Empirical Evaluation of Edge AI for Industrial IoT Security
Table Of Contents
Chapter ONE
INTRODUCTION
- 1.1Introduction
- 1.2Background of the Study
- 1.3Statement of the Problem
- 1.4Aim and Objectives of the Study
- 1.5Research Questions
- 1.6Research Hypotheses
- 1.7Significance of the Study
- 1.8Scope and Delimitation of the Study
- 1.9Limitations of the Study
- 1.10Organisation of the Study
- 1.11Operational Definition of Terms
Chapter TWO
LITERATURE REVIEW
- 2.1Conceptual Review: Edge AI in Industrial IoT Security
- 2.2Conceptual Asset Protection Models for Edge-Driven IIoT
- 2.3Theoretical Framework: Distributed Artificial Intelligence and Security-by-Edge Theories
- 2.4Theoretical Framework: Trust-Edge and Federated Learning Security Theories
- 2.5Empirical Review: Edge AI Applications in IIoT Security Settings
- 2.6Empirical Review: Attack Surfaces in Edge-Deployed IIoT Environments
- 2.7Empirical Review: Threat Detection Latency and Resource Constraints at the Edge
- 2.8Empirical Review: Privacy-Preserving Inference on Edge Devices
- 2.9Empirical Review: Data Acquisition and Labeling in Industrial Environments
- 2.10Empirical Review: Dataset Availability for Edge IIoT Security Research
- 2.11Identified Gaps in the Literature: Edge AI Security in Industrial Contexts
- 2.12Conceptual Model: Integrated Edge AI Security Framework for IIoT
Chapter THREE
SYSTEM DESIGN AND IMPLEMENTATION
- 3.1Research Design: Empirical Field Study in Manufacturing IoT Networks
- 3.2Philosophical Paradigm: Pragmatism for Applied Security Evaluation
- 3.3Population of the Study: Industrial Plants with Edge Nodes and IIoT Sensors
- 3.4Sample Size and Sampling Technique: Stratified Random Sampling of Edge Gateways and Devices
- 3.5Sources and Instruments of Data Collection: Field Experiments, Logs, and Security Tooling
- 3.6Validity and Reliability of Instruments: Pilot Testing, Triangulation, and Calibration
- 3.7Data Collection Procedures: Deployment Scenarios, Attack Simulations, and Data Logging
- 3.8Data Analysis Techniques: Statistical, ML-Based Anomaly Detection, and Comparative Evaluation
- 3.9Model Specification or Analytical Framework: Edge-Driven Security Performance Model
- 3.10Ethical Considerations: Safety, Compliance, and Data Privacy
- 3.11Risk Assessment and Mitigation Plan
Chapter FOUR
SYSTEM TESTING AND EVALUATION
- ANALYSIS AND DISCUSSION OF FINDINGS
- 4.1Data Presentation: Overview of Field Deployment Metrics
- 4.2Descriptive Analysis: Baseline Edge Performance vs. Post-Deployment Security Metrics
- 4.3Hypotheses Testing: Detection Rate, False Positive Rate, and Latency under Edge Inference
- 4.4Interpretation of Results: Trade-offs Between Latency, Bandwidth, and Security Accuracy
- 4.5Comparison with Prior Studies: Alignment and Divergence with Literature
- 4.6Scenario-Based Analysis: Normal Operations, Anomalous Events, and Adversarial Conditions
- 4.7robustness and Generalizability: External Validity Across Plant Environments
- 4.8Discussion of Findings: Implications for Industry Stakeholders
Chapter FIVE
SUMMARY, CONCLUSION AND RECOMMENDATIONS
- CONCLUSION AND RECOMMENDATIONS
- 5.1Summary of Findings
- 5.2Conclusion: Implications for Edge AI Security in IIoT
- 5.3Contribution to Knowledge: Practical Framework and Empirical Evidence
- 5.4Recommendations: Design, Policy, and Practice for Industrial Contexts
- 5.5Suggestions for Further Studies
Thesis Abstract
Industrial Internet of Things (IIoT) deployments increasingly rely on edge artificial intelligence to detect anomalies, enforce security policies, and enable real-time responses at the network edge. However, the heterogeneous and resource-constrained nature of industrial environments, combined with adversarial threats targeting edge devices and federated inference, raises questions about the reliability, robustness, and generalizability of edge-based security solutions. This study aims to empirically evaluate the effectiveness of edge AI for securing IIoT ecosystems, focusing on detection accuracy, latency, resource utilization, and resilience to concept drift and adversarial manipulation in real-world settings. The objectives are to (i) compare edge-based anomaly detection models with cloud-centric baselines in terms of detection performance and latency; (ii) assess the impact of hardware heterogeneity, such as CPU/GPU-assisted edge nodes and constrained microcontrollers, on inference throughput and energy consumption; (iii) examine robustness to concept drift across varying factory conditions and process changes; (iv) evaluate defenses against adversarial inputs and data poisoning at the edge; and (v) formulate a set of design guidelines for deploying secure edge AI in IIoT environments. The study adopts a mixed-methods, empirical field design conducted over twelve months in three manufacturing pilot sites representing discrete, process, and hybrid automation, with a total population of approximately 120 edge devices and 60 human operators. A purposive sampling approach identifies representative edge nodes (industrial gateways, fog nodes, and programmable logic controller aggregations) and associated IIoT sensors (vibration, temperature, current, and network flow metrics). Data collection combines passive telemetry logs, labeled security events, and controlled red-team experiments to generate adversarial and normal-condition datasets. Quantitative data consist of 10 TB of heterogeneous time-series data and 2,400 labeled security events, with a stratified sample of 1,000 edge inferences per site per week. Qualitative insights are drawn from 36 semi-structured interviews with operators and security engineers and 18 on-site