research Group, Department of Computer Science, University of Hertfordshire, Hatfield AL10 9AB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9540-4208","authenticated-orcid":false,"given":"Athanasios","family":"Tsokanos","sequence":"additional","affiliation":[{"name":"Cybersecurity and Computing Systems Research Group, Department of Computer Science, University of Hertfordshire, Hatfield AL10 9AB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6984-0268","authenticated-orcid":false,"given":"Iosif","family":"Mporas","sequence":"additional","affiliation":[{"name":"Cybersecurity and Computing Systems Research Group, Department of Computer Science, University of Hertfordshire, Hatfield AL10 9AB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8819-5831","authenticated-orcid":false,"given":"Alexios","family":"Mylonas","sequence":"additional","affiliation":[{"name":"Cybersecurity and Computing Systems Research Group, Department of Computer Science, University of Hertfordshire, Hatfield AL10 9AB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"ref_1","unstructured":"Tariq, U., Alsaeedi, A., Malik, H., and Song, H. (2023). Securing the evolving IoT with deep learning: A comprehensive review. Sensors, 23."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.icte.2017.12.005","article-title":"A comparative study of LPWAN technologies for IoT deployment","volume":"5","author":"Mekki","year":"2019","journal-title":"ICT Express"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"240","DOI":"10.1016\/j.icte.2024.03.003","article-title":"A comprehensive overview of the state of the art on the security of Low Power Wide Area Networks (LPWANs), with a focus on Sigfox and LoRaWAN","volume":"10","author":"Stanco","year":"2024","journal-title":"ICT Express"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1109\/MWC.2016.7721743","article-title":"Long-Range Communications in Unlicensed Bands: The Rising Stars in the IoT and Smart City Scenarios","volume":"23","author":"Centenaro","year":"2016","journal-title":"IEEE Wirel. Commun."},{"key":"ref_5","unstructured":"Povalac, A., and Kral, J. (2025, January 15). LoRaWAN Traffic Analysis Dataset. Available online: https:\/\/doi.org\/10.5281\/zenodo.7919213."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"3176","DOI":"10.3390\/app11073176","article-title":"Security Vulnerabilities in LPWANs\u2014An Attack Vector Analysis for the IoT Ecosystem","volume":"11","author":"Torres","year":"2021","journal-title":"Appl. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Adewole, K.S., Owolabi, K., and Abdullateef, A.M. (2025). Intrusion Detection Framework for Internet of Things with Ensemble Learning and Rule Induction. Sensors, 25.","DOI":"10.3390\/s25061845"},{"key":"ref_8","first-page":"14","article-title":"Machine Learning for Intrusion Detection System in IoT Environment with Permutation Importance","volume":"Volume 3774","author":"Singh","year":"2024","journal-title":"Proceedings of the SNSFAIT 2024, Delhi, India, 8\u20139 August 2024"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Haque, A., Chowdhury, M.N.-U.-R., Soliman, H., Hossen, M.S., Fatima, T., and Ahmed, I. (2023). Wireless Sensor Networks anomaly detection using Machine Learning: A Survey. arXiv.","DOI":"10.36227\/techrxiv.22580881"},{"key":"ref_10","unstructured":"Scikit-Learn Developers (2025, October 17). Common Pitfalls and Recommended Practices (Explains Data Leakage; Fit Preprocessors on Train Only). Available online: https:\/\/scikit-learn.org\/stable\/common_pitfalls.html."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Ruotsalainen, H., Shen, G., Zhang, J., and Fujdiak, R. (2022). LoRaWAN Physical Layer-Based Attacks and Countermeasures: A Review. Sensors, 22.","DOI":"10.3390\/s22093127"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"e4452","DOI":"10.1002\/ett.4452","article-title":"LoRaWAN security issues and mitigation options","volume":"33","author":"Kuntke","year":"2022","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1191","DOI":"10.1109\/COMST.2019.2962586","article-title":"A Survey on the Internet of Things (IoT) Forensics: Challenges, Approaches, and Open Issues","volume":"22","author":"Stoyanova","year":"2020","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"St. Germain, K., and Kragh, F. (2020). Physical-Layer Authentication Using Channel State Information and Machine Learning. arXiv.","DOI":"10.24251\/HICSS.2021.846"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Pourghasem, A., Kirner, R., Tsokanos, A., Mporas, I., and Mylonas, A. (2025). Machine learning-based multi-attribute physical-layer authentication for spoofing and availability detection in LoRaWAN. Future Internet, 17.","DOI":"10.3390\/fi17020068"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1292","DOI":"10.1109\/TWC.2019.2952584","article-title":"On the Error Rate of the LoRa Modulation with Interference","volume":"19","author":"Afisiadis","year":"2020","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_17","unstructured":"Aras, S., Tavl\u0131, B., and Y\u0131ld\u0131z, H.U. (2017, January 18). Experimental evaluation of selective jamming attacks in LoRaWAN. Proceedings of the ACM Workshop on Wireless Security and Privacy (WiSec), Boston, MA, USA."