DOI: 10.3390/electronics15163620 ISSN: 2079-9292

Quantum-Assisted Cross-Layer Intrusion Detection and Distributed-AI-Driven (QSec-DAI) Active Attribution of Insider and Man-in-the-Middle Attacks in Cooperative Sensing

Iacovos Ioannou, Michael Georgiades

Cooperative sensing systems that exchange state estimates are exposed to two types of adversaries, namely, insiders who transmit correctly authenticated falsified content and outsiders who modify messages in transit after compromising a symmetric link key, each requiring a distinct mitigation strategy. These attacks are observationally identical to a detector that examines only message content, although an insider must be revoked and an outsider must be countered through key rotation and link hardening. To distinguish between insider falsification and outsider in-transit message modification, a cross-layer intrusion detection and attack-attribution framework named QSec-DAI is proposed. Per-message anomaly scores are supplied by a recurrent detector, and a hybrid-symmetric, post-quantum and quantum authentication stack is arbitrated by belief-desire-intention agents under a finite-key budget. Authentication is used as an active probe because a suspicious link is hardened, and the persistence or disappearance of the anomaly is then observed. On real cooperative-localization data, an area under the receiver operating characteristic curve of 0.981 is achieved. Benign, insider and outsider classes are attributed with a macro-averaged accuracy of 0.794 and a man-in-the-middle recall of 0.719. Under the explicitly defined attribution mapping, outsider recall is zero for the evaluated baselines that remain in fixed-symmetric mode after key exposure. In the real-data evaluation, malicious influence on fusion is limited to 0.10 percent. The no-cooperation control indicates that several classical defenses suppress attacks mainly by discarding cooperative information rather than by preserving useful cooperation. Protocol-level fault injection shows that replay is rejected while monotonic freshness state is intact, whereas compromise of the verifier or of all independent strong credentials removes defensible outsider identifiability. The quantum component is therefore presented as one resource-constrained strong-authentication option rather than as a source of quantum-enhanced anomaly detection.

More from our Archive