observation sessions. The research employs a theoretical lens anchored in the Technology-Organization-Environment (TOE) framework and the Secure Edge Computing paradigm, integrating concepts from anomaly detection theory and adversarial machine learning. Methodologically, the study compares multiple edge AI architectures, including lightweight neural networks, ensemble methods, and federated learning configurations, using on-device inference with TensorRT and OpenVINO, and a cloud-based comparator. Data analysis employs (i) time-series anomaly detection metrics (precision, recall, F1-score, ROC-AUC) and latency benchmarks; (ii) resource utilization analysis (CPU/GPU load, memory footprints, energy consumption) using hardware counters and power profiling; (iii) concept drift evaluation via adaptive retraining intervals and drift detection methods (DDM, EDDM); (iv) robustness assessment through adversarial example generation (FGSM, BIM) and poisoning simulations, evaluated with robust accuracy and confusion matrices; and (v) qualitative coding of interview transcripts using thematic analysis to extract perceived security usability and deployment barriers. Inferential analyses include mixed-effects ANOVA to assess performance differences across device classes and sites, and regression modeling to quantify the relationship between latency, energy consumption, and detection accuracy. A hierarchical Bayesian model is employed to fuse heterogeneous data sources and quantify uncertainty in edge-detected events. The study also implements a risk-adjusted evaluation framework to translate technical performance into security posture outcomes. Expected findings indicate that edge AI can achieve near-parity detection accuracy with substantially reduced lateral communication latency compared to cloud baselines, albeit with higher variance across heterogeneous hardware and environmental conditions. Edge-specific adversarial defenses, including input sanitization and lightweight ensemble voting, are anticipated to improve robustness but require periodic retraining to counter concept drift. The investigation is expected to reveal a trade-off between inference speed and model complexity, with federated learning offering resilience benefits at the cost of communication overhead. The contributions to knowledge include empirical benchmarks for edge AI security in IIoT, a validated framework for evaluating edge instability and threat resilience, and practical deployment guidelines for secure, low-latency edge inference in multi-site manufacturing settings. The main conclusion posits that carefully engineered edge AI architectures, complemented by adaptive drift-aware maintenance and robust defense mechanisms, can provide effective, scalable IIoT security without fully relinquishing cloud-assisted oversight. Recommendations emphasize standardized evaluation protocols for edge security, continuous on-device learning with secure aggregation, and governance practices to balance security, privacy, and operational performance across diverse industrial contexts.
Thesis Overview
Edge AI refers to running artificial intelligence algorithms directly on edge devices such as industrial sensors, gateways, and controllers rather than in centralized cloud servers. The study investigates how deploying edge-based AI can enhance security in Industrial Internet of Things (IIoT) environments, where latency, bandwidth constraints, and real-time decision-making are critical. It matters because traditional cloud-centric security approaches may be too slow to detect and respond to threats on the shop floor, and edge processing can reduce exposure by keeping data local and enabling rapid anomaly detection and enforcement.
The central problem is the limited empirical understanding of how well edge AI performs under real-world IIoT conditions, including resource constraints, heterogeneous devices, and evolving threat landscapes. Gaps include: (1) comparative effectiveness of edge vs. cloud-based security models, (2) impact of limited compute and memory on detection accuracy and false positives, (3) operational feasibility in terms of energy use, maintenance, and interoperability with existing industrial protocols.
Research plan in steps:
- Design: formulate a field study in a mid-size manufacturing plant with a mix of sensors, PLCs, and edge devices. Develop threat scenarios (e.g., sensor spoofing, spoofed firmware updates, anomalous traffic bursts) and define security metrics (detection rate, false positive rate, response time, resource utilization).
- Data collection: deploy two parallel security pipelines—edge AI on gateways for anomaly detection and a cloud-based reference model. Collect network traffic, device logs, security alerts, and performance counters over 12 weeks across 150 heterogeneous IIoT nodes.
- Data analysis: use classification metrics (precision, recall, F1) and ROC-AUC to evaluate detection performance; apply ANOVA to compare edge versus cloud models across device types; conduct regression analyses to examine the relationship between resource use and detection accuracy. Thematic analysis will be used to interpret incident logs and operator feedback.
- Validation: perform ablation studies to assess the impact of model size and feature selection; conduct sensitivity analyses to threat variability.
Expected contribution and outcome: provide empirical evidence on the trade-offs between edge and cloud security in IIoT, identify configurations that maximize detection accuracy while maintaining acceptable resource use, and deliver practical guidelines for deploying edge AI in manufacturing security architectures.