},{"key":"ref_18","first-page":"1","article-title":"Jamming of LoRa PHY and countermeasure","volume":"19","author":"Hou","year":"2023","journal-title":"ACM Trans. Sens. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Perkovi\u0107, T., Rude\u0161, H., Damjanovi\u0107, S., and Naki\u0107, A. (2021). Low-Cost Implementation of Reactive Jammer on LoRaWAN Network. Electronics, 10.","DOI":"10.3390\/electronics10070864"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Shakhov, V. (2018). Depletion-of-battery attack: Specificity, modelling and analysis. Sensors, 18.","DOI":"10.3390\/s18061849"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Mikhaylov, K., Fujdiak, R., Pouttu, A., Voz\u0148\u00e1k, M., Malina, L., and Mlynek, P. (2019, January 26\u201329). Energy Attack in LoRaWAN: Experimental Validation. Proceedings of the 14th International Conference on Availability, Reliability and Security (ARES 2019), Canterbury, UK.","DOI":"10.1145\/3339252.3340525"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Singh, R.K., Puluckul, P.P., Berkvens, R., and Weyn, M. (2020). Energy Consumption Analysis of LPWAN Technologies and Lifetime Estimation for IoT Application. Sensors, 20.","DOI":"10.3390\/s20174794"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Kuaban, G.S., Gelenbe, E., Czach\u00f3rski, T., Czekalski, P., and Tangka, J.K. (2023). Modelling of the Energy Depletion Process and Battery Depletion Attacks for Battery-Powered Internet of Things (IoT) Devices. Sensors, 23.","DOI":"10.3390\/s23136183"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/MC.2002.1039518","article-title":"Denial of Service in Sensor Networks","volume":"35","author":"Wood","year":"2002","journal-title":"IEEE Comput."},{"key":"ref_25","unstructured":"Proto, M., Miers, A., and Carvalho, J. (2024, January 25\u201327). Intrusion detection based on energy consumption for EDAs in LoRaWAN. Proceedings of the International Conference on Internet of Things, Big Data and Security (IoTBDS 2024), Angers, France."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"He, P., Zhang, X., Lee, J., and Singh, R. (2024). Energy-Aware Security Mechanisms for the Internet of Things: A Survey. Future Internet, 16.","DOI":"10.3390\/fi16040128"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Ruotsalainen, H. (2022, January 23\u201326). Reactive Jamming Detection for LoRaWAN Based on Meta-Data Differencing. Proceedings of the 17th International Conference on Availability, Reliability and Security (ARES 2022), Vienna, Austria.","DOI":"10.1145\/3538969.3543805"},{"key":"ref_28","unstructured":"Demeslay, C., Gautier, R., Fiche, A., and Burel, G. (2021). Band & Tone Jamming Analysis and Detection on LoRa signals. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"14682","DOI":"10.1109\/JIOT.2023.3343611","article-title":"Jamming Detection in Low-BER Mobile Indoor Scenarios via Deep Learning","volume":"11","author":"Sciancalepore","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MNET.2006.1637931","article-title":"Jamming sensor networks: Attacks and defenses","volume":"20","author":"Xu","year":"2006","journal-title":"IEEE Netw."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Dossa, A., and Amhoud, E.M. (2025). Impact of Reactive Jamming Attacks on LoRaWAN: A Theoretical and Experimental Study. arXiv.","DOI":"10.1109\/PIMRC62392.2025.11275285"},{"key":"ref_32","unstructured":"Testi, E., Arcangeloni, L., and Giorgetti, A. (2023, January 12\u201317). Machine learning-based jamming detection and classification in wireless networks. Proceedings of the SenSys \u201823, Istanbul, Turkey."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Stajano, F., and Anderson, R. (2000). The Resurrecting Duckling: Security Issues for Ad-hoc Wireless Networks. Security Protocols, 7th International Workshop, Springer.","DOI":"10.1007\/10720107_24"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Deng, J., Han, R., and Mishra, S. (2005, January 7). Defending against path-based DoS attacks in wireless sensor networks. Proceedings of the 3rd ACM Workshop on Security of Ad Hoc and Sensor Networks (SASN \u201805), Alexandria, VA, USA.","DOI":"10.1145\/1102219.1102235"},{"key":"ref_35","unstructured":"(2017). LoRaWAN\u00ae Specification v1.1, LoRa Alliance."