STAC-ML: A Trust-Aware Security Architecture for Resource-Constrained NDN-IoT Networks with Lightweight ML-Assisted Threat Detection
Djamal Seghier, Moustafa Maaskri, Pietro Manzoni, Mohamed Goismi, Mohamed DebbabEdge caching improves latency and energy efficiency in IoT deployments, but it also enlarges the attack surface: cache poisoning, content pollution, and Interest flooding can silently corrupt time-critical services. Existing defences sit at two inadequate extremes—blockchain-based trust exceeds edge-device budgets (>10 MB memory, 2–5 s consensus latency), while rule-based filters lack discriminative power against adaptive adversaries. We propose STAC-ML, a trust-and-security architecture for resource-constrained NDN-IoT networks. Behavioural trust evaluation (O(1) updates, 24 KB memory), security-augmented content ranking, and dual-cache isolation form the deterministic defence core, executable on genuinely Class-2 caching nodes; a lightweight INT8-quantised classifier supplements this core on gateway-class nodes (e.g., Raspberry Pi 3B+), falling back to deterministic rules whenever its confidence is insufficient. Across nine simulated topology configurations (289–1200 nodes), STAC-ML sustains a 77–84% cache hit ratio—within 3% of performance-optimised baselines—while cutting poisoning success rate by 91% and flooding impact by 85%, achieving a 96% attack detection rate at a 5% false-positive rate (all statistically significant, Welch’s t-test with Holm–Bonferroni correction). We further validate the full system on a 9-node physical NDN-IoT testbed, confirming 680 KB model memory, 3.07 ms median inference latency, and a 16.1% energy overhead under benign load (24.9% at the gateway under combined attack)—all within 1–4% of simulation projections. Baseline systems and the ablation study remain simulation-based; hardware re-deployment of these comparisons is the primary remaining validation step. Code, trained models, and measurement logs will be released via a persistent-identifier archive (Zenodo) upon acceptance; an anonymised pre-acceptance snapshot is available to reviewers upon request.