},{"key":"ref_36","unstructured":"(2020). LoRaWAN\u00ae L2 1.0.4 Specification (TS001-1.0.4), LoRa Alliance."},{"key":"ref_37","unstructured":"(2025, January 15). The Things Industries. Best Practices. Available online: https:\/\/www.thethingsindustries.com\/docs\/hardware\/devices\/concepts\/best-practices\/."},{"key":"ref_38","unstructured":"Semtech (2025, January 15). Sending Messages: Opening Receive Windows. Available online: https:\/\/learn.semtech.com\/mod\/book\/view.php?id=172&chapterid=127."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Mao, Z., Zhou, B., Huang, J., Liu, D., and Yang, Q. (2024). Research on anomaly detection model for power consumption data based on time-series reconstruction. Energies, 17.","DOI":"10.3390\/en17194810"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1388","DOI":"10.1049\/iet-its.2020.0009","article-title":"Predictive model for battery life in IoT networks","volume":"14","author":"Maddikunta","year":"2020","journal-title":"IET Intell. Transp. Syst."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Tan, X., Su, S., Zuo, Z., Guo, X., and Sun, X. (2019). Intrusion Detection of UAVs Based on the Deep Belief Network Optimized by PSO. Sensors, 19.","DOI":"10.3390\/s19245529"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"767","DOI":"10.1109\/COMST.2022.3159185","article-title":"Jamming Attacks and Anti-Jamming Strategies in Wireless Networks: A Comprehensive Survey","volume":"24","author":"Pirayesh","year":"2022","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_43","unstructured":"Haque, A., and Saifullah, A. (July, January 29). Stackelberg game-based anti-jamming strategies for LPWANs. Proceedings of the IEEE Conference on Communications and Network Security, Virtual."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1109\/MCOM.2017.1600613","article-title":"Understanding the Limits of LoRaWAN","volume":"55","author":"Adelantado","year":"2017","journal-title":"IEEE Commun. Mag."},{"key":"ref_45","unstructured":"Scikit-Learn Developers (2025, October 17). StandardScaler\u2014Scikit-Learn Documentation (Defines z = (x \u2212 \u03bc)\/\u03c3 z = (x-\\mu)\/\\sigma z = (x \u2212 \u03bc)\/\u03c3 and Notes That \u03bc, \u03c3 \\mu, \\sigma \u03bc, \u03c3 Are Computed from Training Samples). Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.preprocessing.StandardScaler.html."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Khan, M.A., Khan, M.A., Jan, S.U., Ahmad, J., Jamal, S.S., Shah, A.A., Pitropakis, N., and Buchanan, W.J. (2021). A deep learning-based intrusion detection system for MQTT enabled IoT. Sensors, 21.","DOI":"10.3390\/s21217016"},{"key":"ref_47","unstructured":"Scikit-Learn Developers (2025, October 17). TimeSeriesSplit\u2014Scikit-Learn Documentation (Time-Ordered Splitting; Avoid Training on the Future). Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.model_selection.TimeSeriesSplit.html."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2382577.2382579","article-title":"Leakage in Data Mining: Formulation, Detection, and Avoidance","volume":"6","author":"Kaufman","year":"2012","journal-title":"ACM Trans. Knowl. Discov. Data (TKDD)"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Reddi, V.J., Cheng, C., Kanter, D., Mattson, P., Schmuelling, G., Wu, C.-J., Anderson, B., Breughe, M., Charlebois, M., and Chou, W. (June, January 30). MLPerf Inference Benchmark. Proceedings of the 47th ACM\/IEEE International Symposium on Computer Architecture (ISCA 2020), Valencia, Spain.","DOI":"10.1109\/ISCA45697.2020.00045"},{"key":"ref_50","unstructured":"OpenMP Architecture Review Board (2025, October 17). OpenMP Application Programming Interface. Available online: https:\/\/www.openmp.org\/specifications\/."},{"key":"ref_51","unstructured":"Netlib (2025, October 17). Basic Linear Algebra Subprograms (BLAS)\u2014Documentation Portal. Available online: http:\/\/www.netlib.org\/blas\/."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/1\/38\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T13:01:54Z","timestamp":1767877314000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/1\/38"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,8]]},"references-count":51,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,1]]}},"alternative-id":["fi18010038"],"URL":"https:\/\/doi.org\/10.3390\/fi18010038","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,8]]}}}